Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 20, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
241181 5.8 警告 アップル - Apple Safari 6.0 未満で使用される WebKit における同一生成元ポリシーを回避される脆弱性 CWE-20
不適切な入力確認
CVE-2012-3689 2012-07-27 12:16 2012-07-25 Show GitHub Exploit DB Packet Storm
241182 4.3 警告 アップル - Apple Safari 6.0 未満における任意のファイルを読まれる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-0679 2012-07-27 12:02 2012-07-25 Show GitHub Exploit DB Packet Storm
241183 4.3 警告 Opera Software ASA - Opera における SSL サーバ証明書の検証不備の脆弱性 CWE-Other
その他
CVE-2012-1251 2012-07-26 17:30 2012-05-25 Show GitHub Exploit DB Packet Storm
241184 9.3 危険 Google - Google Chrome における整数オーバーフローの脆弱性 CWE-189
数値処理の問題
CVE-2012-2834 2012-07-26 17:30 2012-06-26 Show GitHub Exploit DB Packet Storm
241185 7.5 危険 Google - Google Chrome におけるサービス運用妨害 (不正なポインタの使用) の脆弱性 CWE-DesignError
CVE-2012-2830 2012-07-26 17:29 2012-06-26 Show GitHub Exploit DB Packet Storm
241186 5 警告 Google - Google Chrome におけるサービス運用妨害 (out-of-bounds read) の脆弱性 CWE-Other
その他
CVE-2012-2826 2012-07-26 17:28 2012-06-26 Show GitHub Exploit DB Packet Storm
241187 7.5 危険 Google - Google Chrome におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2012-2823 2012-07-26 17:27 2012-06-26 Show GitHub Exploit DB Packet Storm
241188 7.5 危険 Google - Google Chrome の autofill におけるテキスト表示の処理に関する脆弱性 CWE-noinfo
情報不足
CVE-2012-2821 2012-07-26 17:27 2012-06-26 Show GitHub Exploit DB Packet Storm
241189 5 警告 Google - Google Chrome におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2012-2820 2012-07-26 17:27 2012-06-26 Show GitHub Exploit DB Packet Storm
241190 6.8 警告 Google - Google Chrome の texSubImage2D におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2012-2819 2012-07-26 17:26 2012-06-26 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 20, 2026, 4:14 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
268811 6.1 MEDIUM
Network
mozilla nunjucks Nunjucks is a full featured templating engine for JavaScript. Versions 2.4.2 and lower have a cross site scripting (XSS) vulnerability in autoescape mode. In autoescape mode, all template vars should… CWE-79
Cross-site Scripting
CVE-2016-10547 2024-11-21 11:44 2018-06-1 Show GitHub Exploit DB Packet Storm
268812 9.8 CRITICAL
Network
pouchdb pouchdb An arbitrary code injection vector was found in PouchDB 6.0.4 and lesser via the map/reduce functions used in PouchDB temporary views and design documents. The code execution engine for this branch i… CWE-94
Code Injection
CVE-2016-10546 2024-11-21 11:44 2018-06-1 Show GitHub Exploit DB Packet Storm
268813 5.9 MEDIUM
Network
uws_project uws uws is a WebSocket server library. By sending a 256mb websocket message to a uws server instance with permessage-deflate enabled, there is a possibility used compression will shrink said 256mb down t… CWE-20
 Improper Input Validation 
CVE-2016-10544 2024-11-21 11:44 2018-06-1 Show GitHub Exploit DB Packet Storm
268814 5.3 MEDIUM
Network
call_project call call is an HTTP router that is primarily used by the hapi framework. There exists a bug in call versions 2.0.1-3.0.1 that does not validate empty parameters, which could result in invalid input bypas… CWE-20
 Improper Input Validation 
CVE-2016-10543 2024-11-21 11:44 2018-06-1 Show GitHub Exploit DB Packet Storm
268815 7.5 HIGH
Network
ws_project ws ws is a "simple to use, blazing fast and thoroughly tested websocket client, server and console for node.js, up-to-date against RFC-6455". By sending an overly long websocket payload to a `ws` server… CWE-20
 Improper Input Validation 
CVE-2016-10542 2024-11-21 11:44 2018-06-1 Show GitHub Exploit DB Packet Storm
268816 9.8 CRITICAL
Network
shell-quote_project shell-quote The npm module "shell-quote" 1.6.0 and earlier cannot correctly escape ">" and "<" operator used for redirection in shell. Applications that depend on shell-quote may also be vulnerable. A malicious … CWE-94
Code Injection
CVE-2016-10541 2024-11-21 11:44 2018-06-1 Show GitHub Exploit DB Packet Storm
268817 7.5 HIGH
Network
minimatch_project minimatch Minimatch is a minimal matching utility that works by converting glob expressions into JavaScript `RegExp` objects. The primary function, `minimatch(path, pattern)` in Minimatch 3.0.1 and earlier is … CWE-20
 Improper Input Validation 
CVE-2016-10540 2024-11-21 11:44 2018-06-1 Show GitHub Exploit DB Packet Storm
268818 7.5 HIGH
Network
negotiator_project negotiator negotiator is an HTTP content negotiator for Node.js and is used by many modules and frameworks including Express and Koa. The header for "Accept-Language", when parsed by negotiator 0.6.0 and earlie… CWE-20
 Improper Input Validation 
CVE-2016-10539 2024-11-21 11:44 2018-06-1 Show GitHub Exploit DB Packet Storm
268819 3.5 LOW
Network
cli_project
debian
cli
debian_linux
The package `node-cli` before 1.0.0 insecurely uses the lock_file and log_file. Both of these are temporary, but it allows the starting user to overwrite any file they have access to. CWE-362
Race Condition
CVE-2016-10538 2024-11-21 11:44 2018-06-1 Show GitHub Exploit DB Packet Storm
268820 5.4 MEDIUM
Network
backbone_project backbone backbone is a module that adds in structure to a JavaScript heavy application through key-value pairs and custom events connecting to your RESTful API through JSON There exists a potential Cross Site… CWE-79
Cross-site Scripting
CVE-2016-10537 2024-11-21 11:44 2018-06-1 Show GitHub Exploit DB Packet Storm