Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 21, 2026, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
242331 5 警告 cookex
Joomla!
- Joomla! の Cookex Agency ckforms コンポーネントにおけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2010-1345 2012-06-26 16:19 2010-04-9 Show GitHub Exploit DB Packet Storm
242332 7.5 危険 cookex
Joomla!
- Joomla! の Cookex Agency ckforms コンポーネントにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-1344 2012-06-26 16:19 2010-04-9 Show GitHub Exploit DB Packet Storm
242333 7.5 危険 bjsintay - SiteX における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-1343 2012-06-26 16:19 2010-04-9 Show GitHub Exploit DB Packet Storm
242334 6.8 警告 directnews - Direct News における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2010-1342 2012-06-26 16:19 2010-04-9 Show GitHub Exploit DB Packet Storm
242335 5 警告 ermenegildo fiorito - Irmin CMS におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2010-1309 2012-06-26 16:19 2010-04-8 Show GitHub Exploit DB Packet Storm
242336 5 警告 decryptweb
Joomla!
- Joomla! の dwgraphs コンポーネントの dwgraphs.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2010-1302 2012-06-26 16:19 2010-04-7 Show GitHub Exploit DB Packet Storm
242337 7.5 危険 The Cacti Group - Cacti の templates_export.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-1431 2012-06-26 16:19 2009-06-28 Show GitHub Exploit DB Packet Storm
242338 5.1 警告 dynpg - DynPG CMS における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2010-1299 2012-06-26 16:19 2010-04-7 Show GitHub Exploit DB Packet Storm
242339 4.3 警告 bbsxp - BBSXP 2008 SP2 におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-1276 2012-06-26 16:19 2010-04-6 Show GitHub Exploit DB Packet Storm
242340 4.3 警告 bbsxp - BBSXP 2008 の ShowPost.asp におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-1275 2012-06-26 16:19 2010-04-6 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 21, 2026, 4:10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
268701 7.5 HIGH
Network
kddi home_spot_cube_firmware Cross-site request forgery (CSRF) vulnerability on KDDI HOME SPOT CUBE devices before 2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. CWE-352
 Origin Validation Error
CVE-2016-1139 2024-11-21 11:45 2016-01-31 Show GitHub Exploit DB Packet Storm
268702 4.7 MEDIUM
Network
kddi home_spot_cube_firmware CRLF injection vulnerability on KDDI HOME SPOT CUBE devices before 2 allows remote attackers to inject arbitrary HTTP headers via unspecified vectors. NVD-CWE-Other
CVE-2016-1138 2024-11-21 11:45 2016-01-31 Show GitHub Exploit DB Packet Storm
268703 7.4 HIGH
Network
kddi home_spot_cube_firmware Open redirect vulnerability on KDDI HOME SPOT CUBE devices before 2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. NVD-CWE-Other
CVE-2016-1137 2024-11-21 11:45 2016-01-31 Show GitHub Exploit DB Packet Storm
268704 5.4 MEDIUM
Network
kddi home_spot_cube_firmware Cross-site scripting (XSS) vulnerability on KDDI HOME SPOT CUBE devices before 2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. CWE-79
Cross-site Scripting
CVE-2016-1136 2024-11-21 11:45 2016-01-31 Show GitHub Exploit DB Packet Storm
268705 6.1 MEDIUM
Network
buffalotech wmr-300_firmware
wex-300_firmware
wmr-433_firmware
bhr-4grv2_firmware
whr-300hp2_firmware
whr-1166dhp_firmware
whr-600d_firmware
wsr-1166dhp_firmware
Cross-site scripting (XSS) vulnerability on BUFFALO BHR-4GRV2 devices with firmware 1.04 and earlier, WEX-300 devices with firmware 1.90 and earlier, WHR-1166DHP devices with firmware 1.90 and earlie… CWE-79
Cross-site Scripting
CVE-2016-1135 2024-11-21 11:45 2016-01-22 Show GitHub Exploit DB Packet Storm
268706 8.8 HIGH
Network
buffalotech whr-1166dhp_firmware
whr-300hp2_firmware
wmr-300_firmware
bhr-4grv2_firmware
wex-300_firmware
whr-600d_firmware
wmr-433_firmware
wsr-1166dhp_firmware
Cross-site request forgery (CSRF) vulnerability on BUFFALO BHR-4GRV2 devices with firmware 1.04 and earlier, WEX-300 devices with firmware 1.90 and earlier, WHR-1166DHP devices with firmware 1.90 and… CWE-352
 Origin Validation Error
CVE-2016-1134 2024-11-21 11:45 2016-01-22 Show GitHub Exploit DB Packet Storm
268707 9.1 CRITICAL
Network
seeds acmailer Seeds acmailer before 3.8.21 and 3.9.x before 3.9.15 Beta allows remote authenticated users to execute arbitrary OS commands via unspecified vectors. CWE-78
OS Command 
CVE-2016-1142 2024-11-21 11:45 2016-01-16 Show GitHub Exploit DB Packet Storm
268708 3.7 LOW
Network
dena h2o CRLF injection vulnerability in the on_req function in lib/handler/redirect.c in H2O before 1.6.2 and 1.7.x before 1.7.0-beta3 allows remote attackers to inject arbitrary HTTP headers and conduct HTT… NVD-CWE-Other
CVE-2016-1133 2024-11-21 11:45 2016-01-16 Show GitHub Exploit DB Packet Storm
268709 7.8 HIGH
Local
dx_library_project dx_library Buffer overflow in the CL_vsprintf function in Takumi Yamada DX Library before 3.16 allows remote attackers to execute arbitrary code via a crafted string. CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2016-1131 2024-11-21 11:45 2016-01-8 Show GitHub Exploit DB Packet Storm
268710 6.1 MEDIUM
Network
pojo activity_log The aryo-activity-log plugin before 2.3.2 for WordPress has XSS. CWE-79
Cross-site Scripting
CVE-2016-10890 2024-11-21 11:44 2019-08-22 Show GitHub Exploit DB Packet Storm