Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 17, 2026, noon

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
242141 4.3 警告 classifiedphpscript - PHP Open Classifieds Script におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-2785 2012-06-26 16:10 2009-08-17 Show GitHub Exploit DB Packet Storm
242142 7.5 危険 garagesalesjunkie - GarageSales Script の visitor/view.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-2777 2012-06-26 16:10 2009-08-14 Show GitHub Exploit DB Packet Storm
242143 4.3 警告 freearcadescript - Free Arcade Script におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-2771 2012-06-26 16:10 2009-08-14 Show GitHub Exploit DB Packet Storm
242144 7.5 危険 dd-wrt - DD-WRT 24 sp1 の管理 GUI の httpd の httpd.c における設定を変更される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2009-2766 2012-06-26 16:10 2009-07-20 Show GitHub Exploit DB Packet Storm
242145 8.3 危険 dd-wrt - DD-WRT 24 sp1 の管理 GUI の httpd の httpd.c における任意のコマンドを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2009-2765 2012-06-26 16:10 2009-07-20 Show GitHub Exploit DB Packet Storm
242146 7.2 危険 Avira - 複数の Avira 製品で使用されるスケジューラにおける権限を取得される脆弱性 CWE-Other
その他
CVE-2009-2761 2012-06-26 16:10 2009-08-13 Show GitHub Exploit DB Packet Storm
242147 7.5 危険 Achievo - Achievo の get_employee 関数における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-2734 2012-06-26 16:10 2009-10-11 Show GitHub Exploit DB Packet Storm
242148 4.3 警告 Achievo - Achievo におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-2733 2012-06-26 16:10 2009-10-11 Show GitHub Exploit DB Packet Storm
242149 7.8 危険 Digium - 複数の Asterisk 製品における SIP チャネルドライバにおけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2009-2726 2012-06-26 16:10 2009-08-12 Show GitHub Exploit DB Packet Storm
242150 5 警告 Django Software Foundation - Django の core/servers/basehttp.py の Admin メディアハンドラにおける任意のファイルを読まれる脆弱性 CWE-22
パス・トラバーサル
CVE-2009-2659 2012-06-26 16:10 2009-08-4 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 17, 2026, 4:15 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
268651 7.5 HIGH
Network
bouncycastle
debian
legion-of-the-bouncy-castle-java-crytography-api
debian_linux
In the Bouncy Castle JCE Provider version 1.55 and earlier the DSA key pair generator generates a weak private key if used with default values. If the JCA key pair generator is not explicitly initial… CWE-310
Cryptographic Issues
CVE-2016-1000343 2024-11-21 11:43 2018-06-4 Show GitHub Exploit DB Packet Storm
268652 7.5 HIGH
Network
bouncycastle
debian
legion-of-the-bouncy-castle-java-crytography-api
debian_linux
In the Bouncy Castle JCE Provider version 1.55 and earlier ECDSA does not fully validate ASN.1 encoding of signature on verification. It is possible to inject extra elements in the sequence making up… CWE-347
 Improper Verification of Cryptographic Signature
CVE-2016-1000342 2024-11-21 11:43 2018-06-4 Show GitHub Exploit DB Packet Storm
268653 5.9 MEDIUM
Network
bouncycastle
debian
legion-of-the-bouncy-castle-java-crytography-api
debian_linux
In the Bouncy Castle JCE Provider version 1.55 and earlier DSA signature generation is vulnerable to timing attack. Where timings can be closely observed for the generation of signatures, the lack of… CWE-361
 7PK - Time and State
CVE-2016-1000341 2024-11-21 11:43 2018-06-4 Show GitHub Exploit DB Packet Storm
268654 7.5 HIGH
Network
bouncycastle legion-of-the-bouncy-castle-java-crytography-api In the Bouncy Castle JCE Provider versions 1.51 to 1.55, a carry propagation bug was introduced in the implementation of squaring for several raw math classes have been fixed (org.bouncycastle.math.r… CWE-19
 Data Processing Errors
CVE-2016-1000340 2024-11-21 11:43 2018-06-4 Show GitHub Exploit DB Packet Storm
268655 5.3 MEDIUM
Network
bouncycastle
debian
legion-of-the-bouncy-castle-java-crytography-api
debian_linux
In the Bouncy Castle JCE Provider version 1.55 and earlier the primary engine class used for AES was AESFastEngine. Due to the highly table driven approach used in the algorithm it turns out that if … CWE-310
Cryptographic Issues
CVE-2016-1000339 2024-11-21 11:43 2018-06-4 Show GitHub Exploit DB Packet Storm
268656 7.5 HIGH
Network
bouncycastle
redhat
canonical
netapp
legion-of-the-bouncy-castle-java-crytography-api
satellite_capsule
ubuntu_linux
satellite
7-mode_transition_tool
In Bouncy Castle JCE Provider version 1.55 and earlier the DSA does not fully validate ASN.1 encoding of signature on verification. It is possible to inject extra elements in the sequence making up t… CWE-347
 Improper Verification of Cryptographic Signature
CVE-2016-1000338 2024-11-21 11:43 2018-06-2 Show GitHub Exploit DB Packet Storm
268657 9.8 CRITICAL
Network
jfrog artifactory Unrestricted file upload vulnerability in ui/artifact/upload in JFrog Artifactory before 4.16 allows remote attackers to (1) deploy an arbitrary servlet application and execute arbitrary code by uplo… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2016-10036 2024-11-21 11:43 2018-05-2 Show GitHub Exploit DB Packet Storm
268658 9.8 CRITICAL
Network
qualcomm sd_425_firmware
sd_430_firmware
sd_450_firmware
sd_625_firmware
sd_650_firmware
sd_652_firmware
sd_820a_firmware
sd_820_firmware
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 820, and SD 820A, when executing a T… CWE-200
Information Exposure
CVE-2016-10430 2024-11-21 11:43 2018-04-18 Show GitHub Exploit DB Packet Storm
268659 7.5 HIGH
Network
qualcomm sd_425_firmware
sd_430_firmware
sd_450_firmware
sd_625_firmware
sd_650_firmware
sd_652_firmware
sd_820_firmware
sd_820a_firmware
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 820, and SD 820A, HMAC verification … CWE-200
Information Exposure
CVE-2016-10428 2024-11-21 11:43 2018-04-18 Show GitHub Exploit DB Packet Storm
268660 9.8 CRITICAL
Network
qualcomm sd_410_firmware
sd_412_firmware
sd_425_firmware
sd_430_firmware
sd_450_firmware
sd_617_firmware
sd_625_firmware
sd_650_firmware
sd_652_firmware
sd_820a_firmware
sd_810_f…
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile SD 410/12, SD 425, SD 430, SD 450, SD 617, SD 625, SD 650/52, SD 810, SD 820, and … CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2016-10426 2024-11-21 11:43 2018-04-18 Show GitHub Exploit DB Packet Storm