Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 22, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
242731 7.5 危険 esoftpro - Online Guestbook Pro の ogp_show.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-4935 2012-06-26 16:19 2010-07-12 Show GitHub Exploit DB Packet Storm
242732 4.3 警告 esoftpro - Online Photo Pro の index.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4934 2012-06-26 16:19 2010-07-12 Show GitHub Exploit DB Packet Storm
242733 6.8 警告 bestwebsharing - Groovy Media Player におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-4931 2012-06-26 16:19 2010-07-12 Show GitHub Exploit DB Packet Storm
242734 4.3 警告 esoftpro - Online Contact Manager および EContact PRO におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4926 2012-06-26 16:19 2010-07-12 Show GitHub Exploit DB Packet Storm
242735 6.8 警告 creasito - Portale e-commerce Creasito における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-4925 2012-06-26 16:19 2010-07-12 Show GitHub Exploit DB Packet Storm
242736 4.3 警告 dan pascu - Dan Pascu python-cjson における特定のクロスサイトスクリプティング攻撃を誘発する脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4924 2012-06-26 16:19 2010-07-2 Show GitHub Exploit DB Packet Storm
242737 6.8 警告 dootzky - oBlog の admin/index.php における総当りパスワード推測攻撃を実行される脆弱性 CWE-287
不適切な認証
CVE-2009-4909 2012-06-26 16:19 2010-06-25 Show GitHub Exploit DB Packet Storm
242738 4.3 警告 dootzky - oBlog におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4908 2012-06-26 16:19 2010-06-25 Show GitHub Exploit DB Packet Storm
242739 6.8 警告 dootzky - oBlog におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2009-4907 2012-06-26 16:19 2010-06-25 Show GitHub Exploit DB Packet Storm
242740 7.8 危険 シスコシステムズ - Cisco ASA 5580 シリーズの DTLS 実装におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2009-4923 2012-06-26 16:19 2009-04-6 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 23, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
268371 6.1 MEDIUM
Network
cisco ip_interoperability_and_collaboration_system Cross-site scripting (XSS) vulnerability in Cisco IP Interoperability and Collaboration System 4.10(1) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSC… CWE-79
Cross-site Scripting
CVE-2016-1375 2024-11-21 11:46 2016-04-9 Show GitHub Exploit DB Packet Storm
268372 7.0 HIGH
Local
exim exim Exim before 4.86.2, when installed setuid root, allows local users to gain privileges via the perl_startup argument. CWE-264
Permissions, Privileges, and Access Controls
CVE-2016-1531 2024-11-21 11:46 2016-04-8 Show GitHub Exploit DB Packet Storm
268373 8.1 HIGH
Local
redhat
oracle
qemu
openstack
linux
qemu
The (1) fw_cfg_write and (2) fw_cfg_read functions in hw/nvram/fw_cfg.c in QEMU before 2.4, when built with the Firmware Configuration device emulation support, allow guest OS users with the CAP_SYS_… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2016-1714 2024-11-21 11:46 2016-04-8 Show GitHub Exploit DB Packet Storm
268374 6.8 MEDIUM
Network
netapp clustered_data_ontap NetApp Clustered Data ONTAP 8.3.1 does not properly verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafte… CWE-200
CWE-20
Information Exposure
 Improper Input Validation 
CVE-2016-1563 2024-11-21 11:46 2016-04-7 Show GitHub Exploit DB Packet Storm
268375 5.9 MEDIUM
Network
dell
netgear
samsung
zyxel
zzinc
emc_powerscale_onefs
jr6150_firmware
x14j_firmware
gs1900-10hp_firmware
keymouse_firmware
The kernel in Cisco TelePresence Server 3.0 through 4.2(4.18) on Mobility Services Engine (MSE) 8710 devices allows remote attackers to cause a denial of service (panic and reboot) via a crafted sequ… CWE-399
 Resource Management Errors
CVE-2016-1346 2024-11-21 11:46 2016-04-7 Show GitHub Exploit DB Packet Storm
268376 9.8 CRITICAL
Network
cisco ucs_invicta_c3124sa_appliance Cisco UCS Invicta C3124SA Appliance 4.3.1 through 5.0.1, UCS Invicta Scaling System and Appliance, and Whiptail Racerunner improperly store a default SSH private key, which allows remote attackers to… CWE-264
Permissions, Privileges, and Access Controls
CVE-2016-1313 2024-11-21 11:46 2016-04-7 Show GitHub Exploit DB Packet Storm
268377 9.8 CRITICAL
Network
cisco
sun
prime_infrastructure
opensolaris
evolved_programmable_network_manager
Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allow remote attackers to execute arbitrary code via crafted deserialized data in an HTTP POS… CWE-20
 Improper Input Validation 
CVE-2016-1291 2024-11-21 11:46 2016-04-7 Show GitHub Exploit DB Packet Storm
268378 8.1 HIGH
Network
cisco
sun
prime_infrastructure
opensolaris
evolved_programmable_network_manager
The web API in Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allows remote authenticated users to bypass intended RBAC restrictions and gai… CWE-264
Permissions, Privileges, and Access Controls
CVE-2016-1290 2024-11-21 11:46 2016-04-7 Show GitHub Exploit DB Packet Storm
268379 7.5 HIGH
Network
cisco firesight_system_software
asa_with_firepower_services
Cisco FireSIGHT System Software 5.4.0 through 6.0.1 and ASA with FirePOWER Services 5.4.0 through 6.0.0.1 allow remote attackers to bypass malware protection via crafted fields in HTTP headers, aka B… CWE-20
 Improper Input Validation 
CVE-2016-1345 2024-11-21 11:46 2016-04-1 Show GitHub Exploit DB Packet Storm
268380 8.8 HIGH
Network
opensuse
debian
google
opensuse
debian_linux
chrome
The PageCaptureSaveAsMHTMLFunction::ReturnFailure function in browser/extensions/api/page_capture/page_capture_api.cc in Google Chrome before 49.0.2623.108 allows attackers to cause a denial of servi… NVD-CWE-noinfo
CVE-2016-1650 2024-11-21 11:46 2016-03-29 Show GitHub Exploit DB Packet Storm