Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 10, 2026, noon

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
241611 5 警告 Coppermine Photo Gallery - CPG における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2008-7187 2012-06-26 16:10 2009-09-9 Show GitHub Exploit DB Packet Storm
241612 5 警告 Coppermine Photo Gallery - Coppermine Photo Gallery (CPG) におけるデータベーステーブルの接頭語などの重要な情報を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-7186 2012-06-26 16:10 2009-09-9 Show GitHub Exploit DB Packet Storm
241613 4.3 警告 GNOME Project - GNOME Rhythmbox におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2008-7185 2012-06-26 16:10 2009-09-8 Show GitHub Exploit DB Packet Storm
241614 4.3 警告 diigo - Diigo Toolbar および Diigolet におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-7184 2012-06-26 16:10 2009-09-8 Show GitHub Exploit DB Packet Storm
241615 6.8 警告 evacms - EVA CMS の eva/index.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2008-7183 2012-06-26 16:10 2009-09-8 Show GitHub Exploit DB Packet Storm
241616 7.5 危険 butterflymedia - Butterfly Organizer における任意のアカウントを削除される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-7181 2012-06-26 16:10 2009-09-8 Show GitHub Exploit DB Packet Storm
241617 6.8 警告 celina jorge - Facil CMS におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-7176 2012-06-26 16:10 2009-09-8 Show GitHub Exploit DB Packet Storm
241618 4.3 警告 Imagely
WordPress.org
- Wordpress の NextGEN Gallery プラグインの wp-admin/admin.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-7175 2012-06-26 16:10 2009-09-8 Show GitHub Exploit DB Packet Storm
241619 10 危険 gameservers - GSC における任意の管理者コマンドを実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-7170 2012-06-26 16:10 2009-09-8 Show GitHub Exploit DB Packet Storm
241620 5 警告 BitTorrent, Inc. - BitTorrent および uTorrent の Web インターフェースにおけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-7166 2012-06-26 16:10 2009-09-4 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 10, 2026, 4:58 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
267071 9.8 CRITICAL
Network
zend zend_framework
zend-mail
The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework before 2.4.11 might allow remote attackers to pass extr… CWE-77
Command Injection
CVE-2016-10034 2024-11-21 11:43 2016-12-31 Show GitHub Exploit DB Packet Storm
267072 7.0 HIGH
Local
linux linux_kernel The sg implementation in the Linux kernel through 4.9 does not properly restrict write operations in situations where the KERNEL_DS option is set, which allows local users to read or write to arbitra… CWE-416
 Use After Free
CVE-2016-10088 2024-11-21 11:43 2016-12-31 Show GitHub Exploit DB Packet Storm
267073 7.2 HIGH
Network
piwigo piwigo admin/languages.php in Piwigo through 2.8.3 allows remote authenticated administrators to conduct File Inclusion attacks via the tab parameter. CWE-284
Improper Access Control
CVE-2016-10085 2024-11-21 11:43 2016-12-30 Show GitHub Exploit DB Packet Storm
267074 7.2 HIGH
Network
piwigo piwigo admin/batch_manager.php in Piwigo through 2.8.3 allows remote authenticated administrators to conduct File Inclusion attacks via the $page['tab'] variable (aka the mode parameter). CWE-284
Improper Access Control
CVE-2016-10084 2024-11-21 11:43 2016-12-30 Show GitHub Exploit DB Packet Storm
267075 6.1 MEDIUM
Network
piwigo piwigo Cross-site scripting (XSS) vulnerability in admin/plugin.php in Piwigo through 2.8.3 allows remote attackers to inject arbitrary web script or HTML via a crafted filename that is mishandled in a cert… CWE-79
Cross-site Scripting
CVE-2016-10083 2024-11-21 11:43 2016-12-30 Show GitHub Exploit DB Packet Storm
267076 9.8 CRITICAL
Network
s9y serendipity include/functions_installer.inc.php in Serendipity through 2.0.5 is vulnerable to File Inclusion and a possible Code Execution attack during a first-time installation because it fails to sanitize the… CWE-284
Improper Access Control
CVE-2016-10082 2024-11-21 11:43 2016-12-30 Show GitHub Exploit DB Packet Storm
267077 7.8 HIGH
Local
shutter-project shutter /usr/bin/shutter in Shutter through 0.93.1 allows user-assisted remote attackers to execute arbitrary commands via a crafted image name that is mishandled during a "Run a plugin" action. CWE-19
 Data Processing Errors
CVE-2016-10081 2024-11-21 11:43 2016-12-30 Show GitHub Exploit DB Packet Storm
267078 7.5 HIGH
Local
wampserver wampserver WampServer 3.0.6 has two files called 'wampmanager.exe' and 'unins000.exe' with a weak ACL for Modify. This could potentially allow an authorized but non-privileged local user to execute arbitrary co… CWE-264
Permissions, Privileges, and Access Controls
CVE-2016-10072 2024-11-21 11:43 2016-12-27 Show GitHub Exploit DB Packet Storm
267079 7.5 HIGH
Local
wampserver wampserver WampServer 3.0.6 installs two services called 'wampapache' and 'wampmysqld' with weak file permissions, running with SYSTEM privileges. This could potentially allow an authorized but non-privileged l… CWE-264
Permissions, Privileges, and Access Controls
CVE-2016-10031 2024-11-21 11:43 2016-12-27 Show GitHub Exploit DB Packet Storm
267080 6.1 MEDIUM
Network
antisamy_project antisamy In OWASP AntiSamy before 1.5.5, by submitting a specially crafted input (a tag that supports style with active content), you could bypass the library protections and supply executable code. The impac… CWE-79
Cross-site Scripting
CVE-2016-10006 2024-11-21 11:43 2016-12-25 Show GitHub Exploit DB Packet Storm