Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 13, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
241411 4.3 警告 Drupal
Alex Barth
- Drupal の Feed Element Mapper におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4119 2012-06-26 16:18 2009-11-30 Show GitHub Exploit DB Packet Storm
241412 9.3 危険 Mozilla Foundation
didier ernotte
- Firefox の infoRSS におけるクロスドメインスクリプティング攻撃を実行される脆弱性 CWE-20
不適切な入力確認
CVE-2009-4101 2012-06-26 16:18 2009-07-3 Show GitHub Exploit DB Packet Storm
241413 7.5 危険 Joomla!
g4j.laoneo
- Joomla! 用 Google Calendar GCalendar コンポーネンにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-4099 2012-06-26 16:18 2009-11-29 Show GitHub Exploit DB Packet Storm
241414 7.5 危険 companionway - myPhile における認証を回避される脆弱性 CWE-287
不適切な認証
CVE-2009-4095 2012-06-26 16:18 2009-11-29 Show GitHub Exploit DB Packet Storm
241415 7.5 危険 designforjoomla
Joomla!
- Joomla! 用の D4J eZine コンポーネントにおける PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2009-4094 2012-06-26 16:18 2009-11-29 Show GitHub Exploit DB Packet Storm
241416 7.5 危険 e107.org - e107 の検索機能における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-4084 2012-06-26 16:18 2009-11-29 Show GitHub Exploit DB Packet Storm
241417 4.3 警告 e107.org - e107 におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4083 2012-06-26 16:18 2009-11-29 Show GitHub Exploit DB Packet Storm
241418 4.4 警告 DAG - dstat における権限を取得される脆弱性 CWE-Other
その他
CVE-2009-4081 2012-06-26 16:18 2009-11-29 Show GitHub Exploit DB Packet Storm
241419 7.5 危険 GForge Group - GForge における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-4070 2012-06-26 16:18 2009-11-24 Show GitHub Exploit DB Packet Storm
241420 9.3 危険 Krzysztof Kowalczyk
ccxvii
- SumatraPDF で使用される MuPDF の pdf_shade4.c におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-4117 2012-06-26 16:18 2009-11-30 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 14, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
268641 4.3 MEDIUM
Network
ibm maximo_asset_management
smartcloud_control_desk
maximo_for_government
maximo_for_life_sciences
maximo_for_nuclear_power
maximo_for_oil_and_gas
maximo_for_transportation
maximo_fo…
IBM Maximo Asset Management 7.6 before 7.6.0.3 IFIX001 allows remote authenticated users to bypass intended access restrictions and read arbitrary purchase-order work logs via unspecified vectors. CWE-284
Improper Access Control
CVE-2016-0222 2024-11-21 11:41 2016-03-14 Show GitHub Exploit DB Packet Storm
268642 3.7 LOW
Network
ibm websphere_commerce IBM WebSphere Commerce 6.x through 6.0.0.11, 7.x through 7.0.0.9, and 8.x before 8.0.0.3 allows remote attackers to cause a denial of service (order-processing outage) via unspecified vectors. CWE-284
Improper Access Control
CVE-2016-0208 2024-11-21 11:41 2016-03-14 Show GitHub Exploit DB Packet Storm
268643 7.8 HIGH
Local
microsoft word
word_for_mac
office
sharepoint_server
office_web_apps_server
office_compatibility_pack
word_viewer
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Viewer, Word Automation … CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2016-0134 2024-11-21 11:41 2016-03-9 Show GitHub Exploit DB Packet Storm
268644 6.8 MEDIUM
Physics
microsoft windows_rt_8.1
windows_7
windows_10
windows_8.1
windows_server_2008
windows_vista
The USB Mass Storage Class driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold … CWE-264
Permissions, Privileges, and Access Controls
CVE-2016-0133 2024-11-21 11:41 2016-03-9 Show GitHub Exploit DB Packet Storm
268645 9.8 CRITICAL
Network
microsoft .net_framework Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 mishandles signature validation for unspecified elements of XML documents, which allows remote attackers to spoof signatur… CWE-20
 Improper Input Validation 
CVE-2016-0132 2024-11-21 11:41 2016-03-9 Show GitHub Exploit DB Packet Storm
268646 7.5 HIGH
Network
microsoft edge Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Edge Memory Corruption Vulnerability," a diffe… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2016-0130 2024-11-21 11:41 2016-03-9 Show GitHub Exploit DB Packet Storm
268647 7.5 HIGH
Network
microsoft edge Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Edge Memory Corruption Vulnerability," a diffe… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2016-0129 2024-11-21 11:41 2016-03-9 Show GitHub Exploit DB Packet Storm
268648 3.1 LOW
Network
microsoft edge Microsoft Edge mishandles the Referer policy, which allows remote attackers to obtain sensitive browser-history and request information via a crafted HTTPS web site, aka "Microsoft Edge Information D… CWE-200
Information Exposure
CVE-2016-0125 2024-11-21 11:41 2016-03-9 Show GitHub Exploit DB Packet Storm
268649 7.5 HIGH
Network
microsoft edge Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Edge Memory Corruption Vulnerability," a diffe… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2016-0124 2024-11-21 11:41 2016-03-9 Show GitHub Exploit DB Packet Storm
268650 7.5 HIGH
Network
microsoft edge Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Edge Memory Corruption Vulnerability," a diffe… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2016-0123 2024-11-21 11:41 2016-03-9 Show GitHub Exploit DB Packet Storm