Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 10, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
241531 7.5 危険 codefixer - LinksPro Standard Edition の Default.asp における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-0431 2012-06-26 16:10 2009-02-4 Show GitHub Exploit DB Packet Storm
241532 4.3 警告 Activewebsoftwares - Active Bids におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-0430 2012-06-26 16:10 2009-02-4 Show GitHub Exploit DB Packet Storm
241533 7.5 危険 Activewebsoftwares - Active Bids における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-0429 2012-06-26 16:10 2009-02-4 Show GitHub Exploit DB Packet Storm
241534 7.5 危険 DMXReady - DMXReady Secure Document Library の CategoryManager/upload_image_category.asp における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-0428 2012-06-26 16:10 2009-02-4 Show GitHub Exploit DB Packet Storm
241535 7.5 危険 DMXReady - DMXReady Member Directory Manager の CategoryManager/upload_image_category.asp における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-0427 2012-06-26 16:10 2009-02-4 Show GitHub Exploit DB Packet Storm
241536 7.5 危険 DMXReady - DMXReady Classified Listings Manager の CategoryManager/upload_image_category.asp における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-0426 2012-06-26 16:10 2009-02-4 Show GitHub Exploit DB Packet Storm
241537 7.5 危険 blue eye cms - Blue Eye CMS の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-0425 2012-06-26 16:10 2009-02-4 Show GitHub Exploit DB Packet Storm
241538 4.3 警告 an guestbook - AN Guestbook (ANG) の sign1.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-0424 2012-06-26 16:10 2009-02-4 Show GitHub Exploit DB Packet Storm
241539 4.3 警告 agavi - Agavi の AgaviWebRouting::gen(null) メソッドにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-0417 2012-06-26 16:10 2009-02-10 Show GitHub Exploit DB Packet Storm
241540 7.5 危険 community cms - Community CMS の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-0406 2012-06-26 16:10 2009-02-3 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 10, 2026, 4:58 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
267061 9.8 CRITICAL
Network
western_digital mycloud_nas Unauthenticated Remote Command injection as root occurs in the Western Digital MyCloud NAS 2.11.142 /web/google_analytics.php URL via a modified arg parameter in the POST data. CWE-77
Command Injection
CVE-2016-10108 2024-11-21 11:43 2017-01-3 Show GitHub Exploit DB Packet Storm
267062 9.8 CRITICAL
Network
western_digital mycloud_nas Unauthenticated Remote Command injection as root occurs in the Western Digital MyCloud NAS 2.11.142 index.php page via a modified Cookie header. CWE-77
Command Injection
CVE-2016-10107 2024-11-21 11:43 2017-01-3 Show GitHub Exploit DB Packet Storm
267063 6.5 MEDIUM
Network
netgear fvs336gv3_firmware
srx5308_firmware
fvs318gv2_firmware
fvs318n_firmware
Directory traversal vulnerability in scgi-bin/platform.cgi on NETGEAR FVS336Gv3, FVS318N, FVS318Gv2, and SRX5308 devices with firmware before 4.3.3-8 allows remote authenticated users to read arbitra… CWE-22
Path Traversal
CVE-2016-10106 2024-11-21 11:43 2017-01-3 Show GitHub Exploit DB Packet Storm
267064 9.8 CRITICAL
Network
piwigo piwigo admin/plugin.php in Piwigo through 2.8.3 doesn't validate the sections variable while using it to include files. This can cause information disclosure and code execution if it contains a .. sequence. CWE-200
CWE-284
Information Exposure
Improper Access Control
CVE-2016-10105 2024-11-21 11:43 2017-01-3 Show GitHub Exploit DB Packet Storm
267065 5.3 MEDIUM
Network
borg borg Borg (aka BorgBackup) before 1.0.9 has a flaw in the way duplicate archive names were processed during manifest recovery, potentially allowing an attacker to overwrite an archive. CWE-20
 Improper Input Validation 
CVE-2016-10100 2024-11-21 11:43 2017-01-3 Show GitHub Exploit DB Packet Storm
267066 5.3 MEDIUM
Network
borg_project borg Borg (aka BorgBackup) before 1.0.9 has a flaw in the cryptographic protocol used to authenticate the manifest (list of archives), potentially allowing an attacker to spoof the list of archives. CWE-310
Cryptographic Issues
CVE-2016-10099 2024-11-21 11:43 2017-01-3 Show GitHub Exploit DB Packet Storm
267067 7.5 HIGH
Network
forgerock openam XML External Entity (XXE) Vulnerability in /SSOPOST/metaAlias/%realm%/idpv2 in OpenAM - Access Management 10.1.0 allows remote attackers to read arbitrary files via the SAMLRequest parameter. CWE-611
XXE
CVE-2016-10097 2024-11-21 11:43 2017-01-2 Show GitHub Exploit DB Packet Storm
267068 7.3 HIGH
Network
genixcms genixcms SQL injection vulnerability in register.php in GeniXCMS before 1.0.0 allows remote attackers to execute arbitrary SQL commands via the activation parameter. CWE-89
SQL Injection
CVE-2016-10096 2024-11-21 11:43 2017-01-2 Show GitHub Exploit DB Packet Storm
267069 9.8 CRITICAL
Network
swiftmailer swiftmailer The mail transport (aka Swift_Transport_MailTransport) in Swift Mailer before 5.4.5 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code v… CWE-77
Command Injection
CVE-2016-10074 2024-11-21 11:43 2016-12-31 Show GitHub Exploit DB Packet Storm
267070 9.8 CRITICAL
Network
phpmailer_project
wordpress
joomla
phpmailer
wordpress
joomla\!
The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code by leveraging improper interaction be… CWE-77
Command Injection
CVE-2016-10045 2024-11-21 11:43 2016-12-31 Show GitHub Exploit DB Packet Storm