Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 17, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
242171 6.8 警告 chatelao - PHP Address Book における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-2608 2012-06-26 16:10 2009-07-27 Show GitHub Exploit DB Packet Storm
242172 5 警告 brainjar - ASP Football Pool におけるデータベースファイルをダウンロードされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2009-2606 2012-06-26 16:10 2009-07-27 Show GitHub Exploit DB Packet Storm
242173 7.5 危険 Escon Information Consulting - Escon SupportPortal Pro の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-2603 2012-06-26 16:10 2009-07-27 Show GitHub Exploit DB Packet Storm
242174 5 警告 Akiva - Webboard の view.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2009-2600 2012-06-26 16:10 2009-07-27 Show GitHub Exploit DB Packet Storm
242175 4.3 警告 censura - Censura の productSearch.html におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-2595 2012-06-26 16:10 2009-07-24 Show GitHub Exploit DB Packet Storm
242176 4.3 警告 censura - Censura の censura.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-2594 2012-06-26 16:10 2009-07-24 Show GitHub Exploit DB Packet Storm
242177 7.5 危険 censura - Censura の censura.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-2593 2012-06-26 16:10 2009-07-24 Show GitHub Exploit DB Packet Storm
242178 4.3 警告 dragdropcart - DragDropCart におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-2587 2012-06-26 16:10 2009-07-24 Show GitHub Exploit DB Packet Storm
242179 4.3 警告 edgephp - EDGEPHP EZArticles の articles.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-2586 2012-06-26 16:10 2009-07-24 Show GitHub Exploit DB Packet Storm
242180 9.3 危険 アカマイテクノロジーズ - Akamai Download Manager の manager.exe におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-2582 2012-06-26 16:10 2009-07-23 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 17, 2026, 4:15 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
266851 6.1 MEDIUM
Network
huawei agile_controller-campus Cross-site scripting (XSS) vulnerability in an unspecified portal authentication page in Huawei Agile Controller-Campus with software before V100R001C00SPC319 allows remote attackers to inject arbitr… CWE-79
Cross-site Scripting
CVE-2016-2214 2024-11-21 11:48 2016-02-9 Show GitHub Exploit DB Packet Storm
266852 9.8 CRITICAL
Network
openelec openelec OpenELEC and RasPlex devices have a hardcoded password for the root account, which makes it easier for remote attackers to obtain access via an SSH session. CWE-255
Credentials Management
CVE-2016-2230 2024-11-21 11:48 2016-02-9 Show GitHub Exploit DB Packet Storm
266853 5.3 MEDIUM
Network
siemens simatic_s7-1500_cpu_firmware Siemens SIMATIC S7-1500 CPU devices before 1.8.3 allow remote attackers to bypass a replay protection mechanism via packets on TCP port 102. CWE-20
 Improper Input Validation 
CVE-2016-2201 2024-11-21 11:48 2016-02-9 Show GitHub Exploit DB Packet Storm
266854 7.5 HIGH
Network
siemens simatic_s7-1500_cpu_firmware Siemens SIMATIC S7-1500 CPU devices before 1.8.3 allow remote attackers to cause a denial of service (STOP mode transition) via crafted packets on TCP port 102. CWE-20
 Improper Input Validation 
CVE-2016-2200 2024-11-21 11:48 2016-02-9 Show GitHub Exploit DB Packet Storm
266855 6.5 MEDIUM
Network
ffmpeg ffmpeg The jpeg2000_decode_tile function in libavcodec/jpeg2000dec.c in FFmpeg before 2.8.6 allows remote attackers to cause a denial of service (out-of-bounds array read access) via crafted JPEG 2000 data. CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2016-2213 2024-11-21 11:48 2016-02-3 Show GitHub Exploit DB Packet Storm
266856 8.8 HIGH
Network
mcafee vulnerability_manager Multiple cross-site request forgery (CSRF) vulnerabilities in the Organizations and Remediation management page in Enterprise Manager in McAfee Vulnerability Manager (MVM) before 7.5.10 allow remote … CWE-352
 Origin Validation Error
CVE-2016-2199 2024-11-21 11:48 2016-02-2 Show GitHub Exploit DB Packet Storm
266857 - - - In the Linux kernel before 4.8, usb_parse_endpoint in drivers/usb/core/config.c does not validate the wMaxPacketSize field of an endpoint descriptor. NOTE: This vulnerability only affects products th… - CVE-2016-20022 2024-11-21 11:47 2024-06-28 Show GitHub Exploit DB Packet Storm
266858 9.8 CRITICAL
Network
gentoo portage In Gentoo Portage before 3.0.47, there is missing PGP validation of executed code: the standalone emerge-webrsync downloads a .gpgsig file but does not perform signature verification. Unless emerge-w… CWE-347
 Improper Verification of Cryptographic Signature
CVE-2016-20021 2024-11-21 11:47 2024-01-12 Show GitHub Exploit DB Packet Storm
266859 7.5 HIGH
Network
knexjs knex Knex Knex.js through 2.3.0 has a limited SQL injection vulnerability that can be exploited to ignore the WHERE clause of a SQL query. CWE-89
SQL Injection
CVE-2016-20018 2024-11-21 11:47 2022-12-19 Show GitHub Exploit DB Packet Storm
266860 9.8 CRITICAL
Network
dlink dsl-2750b_firmware D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wild in 2016 through 2022. CWE-77
Command Injection
CVE-2016-20017 2024-11-21 11:47 2022-10-19 Show GitHub Exploit DB Packet Storm