Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 11, 2026, 2 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
230181 6.5 警告 stephane rajalu - Malleo の admin.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2009-1456 2012-12-20 19:10 2009-04-28 Show GitHub Exploit DB Packet Storm
230182 7.5 危険 webportal - WebPortal CMS の indexk.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2009-1444 2012-12-20 19:10 2009-04-27 Show GitHub Exploit DB Packet Storm
230183 2.1 注意 トレンドマイクロ - Trend Micro OfficeScan Client の NTRtScan.exe におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2009-1435 2012-12-20 19:10 2009-04-27 Show GitHub Exploit DB Packet Storm
230184 7.5 危険 SilverStripe - SilverStripe の File::find における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-1433 2012-12-20 19:10 2009-04-24 Show GitHub Exploit DB Packet Storm
230185 5 警告 シマンテック - SEP の Symantec Reporting Server におけるログイン画面に任意のテキストを挿入される脆弱性 CWE-20
不適切な入力確認
CVE-2009-1432 2012-12-20 19:10 2009-04-28 Show GitHub Exploit DB Packet Storm
230186 9.3 危険 シマンテック - SSS などで使用される AMS の XFR.EXE における任意のコードを実行される脆弱性 CWE-DesignError
CVE-2009-1431 2012-12-20 19:10 2009-04-28 Show GitHub Exploit DB Packet Storm
230187 9.3 危険 シマンテック - SSS などで使用される AMS の IAO.EXE におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-1430 2012-12-20 19:10 2009-04-28 Show GitHub Exploit DB Packet Storm
230188 10 危険 シマンテック - SSS などで使用される AMS の CBA における任意のコマンドを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2009-1429 2012-12-20 19:10 2009-04-28 Show GitHub Exploit DB Packet Storm
230189 4.3 警告 シマンテック - SAV などで使用される Symantec Log Viewer におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-1428 2012-12-20 19:10 2009-04-28 Show GitHub Exploit DB Packet Storm
230190 4.3 警告 webSPELL - webSPELL におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-1408 2012-12-20 19:10 2009-04-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 11, 2026, 5:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
294701 - systemd_project
debian
canonical
systemd
debian_linux
ubuntu_linux
systemd does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race con… CWE-362
Race Condition
CVE-2013-4327 2024-11-21 10:55 2013-10-4 Show GitHub Exploit DB Packet Storm
294702 - lennart_poettering
redhat
rkit
enterprise_linux
RealtimeKit (aka rtkit) 0.5 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess Po… CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-4326 2024-11-21 10:55 2013-10-4 Show GitHub Exploit DB Packet Storm
294703 - spice-gtk_project
redhat
spice-gtk
enterprise_linux
spice-gtk 0.14, and possibly other versions, invokes the polkit authority using the insecure polkit_unix_process_new API function, which allows local users to bypass intended access restrictions by l… CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-4324 2024-11-21 10:55 2013-10-4 Show GitHub Exploit DB Packet Storm
294704 - redhat
canonical
libvirt
ubuntu_linux
enterprise_linux
libvirt 1.0.5.x before 1.0.5.6, 0.10.2.x before 0.10.2.8, and 0.9.12.x before 0.9.12.2 allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race c… CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-4311 2024-11-21 10:55 2013-10-4 Show GitHub Exploit DB Packet Storm
294705 - opensuse
polkit_project
canonical
redhat
opensuse
polkit
ubuntu_linux
enterprise_linux
Race condition in PolicyKit (aka polkit) allows local users to bypass intended PolicyKit restrictions and gain privileges by starting a setuid or pkexec process before the authorization check is perf… CWE-362
Race Condition
CVE-2013-4288 2024-11-21 10:55 2013-10-4 Show GitHub Exploit DB Packet Storm
294706 - xen xen The fbld instruction emulation in Xen 3.3.x through 4.3.x does not use the correct variable for the source effective address, which allows local HVM guests to obtain hypervisor stack information by r… CWE-200
Information Exposure
CVE-2013-4361 2024-11-21 10:55 2013-10-2 Show GitHub Exploit DB Packet Storm
294707 - xen xen Xen 4.3.x and earlier does not properly handle certain errors, which allows local HVM guests to obtain hypervisor stack memory via a (1) port or (2) memory mapped I/O write or (3) other unspecified o… CWE-200
Information Exposure
CVE-2013-4355 2024-11-21 10:55 2013-10-2 Show GitHub Exploit DB Packet Storm
294708 - redhat jboss_enterprise_web_platform
jboss_enterprise_brms_platform
jboss_enterprise_soa_platform
jboss_enterprise_application_platform
The org.jboss.remoting.transport.socket.ServerThread class in Red Hat JBoss Remoting for Red Hat JBoss SOA Platform 5.3.1 GA, Web Platform 5.2.0, Enterprise Application Platform 5.2.0, and other prod… NVD-CWE-noinfo
CVE-2013-4210 2024-11-21 10:55 2013-10-2 Show GitHub Exploit DB Packet Storm
294709 - polarssl polarssl The x509parse_crt function in x509.h in PolarSSL 1.1.x before 1.1.7 and 1.2.x before 1.2.8 does not properly parse certificate messages during the SSL/TLS handshake, which allows remote attackers to … CWE-20
 Improper Input Validation 
CVE-2013-4623 2024-11-21 10:55 2013-10-1 Show GitHub Exploit DB Packet Storm
294710 - werner_baumann davfs2 WEB-DAV Linux File System (davfs2) 1.4.6 and 1.4.7 allow local users to gain privileges via unknown attack vectors in (1) kernel_interface.c and (2) mount_davfs.c, related to the "system" function. CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-4362 2024-11-21 10:55 2013-10-1 Show GitHub Exploit DB Packet Storm