Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 24, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
242861 4.3 警告 cromosoft - Cromosoft Technologies Facil Helpdesk Lite の kbase/kbase.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4544 2012-06-26 16:19 2010-01-4 Show GitHub Exploit DB Packet Storm
242862 6.8 警告 cromosoft - Cromosoft Technologies Facil Helpdesk Lite の index.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2009-4543 2012-06-26 16:19 2010-01-4 Show GitHub Exploit DB Packet Storm
242863 6.8 警告 bpowerhouse - Mini CMS の page.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-4540 2012-06-26 16:19 2010-01-4 Show GitHub Exploit DB Packet Storm
242864 4.3 警告 Alkacon Software - OpenCMS OAMP Comments モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4505 2012-06-26 16:19 2010-03-26 Show GitHub Exploit DB Packet Storm
242865 5 警告 Boa - Boa におけるウィンドウのタイトルを変更される脆弱性 CWE-20
不適切な入力確認
CVE-2009-4496 2012-06-26 16:19 2010-01-13 Show GitHub Exploit DB Packet Storm
242866 5 警告 AOL - AOLserver におけるファイルを上書きされる脆弱性 CWE-20
不適切な入力確認
CVE-2009-4494 2012-06-26 16:19 2010-01-13 Show GitHub Exploit DB Packet Storm
242867 5 警告 ACME Laboratories - thttpd におけるファイルを上書きされる脆弱性 CWE-20
不適切な入力確認
CVE-2009-4491 2012-06-26 16:19 2010-01-13 Show GitHub Exploit DB Packet Storm
242868 5 警告 ACME Laboratories - mini_httpd におけるファイルを上書きされる脆弱性 CWE-20
不適切な入力確認
CVE-2009-4490 2012-06-26 16:19 2010-01-13 Show GitHub Exploit DB Packet Storm
242869 5 警告 Cherokee Project - Cherokee の header.c におけるウィンドウのタイトルを変更される脆弱性 CWE-20
不適切な入力確認
CVE-2009-4489 2012-06-26 16:19 2010-01-13 Show GitHub Exploit DB Packet Storm
242870 4.3 警告 bloofox - BloofoxCMS の search.5.html におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4522 2012-06-26 16:19 2009-12-31 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 24, 2026, 4:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
268041 9.8 CRITICAL
Network
kubernetes kubernetes Openshift allows remote attackers to gain privileges by updating a build configuration that was created with an allowed type to a type that is not allowed. CWE-264
Permissions, Privileges, and Access Controls
CVE-2016-1906 2024-11-21 11:47 2016-02-4 Show GitHub Exploit DB Packet Storm
268042 7.7 HIGH
Network
kubernetes kubernetes The API server in Kubernetes does not properly check admission control, which allows remote authenticated users to access additional resources via a crafted patched object. CWE-284
Improper Access Control
CVE-2016-1905 2024-11-21 11:47 2016-02-4 Show GitHub Exploit DB Packet Storm
268043 8.8 HIGH
Network
janrain php-openid examples/consumer/common.php in JanRain PHP OpenID library (aka php-openid) improperly checks the openid.realm parameter against the SERVER_NAME element in the SERVER superglobal array, which might a… CWE-284
Improper Access Control
CVE-2016-2049 2024-11-21 11:47 2016-02-2 Show GitHub Exploit DB Packet Storm
268044 5.3 MEDIUM
Network
google
mozilla
android
firefox
Mozilla Firefox before 44.0 on Android does not ensure that HTTPS is used for a lightweight-theme installation, which allows man-in-the-middle attackers to replace a theme's images and colors by modi… CWE-310
Cryptographic Issues
CVE-2016-1948 2024-11-21 11:47 2016-02-1 Show GitHub Exploit DB Packet Storm
268045 4.7 MEDIUM
Network
canonical
opensuse
mozilla
ubuntu_linux
leap
opensuse
firefox
Mozilla Firefox 43.x mishandles attempts to connect to the Application Reputation service, which makes it easier for remote attackers to trigger an unintended download by leveraging the absence of re… CWE-19
 Data Processing Errors
CVE-2016-1947 2024-11-21 11:47 2016-02-1 Show GitHub Exploit DB Packet Storm
268046 9.8 CRITICAL
Network
opensuse
mozilla
leap
opensuse
firefox
The MoofParser::Metadata function in binding/MoofParser.cpp in libstagefright in Mozilla Firefox before 44.0 does not limit the size of read operations, which might allow remote attackers to cause a … CWE-119
CWE-189
Incorrect Access of Indexable Resource ('Range Error') 
Numeric Errors
CVE-2016-1946 2024-11-21 11:47 2016-02-1 Show GitHub Exploit DB Packet Storm
268047 8.8 HIGH
Network
mozilla
opensuse
firefox
leap
opensuse
The nsZipArchive function in Mozilla Firefox before 44.0 might allow remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging incorrect use of a pointer d… NVD-CWE-noinfo
CVE-2016-1945 2024-11-21 11:47 2016-02-1 Show GitHub Exploit DB Packet Storm
268048 9.8 CRITICAL
Network
mozilla
opensuse
firefox
leap
opensuse
The Buffer11::NativeBuffer11::map function in ANGLE, as used in Mozilla Firefox before 44.0, might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2016-1944 2024-11-21 11:47 2016-02-1 Show GitHub Exploit DB Packet Storm
268049 4.7 MEDIUM
Network
opensuse
mozilla
google
leap
opensuse
firefox
android
Mozilla Firefox before 44.0 on Android allows remote attackers to spoof the address bar via the scrollTo method. CWE-17
Code
CVE-2016-1943 2024-11-21 11:47 2016-02-1 Show GitHub Exploit DB Packet Storm
268050 7.4 HIGH
Network
opensuse
mozilla
leap
opensuse
firefox
Mozilla Firefox before 44.0 allows user-assisted remote attackers to spoof a trailing substring in the address bar by leveraging a user's paste of a (1) wyciwyg: URI or (2) resource: URI. CWE-20
 Improper Input Validation 
CVE-2016-1942 2024-11-21 11:47 2016-02-1 Show GitHub Exploit DB Packet Storm