Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 16, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
241971 6.8 警告 Joomla!
Blue Constant Media Ltd
- Joomla! 用の DJ-Catalog コンポーネントにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-3661 2012-06-26 16:18 2009-10-11 Show GitHub Exploit DB Packet Storm
241972 6.8 警告 eFront Learning - Efront の libraries/database.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2009-3660 2012-06-26 16:18 2009-10-11 Show GitHub Exploit DB Packet Storm
241973 9.3 危険 AOL - AOL の sb.dll における任意のコードを実行される脆弱性 CWE-399
リソース管理の問題
CVE-2009-3658 2012-06-26 16:18 2009-10-9 Show GitHub Exploit DB Packet Storm
241974 6.4 警告 Drupal
316solutions
- Drupal 用の Boost モジュールにおける新しい webroot ディレクトリを生成される脆弱性 CWE-Other
その他
CVE-2009-3654 2012-06-26 16:18 2009-09-30 Show GitHub Exploit DB Packet Storm
241975 3.5 注意 Drupal
darren oh
- Drupal 用モジュールの XML Sitemap の追加リンクインターフェースにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-3653 2012-06-26 16:18 2009-09-30 Show GitHub Exploit DB Packet Storm
241976 4.3 警告 Drupal
david strauss
- Drupa のモジュールの Dex におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-3650 2012-06-26 16:18 2009-09-30 Show GitHub Exploit DB Packet Storm
241977 3.5 注意 Drupal
apsivam
- Drupal のモジュールの Service Links におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-3648 2012-06-26 16:18 2009-10-9 Show GitHub Exploit DB Packet Storm
241978 5 警告 dxmsoft - Dxmsoft XM Easy Personal FTP Server におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2009-3643 2012-06-26 16:18 2009-10-9 Show GitHub Exploit DB Packet Storm
241979 7.5 危険 frontrange - FrontRange HEAT の Call Logging 機能における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-3642 2012-06-26 16:18 2009-10-9 Show GitHub Exploit DB Packet Storm
241980 4.3 警告 derrick oswald - HTML-Parser の decode_entities 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2009-3627 2012-06-26 16:18 2009-10-29 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 16, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
266831 5.3 MEDIUM
Network
google
mozilla
android
firefox
Mozilla Firefox before 44.0 on Android does not ensure that HTTPS is used for a lightweight-theme installation, which allows man-in-the-middle attackers to replace a theme's images and colors by modi… CWE-310
Cryptographic Issues
CVE-2016-1948 2024-11-21 11:47 2016-02-1 Show GitHub Exploit DB Packet Storm
266832 4.7 MEDIUM
Network
canonical
opensuse
mozilla
ubuntu_linux
leap
opensuse
firefox
Mozilla Firefox 43.x mishandles attempts to connect to the Application Reputation service, which makes it easier for remote attackers to trigger an unintended download by leveraging the absence of re… CWE-19
 Data Processing Errors
CVE-2016-1947 2024-11-21 11:47 2016-02-1 Show GitHub Exploit DB Packet Storm
266833 9.8 CRITICAL
Network
opensuse
mozilla
leap
opensuse
firefox
The MoofParser::Metadata function in binding/MoofParser.cpp in libstagefright in Mozilla Firefox before 44.0 does not limit the size of read operations, which might allow remote attackers to cause a … CWE-119
CWE-189
Incorrect Access of Indexable Resource ('Range Error') 
Numeric Errors
CVE-2016-1946 2024-11-21 11:47 2016-02-1 Show GitHub Exploit DB Packet Storm
266834 8.8 HIGH
Network
mozilla
opensuse
firefox
leap
opensuse
The nsZipArchive function in Mozilla Firefox before 44.0 might allow remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging incorrect use of a pointer d… NVD-CWE-noinfo
CVE-2016-1945 2024-11-21 11:47 2016-02-1 Show GitHub Exploit DB Packet Storm
266835 9.8 CRITICAL
Network
mozilla
opensuse
firefox
leap
opensuse
The Buffer11::NativeBuffer11::map function in ANGLE, as used in Mozilla Firefox before 44.0, might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2016-1944 2024-11-21 11:47 2016-02-1 Show GitHub Exploit DB Packet Storm
266836 4.7 MEDIUM
Network
opensuse
mozilla
google
leap
opensuse
firefox
android
Mozilla Firefox before 44.0 on Android allows remote attackers to spoof the address bar via the scrollTo method. CWE-17
Code
CVE-2016-1943 2024-11-21 11:47 2016-02-1 Show GitHub Exploit DB Packet Storm
266837 7.4 HIGH
Network
opensuse
mozilla
leap
opensuse
firefox
Mozilla Firefox before 44.0 allows user-assisted remote attackers to spoof a trailing substring in the address bar by leveraging a user's paste of a (1) wyciwyg: URI or (2) resource: URI. CWE-20
 Improper Input Validation 
CVE-2016-1942 2024-11-21 11:47 2016-02-1 Show GitHub Exploit DB Packet Storm
266838 6.1 MEDIUM
Network
apple
mozilla
mac_os_x
firefox
The file-download dialog in Mozilla Firefox before 44.0 on OS X enables a certain button too quickly, which allows remote attackers to conduct clickjacking attacks via a crafted web site that trigger… CWE-79
Cross-site Scripting
CVE-2016-1941 2024-11-21 11:47 2016-02-1 Show GitHub Exploit DB Packet Storm
266839 5.3 MEDIUM
Network
google
mozilla
android
firefox
Mozilla Firefox before 44.0 on Android allows remote attackers to spoof the address bar via a data: URL that is mishandled during (1) shortcut opening or (2) BOOKMARK intent processing. CWE-17
Code
CVE-2016-1940 2024-11-21 11:47 2016-02-1 Show GitHub Exploit DB Packet Storm
266840 5.3 MEDIUM
Network
opensuse
mozilla
leap
opensuse
firefox
Mozilla Firefox before 44.0 stores cookies with names containing vertical tab characters, which allows remote attackers to obtain sensitive information by reading HTTP Cookie headers. NOTE: this vul… CWE-200
Information Exposure
CVE-2016-1939 2024-11-21 11:47 2016-02-1 Show GitHub Exploit DB Packet Storm