Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 20, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
242781 7.5 危険 classified-software
68classifieds
- Super Mod System の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-3224 2012-06-26 16:18 2009-09-16 Show GitHub Exploit DB Packet Storm
242782 4.3 警告 freewebscriptz - FWSHT の index.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-3222 2012-06-26 16:18 2009-09-16 Show GitHub Exploit DB Packet Storm
242783 9.3 危険 basicunivers.free.fr - ALP におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-3221 2012-06-26 16:18 2009-09-16 Show GitHub Exploit DB Packet Storm
242784 9.3 危険 broid - broid におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-3213 2012-06-26 16:18 2009-09-16 Show GitHub Exploit DB Packet Storm
242785 6.8 警告 dimofinf - VivaPrograms Infinity Script における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-3212 2012-06-26 16:18 2009-09-16 Show GitHub Exploit DB Packet Storm
242786 6.8 警告 dimofinf - VivaPrograms Infinity Script におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2009-3211 2012-06-26 16:18 2009-09-16 Show GitHub Exploit DB Packet Storm
242787 6.8 警告 Drupal
drewish
- Drupal の ImageCache モジュールにおける任意のイメージを表示される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2009-3207 2012-06-26 16:18 2009-08-19 Show GitHub Exploit DB Packet Storm
242788 3.5 注意 Drupal
drewish
- Drupal の ImageCache モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-3206 2012-06-26 16:18 2009-08-19 Show GitHub Exploit DB Packet Storm
242789 7.5 危険 cbauthority - CBAuthority の main.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-3205 2012-06-26 16:18 2009-09-16 Show GitHub Exploit DB Packet Storm
242790 7.5 危険 aj square - AJ Auction Pro OOPD の store.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-3203 2012-06-26 16:18 2009-09-16 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 20, 2026, 4:14 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
267291 7.8 HIGH
Local
apache
debian
pdfbox
debian_linux
Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize the XML parsers, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted PDF. NVD-CWE-Other
CVE-2016-2175 2024-11-21 11:47 2016-06-2 Show GitHub Exploit DB Packet Storm
267292 7.5 HIGH
Network
hp service_manager HPE Service Manager 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, and 9.41 allows remote attackers to obtain sensitive information via unspecified vectors, related to the Web Client, Service Request Cata… CWE-200
Information Exposure
CVE-2016-2025 2024-11-21 11:47 2016-05-30 Show GitHub Exploit DB Packet Storm
267293 5.5 MEDIUM
Local
hp restful_interface_tool HPE RESTful Interface Tool 1.40 allows local users to obtain sensitive information via unspecified vectors. CWE-200
Information Exposure
CVE-2016-2023 2024-11-21 11:47 2016-05-30 Show GitHub Exploit DB Packet Storm
267294 9.8 CRITICAL
Network
hp release_control The server in HP Release Control 9.13, 9.20, and 9.21 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library. CWE-284
Improper Access Control
CVE-2016-1999 2024-11-21 11:47 2016-05-30 Show GitHub Exploit DB Packet Storm
267295 7.8 HIGH
Local
freebsd freebsd Integer signedness error in the sockargs function in sys/kern/uipc_syscalls.c in FreeBSD 10.1 before p34, 10.2 before p17, and 10.3 before p3 allows local users to cause a denial of service (memory o… CWE-264
Permissions, Privileges, and Access Controls
CVE-2016-1887 2024-11-21 11:47 2016-05-26 Show GitHub Exploit DB Packet Storm
267296 7.8 HIGH
Local
freebsd freebsd Integer signedness error in the genkbd_commonioctl function in sys/dev/kbd/kbd.c in FreeBSD 9.3 before p42, 10.1 before p34, 10.2 before p17, and 10.3 before p3 allows local users to obtain sensitive… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2016-1886 2024-11-21 11:47 2016-05-26 Show GitHub Exploit DB Packet Storm
267297 4.3 MEDIUM
Network
moodle moodle The save_submission function in mod/assign/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allows remote authenticated u… CWE-284
Improper Access Control
CVE-2016-2159 2024-11-21 11:47 2016-05-23 Show GitHub Exploit DB Packet Storm
267298 4.3 MEDIUM
Network
moodle moodle lib/ajax/getnavbranch.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3, when the forcelogin feature is enabled, allows remote attacke… CWE-200
Information Exposure
CVE-2016-2158 2024-11-21 11:47 2016-05-23 Show GitHub Exploit DB Packet Storm
267299 8.8 HIGH
Network
moodle moodle Cross-site request forgery (CSRF) vulnerability in mod/assign/adminmanageplugins.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 all… CWE-352
 Origin Validation Error
CVE-2016-2157 2024-11-21 11:47 2016-05-23 Show GitHub Exploit DB Packet Storm
267300 4.3 MEDIUM
Network
moodle moodle calendar/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 provides calendar-event data without considering whether an act… CWE-200
Information Exposure
CVE-2016-2156 2024-11-21 11:47 2016-05-23 Show GitHub Exploit DB Packet Storm