Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 21, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
242761 5.8 警告 Best Practical Solutions - Best Practical Solutions RT の html/Elements/SetupSessionCookie におけるセッションをハイジャックされるの脆弱性 CWE-287
不適切な認証
CVE-2009-4151 2012-06-26 16:18 2009-11-30 Show GitHub Exploit DB Packet Storm
242762 9.3 危険 daz3d - DAZ Studio における任意の JavaScript コードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2009-4148 2012-06-26 16:18 2009-12-4 Show GitHub Exploit DB Packet Storm
242763 7.2 危険 FreeBSD - FreeBSD の libexec/rtld-elf/rtld.c における権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2009-4147 2012-06-26 16:18 2009-12-2 Show GitHub Exploit DB Packet Storm
242764 7.2 危険 FreeBSD - FreeBSD の libexec/rtld-elf/rtld.c における権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2009-4146 2012-06-26 16:18 2009-12-2 Show GitHub Exploit DB Packet Storm
242765 4.4 警告 GNU Project - GNU coreutils の dist-check.mk の distcheck rule における権限を取得される脆弱性 CWE-59
リンク解釈の問題
CVE-2009-4135 2012-06-26 16:18 2009-12-5 Show GitHub Exploit DB Packet Storm
242766 6.5 警告 Condor Project
レッドハット
- MRG の Grid Execute Node で使用される Condor における権限を取得される脆弱性 CWE-noinfo
情報不足
CVE-2009-4133 2012-06-26 16:18 2009-12-23 Show GitHub Exploit DB Packet Storm
242767 7.2 危険 GNU Project - GNU GRUB における認証を回避される脆弱性 CWE-287
不適切な認証
CVE-2009-4128 2012-06-26 16:18 2009-12-1 Show GitHub Exploit DB Packet Storm
242768 4.3 警告 Drupal
Alex Barth
- Drupal の Feed Element Mapper におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4119 2012-06-26 16:18 2009-11-30 Show GitHub Exploit DB Packet Storm
242769 9.3 危険 Mozilla Foundation
didier ernotte
- Firefox の infoRSS におけるクロスドメインスクリプティング攻撃を実行される脆弱性 CWE-20
不適切な入力確認
CVE-2009-4101 2012-06-26 16:18 2009-07-3 Show GitHub Exploit DB Packet Storm
242770 7.5 危険 Joomla!
g4j.laoneo
- Joomla! 用 Google Calendar GCalendar コンポーネンにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-4099 2012-06-26 16:18 2009-11-29 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 21, 2026, 4:10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
267351 9.8 CRITICAL
Network
advantech vesp211-eu_firmware
vesp211-232_firmware
The web interface on Advantech/B+B SmartWorx VESP211-EU devices with firmware 1.7.2 and VESP211-232 devices with firmware 1.5.1 and 1.7.2 relies on the client to implement access control, which allow… CWE-284
Improper Access Control
CVE-2016-2275 2024-11-21 11:48 2016-02-21 Show GitHub Exploit DB Packet Storm
267352 5.5 MEDIUM
Local
xen xen VMX in Xen 4.6.x and earlier, when using an Intel or Cyrix CPU, allows local HVM guest users to cause a denial of service (guest crash) via vectors related to a non-canonical RIP. NVD-CWE-Other
CVE-2016-2271 2024-11-21 11:48 2016-02-20 Show GitHub Exploit DB Packet Storm
267353 6.8 MEDIUM
Network
debian
fedoraproject
xen
oracle
debian_linux
fedora
xen
vm_server
Xen 4.6.x and earlier allows local guest administrators to cause a denial of service (host reboot) via vectors related to multiple mappings of MMIO pages with different cachability settings. CWE-20
 Improper Input Validation 
CVE-2016-2270 2024-11-21 11:48 2016-02-20 Show GitHub Exploit DB Packet Storm
267354 5.3 MEDIUM
Adjacent
belden hirschmann_firmware
hirschmann_l2b
The password-sync feature on Belden Hirschmann Classic Platform switches L2B before 05.3.07 and L2E, L2P, L3E, and L3P before 09.0.06 sets an SNMP community to the same string as the administrator pa… CWE-200
Information Exposure
CVE-2016-2509 2024-11-21 11:48 2016-02-19 Show GitHub Exploit DB Packet Storm
267355 6.5 MEDIUM
Adjacent
comcast xfinity_home_security_system Comcast XFINITY Home Security System does not properly maintain base-station communication, which allows physically proximate attackers to defeat sensor functionality by interfering with ZigBee 2.4 G… CWE-254
 7PK - Security Features
CVE-2016-2398 2024-11-21 11:48 2016-02-18 Show GitHub Exploit DB Packet Storm
267356 9.8 CRITICAL
Network
sonicwall uma_em5000_firmware
analyzer
global_management_system
The cliserver implementation in Dell SonicWALL GMS, Analyzer, and UMA EM5000 7.2, 8.0, and 8.1 before Hotfix 168056 allows remote attackers to deserialize and execute arbitrary Java code via crafted … CWE-77
Command Injection
CVE-2016-2397 2024-11-21 11:48 2016-02-18 Show GitHub Exploit DB Packet Storm
267357 9.9 CRITICAL
Network
sonicwall analyzer
global_management_system
uma_em5000_firmware
The GMS ViewPoint (GMSVP) web application in Dell SonicWALL GMS, Analyzer, and UMA EM5000 7.2, 8.0, and 8.1 before Hotfix 168056 allows remote authenticated users to execute arbitrary commands via ve… CWE-77
Command Injection
CVE-2016-2396 2024-11-21 11:48 2016-02-18 Show GitHub Exploit DB Packet Storm
267358 7.5 HIGH
Network
sap netweaver Directory traversal vulnerability in the GetFileList function in the SAP Manufacturing Integration and Intelligence (xMII) component 15.0 for SAP NetWeaver 7.4 allows remote attackers to read arbitra… CWE-22
Path Traversal
CVE-2016-2389 2024-11-21 11:48 2016-02-17 Show GitHub Exploit DB Packet Storm
267359 6.1 MEDIUM
Network
sap netweaver Multiple cross-site scripting (XSS) vulnerabilities in the Java Proxy Runtime ProxyServer servlet in SAP NetWeaver 7.4 allow remote attackers to inject arbitrary web script or HTML via the (1) ns or … CWE-79
Cross-site Scripting
CVE-2016-2387 2024-11-21 11:48 2016-02-17 Show GitHub Exploit DB Packet Storm
267360 4.9 MEDIUM
Network
huawei mt882_firmware GlobespanVirata ftpd 1.0, as used on Huawei SmartAX MT882 devices V200R002B022 Arg, allows remote authenticated users to cause a denial of service (device outage) by using the FTP MKD command to crea… CWE-17
Code
CVE-2016-2314 2024-11-21 11:48 2016-02-15 Show GitHub Exploit DB Packet Storm