Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 15, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
240741 4.3 警告 Moodle - Moodle の mod/lti/typessettings.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-3389 2012-07-25 13:35 2012-07-23 Show GitHub Exploit DB Packet Storm
240742 4 警告 Moodle - Moodle の lib/accesslib.php における機能チェックを回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-3388 2012-07-25 12:28 2012-07-23 Show GitHub Exploit DB Packet Storm
240743 4 警告 Moodle - Moodle におけるエイリアスの制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-3387 2012-07-25 12:22 2012-07-23 Show GitHub Exploit DB Packet Storm
240744 4.3 警告 ESET
マカフィー
AVG Technologies
Jiangmin
Norman
FRISK Software International
VirusBlokAda
クイックヒール・テクノロジーズ・ジャパン株式会社
エフ・セキュア
G Data Software
AVAST Software s.r.o.
Beijing Rising International Software
Panda Security
カスペルスキ
- 複数の製品の TAR ファイルパーサにおけるマルウェア検知を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-1459 2012-07-25 11:09 2012-03-21 Show GitHub Exploit DB Packet Storm
240745 4.3 警告 ClamAV
ソフォス
- ClamAV および Sophos Anti-Virus の Microsoft CHM ファイルパーサにおけるマルウェア検知を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-1458 2012-07-25 11:08 2012-03-21 Show GitHub Exploit DB Packet Storm
240746 4.3 警告 ESET
マカフィー
AVG Technologies
Jiangmin
Norman
FRISK Software International
VirusBlokAda
クイックヒール・テクノロジーズ・ジャパン株式会社
G Data Software
AVAST Software s.r.o.
Beijing Rising International Software
カスペルスキー
Avira
Emsisoft
シマン
- 複数の製品の TAR ファイルパーサにおけるマルウェア検知を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-1457 2012-07-25 11:06 2012-03-21 Show GitHub Exploit DB Packet Storm
240747 4.4 警告 Puppet - Puppet および Puppet Enterprise における権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-1054 2012-07-25 11:02 2012-05-29 Show GitHub Exploit DB Packet Storm
240748 6.9 警告 Puppet - Puppet および Puppet Enterprise の change_user メソッドにおける権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-1053 2012-07-25 11:00 2012-05-29 Show GitHub Exploit DB Packet Storm
240749 7.5 危険 The PHP Group - PHP の php_variables.c 内の php_register_variable_ex 関数における任意のコードを実行される脆弱性 CWE-399
リソース管理の問題
CVE-2012-0830 2012-07-24 18:02 2012-02-1 Show GitHub Exploit DB Packet Storm
240750 7.5 危険 PNG Development Group - libpng の pngerror.c におけるサービス運用妨害 (アプリケーションクラッシュ) の脆弱性 CWE-189
数値処理の問題
CVE-2011-3464 2012-07-24 16:44 2012-07-22 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 16, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
268121 8.1 HIGH
Network
strider-sauce_project strider-sauce strider-sauce is Sauce Labs / Selenium support for Strider. strider-sauce downloads zipped resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code exe… CWE-310
Cryptographic Issues
CVE-2016-10611 2024-11-21 11:44 2018-05-30 Show GitHub Exploit DB Packet Storm
268122 8.1 HIGH
Network
uxebu webdrvr webdrvr is a npm wrapper for Selenium Webdriver including Chromedriver / IEDriver / IOSDriver / Ghostdriver. webdrvr downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. … CWE-310
Cryptographic Issues
CVE-2016-10601 2024-11-21 11:44 2018-05-30 Show GitHub Exploit DB Packet Storm
268123 8.1 HIGH
Network
interactivebrokers ibapi ibapi is an Interactive Brokers API addon for NodeJS. ibapi downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. Before 2.5.6, it may be possible to cause remote code exe… CWE-310
Cryptographic Issues
CVE-2016-10593 2024-11-21 11:44 2018-05-30 Show GitHub Exploit DB Packet Storm
268124 8.1 HIGH
Network
prince_project prince Prince is a Node API for executing XML/HTML to PDF renderer PrinceXML via prince(1) CLI. prince downloads zipped resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to… CWE-310
Cryptographic Issues
CVE-2016-10591 2024-11-21 11:44 2018-05-30 Show GitHub Exploit DB Packet Storm
268125 8.1 HIGH
Network
cue-sdk-node_project cue-sdk-node cue-sdk-node is a Corsair Cue SDK wrapper for node.js. cue-sdk-node downloads zipped resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution… CWE-310
Cryptographic Issues
CVE-2016-10590 2024-11-21 11:44 2018-05-30 Show GitHub Exploit DB Packet Storm
268126 8.1 HIGH
Network
spunjs selenium-binaries selenium-binaries downloads Selenium related binaries for your OS. selenium-binaries downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remo… CWE-310
Cryptographic Issues
CVE-2016-10589 2024-11-21 11:44 2018-05-30 Show GitHub Exploit DB Packet Storm
268127 8.1 HIGH
Network
macacajs macaca-chromedriver macaca-chromedriver is a Node.js wrapper for the selenium chromedriver. macaca-chromedriver before 1.0.29 downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be p… CWE-310
Cryptographic Issues
CVE-2016-10586 2024-11-21 11:44 2018-05-30 Show GitHub Exploit DB Packet Storm
268128 8.1 HIGH
Network
dalekjs dalekjs dalek-browser-chrome-canary provides Google Chrome bindings for DalekJS. dalek-browser-chrome-canary downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possib… CWE-310
Cryptographic Issues
CVE-2016-10584 2024-11-21 11:44 2018-05-30 Show GitHub Exploit DB Packet Storm
268129 8.1 HIGH
Network
unicode_project unicode unicode loads unicode data downloaded from unicode.org into nodejs. Unicode before 9.0.0 downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. CWE-310
Cryptographic Issues
CVE-2016-10578 2024-11-21 11:44 2018-05-30 Show GitHub Exploit DB Packet Storm
268130 8.1 HIGH
Network
ibm ibm_db ibm_db is an asynchronous/synchronous interface for node.js to IBM DB2 and IBM Informix. ibm_db before 1.0.2 downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may b… CWE-310
Cryptographic Issues
CVE-2016-10577 2024-11-21 11:44 2018-05-30 Show GitHub Exploit DB Packet Storm