Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 21, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
242781 9 危険 The Cacti Group - Cacti における権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2009-4112 2012-06-26 16:18 2009-11-30 Show GitHub Exploit DB Packet Storm
242782 4.3 警告 DNN - DotNetNuke の search 機能におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4110 2012-06-26 16:18 2009-11-26 Show GitHub Exploit DB Packet Storm
242783 5 警告 DNN - DotNetNuke のインストールウィザードにおけるバージョン情報などの重要な情報へアクセスされる脆弱性 CWE-200
情報漏えい
CVE-2009-4109 2012-06-26 16:18 2009-11-26 Show GitHub Exploit DB Packet Storm
242784 4 警告 dxm2008 - XM Easy Personal FTP Server におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2009-4108 2012-06-26 16:18 2009-11-29 Show GitHub Exploit DB Packet Storm
242785 9.3 危険 amplusnet - Invisible Browsing におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-4107 2012-06-26 16:18 2009-11-29 Show GitHub Exploit DB Packet Storm
242786 7.5 危険 Debian - Lintian における任意のコマンドを実行される脆弱性 CWE-89
SQLインジェクション
CVE-2009-4015 2012-06-26 16:18 2010-01-27 Show GitHub Exploit DB Packet Storm
242787 4.3 警告 GForge Group - GForge におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4069 2012-06-26 16:18 2009-11-24 Show GitHub Exploit DB Packet Storm
242788 6.8 警告 Drupal
paul beaney
- Drupal 用の PHPList Integration モジュールの "My Account" 機能におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2009-4066 2012-06-26 16:18 2009-11-18 Show GitHub Exploit DB Packet Storm
242789 4.3 警告 Ezra Barnett Gildesgame
Drupal
- Drupal の OG モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4063 2012-06-26 16:18 2009-11-4 Show GitHub Exploit DB Packet Storm
242790 4.3 警告 Drupal
anon-design
- Drupal の Printfriendly モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4062 2012-06-26 16:18 2009-11-18 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 21, 2026, 4:10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
268011 7.5 HIGH
Network
cisco telepresence_video_communication_server Cisco TelePresence Video Communications Server (VCS) X8.x before X8.7.2 allows remote attackers to cause a denial of service (service disruption) via a crafted URI in a SIP header, aka Bug ID CSCuy43… CWE-20
 Improper Input Validation 
CVE-2016-1400 2024-11-21 11:46 2016-05-25 Show GitHub Exploit DB Packet Storm
268012 7.5 HIGH
Network
cisco web_security_appliance_\(wsa\) Memory leak in Cisco AsyncOS through 8.8 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (memory consumption) via an unspecified HTTP status code, aka Bug… CWE-399
 Resource Management Errors
CVE-2016-1383 2024-11-21 11:46 2016-05-25 Show GitHub Exploit DB Packet Storm
268013 7.5 HIGH
Network
cisco web_security_appliance_\(wsa\) Cisco AsyncOS before 8.5.3-069 and 8.6 through 8.8 on Web Security Appliance (WSA) devices mishandles memory allocation for HTTP requests, which allows remote attackers to cause a denial of service (… CWE-20
 Improper Input Validation 
CVE-2016-1382 2024-11-21 11:46 2016-05-25 Show GitHub Exploit DB Packet Storm
268014 7.5 HIGH
Network
cisco web_security_appliance Memory leak in Cisco AsyncOS 8.5 through 9.0 before 9.0.1-162 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (memory consumption) via an HTTP file-range … CWE-399
 Resource Management Errors
CVE-2016-1381 2024-11-21 11:46 2016-05-25 Show GitHub Exploit DB Packet Storm
268015 7.5 HIGH
Network
cisco web_security_appliance Cisco AsyncOS 8.0 before 8.0.6-119 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (proxy-process hang) via a crafted HTTP POST request, aka Bug ID CSCuo1… CWE-20
 Improper Input Validation 
CVE-2016-1380 2024-11-21 11:46 2016-05-25 Show GitHub Exploit DB Packet Storm
268016 6.1 MEDIUM
Network
wordpress wordpress Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/class-wp-theme.php in WordPress before 4.4.1 allow remote attackers to inject arbitrary web script or HTML via a (1) stylesheet name… CWE-79
Cross-site Scripting
CVE-2016-1564 2024-11-21 11:46 2016-05-22 Show GitHub Exploit DB Packet Storm
268017 7.5 HIGH
Network
cisco identity_services_engine_software The Active Directory (AD) integration component in Cisco Identity Service Engine (ISE) before 1.2.0.899 patch 7, when AD group-membership authorization is enabled, allows remote attackers to cause a … CWE-287
CWE-119
Improper Authentication
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2016-1402 2024-11-21 11:46 2016-05-21 Show GitHub Exploit DB Packet Storm
268018 6.1 MEDIUM
Network
cisco unified_computing_system_central_software Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unified Computing System (UCS) Central Software 1.4(1a) allows remote attackers to inject arbitrary web script or HTML vi… CWE-79
Cross-site Scripting
CVE-2016-1401 2024-11-21 11:46 2016-05-21 Show GitHub Exploit DB Packet Storm
268019 7.8 HIGH
Local
apple itunes Untrusted search path vulnerability in the installer in Apple iTunes before 12.4 allows local users to gain privileges via a Trojan horse DLL in the current working directory. CWE-264
Permissions, Privileges, and Access Controls
CVE-2016-1742 2024-11-21 11:46 2016-05-20 Show GitHub Exploit DB Packet Storm
268020 8.1 HIGH
Network
google chrome Google Chrome before 50.0.2661.102 on Android mishandles / (slash) and \ (backslash) characters, which allows attackers to conduct directory traversal attacks via a file: URL, related to net/base/esc… CWE-22
Path Traversal
CVE-2016-1671 2024-11-21 11:46 2016-05-15 Show GitHub Exploit DB Packet Storm