Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 24, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
242891 3.5 注意 Drupal
alexander hass
- Drupal の Sections モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4429 2012-06-26 16:18 2009-12-16 Show GitHub Exploit DB Packet Storm
242892 7.5 危険 Deon George - phpLDAPadmin のcmd.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2009-4427 2012-06-26 16:18 2009-12-28 Show GitHub Exploit DB Packet Storm
242893 4.3 警告 aditus - Aditus Consulting JpGraph の GetURLArguments 関数におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4422 2012-06-26 16:18 2009-12-24 Show GitHub Exploit DB Packet Storm
242894 6.5 警告 Alexander Palmo - Simple PHP Blog の languages_cgi.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2009-4421 2012-06-26 16:18 2009-12-24 Show GitHub Exploit DB Packet Storm
242895 7.5 危険 edgewall - Trac における詳細不明な脆弱性 CWE-noinfo
情報不足
CVE-2009-4405 2012-06-26 16:18 2009-12-23 Show GitHub Exploit DB Packet Storm
242896 7.5 危険 daniel ptzinger
TYPO3 Association
- TYPO3 用の Document Directorys 拡張機能における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-4393 2012-06-26 16:18 2009-12-22 Show GitHub Exploit DB Packet Storm
242897 4.3 警告 daniel regelein
TYPO3 Association
- TYPO3 用の File list 拡張機能におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4391 2012-06-26 16:18 2009-12-22 Show GitHub Exploit DB Packet Storm
242898 4.3 警告 frank krger
TYPO3 Association
- TYPO3 の nl_listman 拡張におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4388 2012-06-26 16:18 2009-12-22 Show GitHub Exploit DB Packet Storm
242899 7.5 危険 bookingcentre - Venalsur Booking Centre Booking System の hotel_tiempolibre_ext.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-4386 2012-06-26 16:18 2009-12-22 Show GitHub Exploit DB Packet Storm
242900 7.5 危険 AlienVault - AlienVault OSSIM の repository/repository_attachment.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-4375 2012-06-26 16:18 2009-12-21 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 25, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
267981 7.7 HIGH
Local
hp system_management_homepage HPE System Management Homepage before 7.5.4 allows local users to obtain sensitive information or modify data via unspecified vectors. NVD-CWE-noinfo
CVE-2016-1996 2024-11-21 11:47 2016-03-18 Show GitHub Exploit DB Packet Storm
267982 9.8 CRITICAL
Network
hp system_management_homepage HPE System Management Homepage before 7.5.4 allows remote attackers to execute arbitrary code via unspecified vectors. NVD-CWE-noinfo
CVE-2016-1995 2024-11-21 11:47 2016-03-18 Show GitHub Exploit DB Packet Storm
267983 6.5 MEDIUM
Network
hp system_management_homepage HPE System Management Homepage before 7.5.4 allows remote authenticated users to obtain sensitive information via unspecified vectors. CWE-200
Information Exposure
CVE-2016-1994 2024-11-21 11:47 2016-03-18 Show GitHub Exploit DB Packet Storm
267984 8.1 HIGH
Network
hp system_management_homepage HPE System Management Homepage before 7.5.4 allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors. NVD-CWE-noinfo
CVE-2016-1993 2024-11-21 11:47 2016-03-18 Show GitHub Exploit DB Packet Storm
267985 6.5 MEDIUM
Network
hp enterprise_security_manager_express
enterprise_security_manager
HPE ArcSight ESM before 6.8c, and ArcSight ESM Express before 6.9.1, allows remote authenticated users to obtain sensitive information via unspecified vectors. CWE-200
Information Exposure
CVE-2016-1992 2024-11-21 11:47 2016-03-17 Show GitHub Exploit DB Packet Storm
267986 5.4 MEDIUM
Network
vmware vrealize_business_advanced_and_enterprise Cross-site scripting (XSS) vulnerability in VMware vRealize Business Advanced and Enterprise 8.x before 8.2.5 on Linux allows remote authenticated users to inject arbitrary web script or HTML via uns… CWE-79
Cross-site Scripting
CVE-2016-2075 2024-11-21 11:47 2016-03-16 Show GitHub Exploit DB Packet Storm
267987 8.0 HIGH
Network
microfocus arcsight_enterprise_security_manager HPE ArcSight ESM 5.x before 5.6, 6.0, 6.5.x before 6.5C SP1 Patch 2, and 6.8c before P1, and ArcSight ESM Express before 6.9.1, allows remote authenticated users to conduct unspecified "file download… NVD-CWE-noinfo
CVE-2016-1991 2024-11-21 11:47 2016-03-16 Show GitHub Exploit DB Packet Storm
267988 7.8 HIGH
Local
microfocus arcsight_enterprise_security_manager HPE ArcSight ESM 5.x before 5.6, 6.0, 6.5.x before 6.5C SP1 Patch 2, and 6.8c before P1, and ArcSight ESM Express before 6.9.1, allows local users to gain privileges for command execution via unspeci… CWE-264
Permissions, Privileges, and Access Controls
CVE-2016-1990 2024-11-21 11:47 2016-03-16 Show GitHub Exploit DB Packet Storm
267989 9.8 CRITICAL
Network
hp network_automation HPE Network Automation 9.22 through 9.22.02 and 10.x before 10.00.02 allows remote attackers to execute arbitrary code or obtain sensitive information via unspecified vectors, a different vulnerabili… NVD-CWE-noinfo
CVE-2016-1989 2024-11-21 11:47 2016-03-15 Show GitHub Exploit DB Packet Storm
267990 9.8 CRITICAL
Network
hp network_automation HPE Network Automation 9.22 through 9.22.02 and 10.x before 10.00.02 allows remote attackers to execute arbitrary code or obtain sensitive information via unspecified vectors, a different vulnerabili… NVD-CWE-noinfo
CVE-2016-1988 2024-11-21 11:47 2016-03-15 Show GitHub Exploit DB Packet Storm