Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
238561 4.3 警告 シスコシステムズ - Cisco SESM におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-1287 2012-06-26 16:10 2009-04-13 Show GitHub Exploit DB Packet Storm
238562 5 警告 bibtex - BibTeX におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-1284 2012-06-26 16:10 2009-04-9 Show GitHub Exploit DB Packet Storm
238563 10 危険 Debian - apt の apt-get における悪意のあるリポジトリをインストールされる脆弱性 CWE-DesignError
CVE-2009-1358 2012-06-26 16:10 2007-07-14 Show GitHub Exploit DB Packet Storm
238564 6.8 警告 glFusion - glFusion における権限を取得される脆弱性 CWE-310
暗号の問題
CVE-2009-1283 2012-06-26 16:10 2009-04-9 Show GitHub Exploit DB Packet Storm
238565 7.5 危険 glFusion - glFusion の private/system/lib-session.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-1282 2012-06-26 16:10 2009-04-9 Show GitHub Exploit DB Packet Storm
238566 4.3 警告 glFusion - glFusion におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-1281 2012-06-26 16:10 2009-04-9 Show GitHub Exploit DB Packet Storm
238567 7.5 危険 gravityboardx - GBX の forms/ajax/configure.php における任意の PHP コードを挿入される脆弱性 CWE-94
コード・インジェクション
CVE-2009-1278 2012-06-26 16:10 2009-04-9 Show GitHub Exploit DB Packet Storm
238568 7.5 危険 gravityboardx - GBX の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-1277 2012-06-26 16:10 2009-04-9 Show GitHub Exploit DB Packet Storm
238569 6.8 警告 Apache Software Foundation - Apache Struts などで使用される Apache Tiles における重要情報を取得される脆弱性 CWE-Other
その他
CVE-2009-1275 2012-06-26 16:10 2009-04-9 Show GitHub Exploit DB Packet Storm
238570 5 警告 andrew j.korty - USE=ssh でコンパイルされた PAM で使用される pam_ssh におけるユーザ名が列挙される脆弱性 CWE-255
証明書・パスワード管理
CVE-2009-1273 2012-06-26 16:10 2009-04-8 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 25, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
256371 9.8 CRITICAL
Network
totolink lr350_firmware Incorrect access control in TOTOLINK LR350 V9.3.5u.6369_B20220309 allows attackers to obtain the apmib configuration file, which contains the username and the password, via a crafted request to /cgi-… NVD-CWE-noinfo
CVE-2024-42967 2024-09-7 02:35 2024-08-16 Show GitHub Exploit DB Packet Storm
256372 9.8 CRITICAL
Network
tenda fh1201_firmware An issue in the handler function in /goform/telnet of Tenda FH1201 v1.2.0.14 (408) allows attackers to execute arbitrary commands via a crafted HTTP request. NVD-CWE-noinfo
CVE-2024-42947 2024-09-7 02:35 2024-08-16 Show GitHub Exploit DB Packet Storm
256373 7.8 HIGH
Local
cysoft168 super_easy_enterprise_management_system SQL Injection vulnerability in Super easy enterprise management system v.1.0.0 and before allows a local attacker to execute arbitrary code via a crafted script to the/ajax/Login.ashx component. CWE-89
SQL Injection
CVE-2024-42679 2024-09-7 02:35 2024-08-15 Show GitHub Exploit DB Packet Storm
256374 4.8 MEDIUM
Network
micro.company collect.chat The Chatbot for WordPress by Collect.chat ?? WordPress plugin before 2.4.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Sit… CWE-79
Cross-site Scripting
CVE-2024-6498 2024-09-7 02:35 2024-08-5 Show GitHub Exploit DB Packet Storm
256375 8.6 HIGH
Network
rocket.chat rocket.chat A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1. CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2024-39713 2024-09-7 02:35 2024-08-5 Show GitHub Exploit DB Packet Storm
256376 - - - The UsersWP WordPress plugin before 1.2.12 uses predictable filenames when an admin generates an export, which could allow unauthenticated attackers to download them and retrieve sensitive informati… - CVE-2024-6477 2024-09-7 02:35 2024-08-3 Show GitHub Exploit DB Packet Storm
256377 7.2 HIGH
Network
teamt5 threatsonar_anti-ransomware ThreatSonar Anti-Ransomware from TeamT5 does not properly validate the content of uploaded files. Remote attackers with administrator privileges on the product platform can upload malicious files, w… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2024-7694 2024-09-7 02:24 2024-08-12 Show GitHub Exploit DB Packet Storm
256378 5.4 MEDIUM
Network
wpextended wp_extended The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.0.8 via the duplicate_post function due… CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2024-8123 2024-09-7 02:20 2024-09-4 Show GitHub Exploit DB Packet Storm
256379 6.1 MEDIUM
Network
cisco unified_communications_manager A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could a… CWE-79
Cross-site Scripting
CVE-2024-20488 2024-09-7 02:18 2024-08-22 Show GitHub Exploit DB Packet Storm
256380 - - - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-45294. Reason: This candidate is a duplicate of CVE-2024-45294. Notes: All CVE users should reference CVE-2024-452… - CVE-2024-45295 2024-09-7 02:15 2024-09-7 Show GitHub Exploit DB Packet Storm