Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 9, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
241521 4.3 警告 armorlogic - Profense Web Application Firewall の proxy.html におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-0467 2012-06-26 16:10 2009-02-10 Show GitHub Exploit DB Packet Storm
241522 5.1 警告 Groone's World - Groone GBook の includes/header.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2009-0464 2012-06-26 16:10 2009-02-10 Show GitHub Exploit DB Packet Storm
241523 6.8 警告 Groone's World - Groone GLinks の includes/header.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2009-0463 2012-06-26 16:10 2009-02-10 Show GitHub Exploit DB Packet Storm
241524 7.5 危険 clicktech - ClickTech ClickCart の customer_login_check.asp における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-0462 2012-06-26 16:10 2009-02-10 Show GitHub Exploit DB Packet Storm
241525 2.6 注意 glFusion - glFusion の lib-comment.php の 匿名のコメント機能 におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-0455 2012-06-26 16:10 2009-02-10 Show GitHub Exploit DB Packet Storm
241526 7.5 危険 DMXReady - DMXReady Online Notebook Manager における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-0454 2012-06-26 16:10 2009-02-10 Show GitHub Exploit DB Packet Storm
241527 9.3 危険 blazevideo - BlazeVideo HDTV Player におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-0450 2012-06-26 16:10 2009-02-10 Show GitHub Exploit DB Packet Storm
241528 7.5 危険 ASP indir - MyDesign Sayac の default.asp における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-0447 2012-06-26 16:10 2009-02-10 Show GitHub Exploit DB Packet Storm
241529 7.5 危険 dreampics - Dreampics Gallery Builder の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-0445 2012-06-26 16:10 2009-02-10 Show GitHub Exploit DB Packet Storm
241530 9.3 危険 elecard - Elecard AVC HD PLAYER におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-0443 2012-06-26 16:10 2009-02-10 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 10, 2026, 4:58 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
267071 9.8 CRITICAL
Network
zend zend_framework
zend-mail
The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework before 2.4.11 might allow remote attackers to pass extr… CWE-77
Command Injection
CVE-2016-10034 2024-11-21 11:43 2016-12-31 Show GitHub Exploit DB Packet Storm
267072 7.0 HIGH
Local
linux linux_kernel The sg implementation in the Linux kernel through 4.9 does not properly restrict write operations in situations where the KERNEL_DS option is set, which allows local users to read or write to arbitra… CWE-416
 Use After Free
CVE-2016-10088 2024-11-21 11:43 2016-12-31 Show GitHub Exploit DB Packet Storm
267073 7.2 HIGH
Network
piwigo piwigo admin/languages.php in Piwigo through 2.8.3 allows remote authenticated administrators to conduct File Inclusion attacks via the tab parameter. CWE-284
Improper Access Control
CVE-2016-10085 2024-11-21 11:43 2016-12-30 Show GitHub Exploit DB Packet Storm
267074 7.2 HIGH
Network
piwigo piwigo admin/batch_manager.php in Piwigo through 2.8.3 allows remote authenticated administrators to conduct File Inclusion attacks via the $page['tab'] variable (aka the mode parameter). CWE-284
Improper Access Control
CVE-2016-10084 2024-11-21 11:43 2016-12-30 Show GitHub Exploit DB Packet Storm
267075 6.1 MEDIUM
Network
piwigo piwigo Cross-site scripting (XSS) vulnerability in admin/plugin.php in Piwigo through 2.8.3 allows remote attackers to inject arbitrary web script or HTML via a crafted filename that is mishandled in a cert… CWE-79
Cross-site Scripting
CVE-2016-10083 2024-11-21 11:43 2016-12-30 Show GitHub Exploit DB Packet Storm
267076 9.8 CRITICAL
Network
s9y serendipity include/functions_installer.inc.php in Serendipity through 2.0.5 is vulnerable to File Inclusion and a possible Code Execution attack during a first-time installation because it fails to sanitize the… CWE-284
Improper Access Control
CVE-2016-10082 2024-11-21 11:43 2016-12-30 Show GitHub Exploit DB Packet Storm
267077 7.8 HIGH
Local
shutter-project shutter /usr/bin/shutter in Shutter through 0.93.1 allows user-assisted remote attackers to execute arbitrary commands via a crafted image name that is mishandled during a "Run a plugin" action. CWE-19
 Data Processing Errors
CVE-2016-10081 2024-11-21 11:43 2016-12-30 Show GitHub Exploit DB Packet Storm
267078 7.5 HIGH
Local
wampserver wampserver WampServer 3.0.6 has two files called 'wampmanager.exe' and 'unins000.exe' with a weak ACL for Modify. This could potentially allow an authorized but non-privileged local user to execute arbitrary co… CWE-264
Permissions, Privileges, and Access Controls
CVE-2016-10072 2024-11-21 11:43 2016-12-27 Show GitHub Exploit DB Packet Storm
267079 7.5 HIGH
Local
wampserver wampserver WampServer 3.0.6 installs two services called 'wampapache' and 'wampmysqld' with weak file permissions, running with SYSTEM privileges. This could potentially allow an authorized but non-privileged l… CWE-264
Permissions, Privileges, and Access Controls
CVE-2016-10031 2024-11-21 11:43 2016-12-27 Show GitHub Exploit DB Packet Storm
267080 6.1 MEDIUM
Network
antisamy_project antisamy In OWASP AntiSamy before 1.5.5, by submitting a specially crafted input (a tag that supports style with active content), you could bypass the library protections and supply executable code. The impac… CWE-79
Cross-site Scripting
CVE-2016-10006 2024-11-21 11:43 2016-12-25 Show GitHub Exploit DB Packet Storm