Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 28, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
243031 7.5 危険 fernando soares
Joomla!
- Joomla! 用 Fernando Soares Mamboleto コンポーネントの mamboleto.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2009-4604 2012-06-26 16:19 2010-01-12 Show GitHub Exploit DB Packet Storm
243032 7.5 危険 corephp
Joomla!
- Joomla! の jphoto コンポーネントにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-4598 2012-06-26 16:19 2010-01-12 Show GitHub Exploit DB Packet Storm
243033 9.3 危険 awingsoft - AwingSoft Awakening Web3D Player などの WindsPlayerIE.View.1 ActiveX コントロールにおけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-4588 2012-06-26 16:19 2010-01-7 Show GitHub Exploit DB Packet Storm
243034 5 警告 Cherokee Project - Cherokee Web Server におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2009-4587 2012-06-26 16:19 2010-01-7 Show GitHub Exploit DB Packet Storm
243035 5 警告 ASP indir - UranyumSoft Listing Service におけるデータベースをダウンロードされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2009-4585 2012-06-26 16:19 2010-01-6 Show GitHub Exploit DB Packet Storm
243036 7.5 危険 dbmasters - dB Masters Multimedia Links Directory の admin.php における管理者アクセス権を取得される脆弱性 CWE-287
不適切な認証
CVE-2009-4584 2012-06-26 16:19 2010-01-6 Show GitHub Exploit DB Packet Storm
243037 4.3 警告 FacileForms
Joomla!
Mambo Foundation
- Mambo および Joomla! 用の Facileforms コンポーネントにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4578 2012-06-26 16:19 2010-01-6 Show GitHub Exploit DB Packet Storm
243038 4.3 警告 Drupal - Drupal 用の Randomizer モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4602 2012-06-26 16:19 2009-12-9 Show GitHub Exploit DB Packet Storm
243039 7.5 危険 cmstactics
Joomla!
- Joomla! の beeheard コンポーネントにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-4576 2012-06-26 16:19 2010-01-6 Show GitHub Exploit DB Packet Storm
243040 7.5 危険 elkagroup - elkagroup Image Gallery における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-4569 2012-06-26 16:19 2010-01-5 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 28, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
268491 7.8 HIGH
Local
microsoft windows_rt_8.1
windows_server_2012
windows_7
windows_10
windows_8.1
windows_server_2008
windows_vista
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 a… CWE-264
Permissions, Privileges, and Access Controls
CVE-2016-3221 2024-11-21 11:49 2016-06-16 Show GitHub Exploit DB Packet Storm
268492 7.8 HIGH
Local
microsoft windows_rt_8.1
windows_server_2012
windows_7
windows_10
windows_8.1
windows_server_2008
windows_vista
atmfd.dll in the Adobe Type Manager Font Driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Wi… CWE-264
Permissions, Privileges, and Access Controls
CVE-2016-3220 2024-11-21 11:49 2016-06-16 Show GitHub Exploit DB Packet Storm
268493 7.8 HIGH
Local
microsoft windows_10 The kernel-mode driver in Microsoft Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability." CWE-264
Permissions, Privileges, and Access Controls
CVE-2016-3219 2024-11-21 11:49 2016-06-16 Show GitHub Exploit DB Packet Storm
268494 7.8 HIGH
Local
microsoft windows_rt_8.1
windows_server_2012
windows_7
windows_10
windows_8.1
windows_server_2008
windows_vista
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 a… CWE-264
Permissions, Privileges, and Access Controls
CVE-2016-3218 2024-11-21 11:49 2016-06-16 Show GitHub Exploit DB Packet Storm
268495 4.3 MEDIUM
Network
microsoft windows_rt_8.1
windows_server_2012
windows_10
windows_8.1
windows_7
windows_server_2008
windows_vista
GDI32.dll in the Graphics component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gol… CWE-200
Information Exposure
CVE-2016-3216 2024-11-21 11:49 2016-06-16 Show GitHub Exploit DB Packet Storm
268496 5.5 MEDIUM
Local
microsoft windows_server_2012
windows_10
windows_8.1
edge
Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 1511, and Microsoft Edge allow remote attackers to obtain sensitive information from process memory via a crafted PDF document, aka … CWE-200
Information Exposure
CVE-2016-3215 2024-11-21 11:49 2016-06-16 Show GitHub Exploit DB Packet Storm
268497 8.8 HIGH
Network
microsoft edge The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory … CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2016-3214 2024-11-21 11:49 2016-06-16 Show GitHub Exploit DB Packet Storm
268498 6.1 MEDIUM
Network
microsoft internet_explorer The XSS Filter in Microsoft Internet Explorer 9 through 11 does not properly identify JavaScript, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafte… CWE-79
Cross-site Scripting
CVE-2016-3212 2024-11-21 11:49 2016-06-16 Show GitHub Exploit DB Packet Storm
268499 8.8 HIGH
Network
microsoft internet_explorer Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corru… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2016-3211 2024-11-21 11:49 2016-06-16 Show GitHub Exploit DB Packet Storm
268500 8.8 HIGH
Network
microsoft internet_explorer The Microsoft (1) JScript and (2) VBScript engines, as used in Internet Explorer 11, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted we… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2016-3210 2024-11-21 11:49 2016-06-16 Show GitHub Exploit DB Packet Storm