Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 5, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
251091 5 警告 OTRS プロジェクト - OTRS における電子メール通信をなりすまされる脆弱性 CWE-255
証明書・パスワード管理
CVE-2010-4764 2012-03-27 18:42 2011-03-18 Show GitHub Exploit DB Packet Storm
251092 6.5 警告 OTRS プロジェクト - OTRS の ACL 顧客ステータスチケットタイプ設定における ACL 制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2010-4763 2012-03-27 18:42 2011-03-18 Show GitHub Exploit DB Packet Storm
251093 3.5 注意 OTRS プロジェクト - OTRS のリッチテキストエディタコンポーネントにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-4762 2012-03-27 18:42 2011-03-18 Show GitHub Exploit DB Packet Storm
251094 4 警告 OTRS プロジェクト - OTRS の顧客インターフェースチケット印刷ダイアログにおける重要な情報を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2010-4761 2012-03-27 18:42 2011-03-18 Show GitHub Exploit DB Packet Storm
251095 3.5 注意 OTRS プロジェクト - OTRS における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2010-4760 2012-03-27 18:42 2011-03-18 Show GitHub Exploit DB Packet Storm
251096 4 警告 OTRS プロジェクト - OTRS におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2010-4759 2012-03-27 18:42 2011-03-18 Show GitHub Exploit DB Packet Storm
251097 1.9 注意 OTRS プロジェクト - OTRS の installer.pl におけるパスワード取得される脆弱性 CWE-310
暗号の問題
CVE-2010-4758 2012-03-27 18:42 2011-03-18 Show GitHub Exploit DB Packet Storm
251098 4.3 警告 e107.org - e107 におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-4757 2012-03-27 18:42 2011-03-15 Show GitHub Exploit DB Packet Storm
251099 4 警告 GNU Project - GNU C Library の glob 実装におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2010-4756 2012-03-27 18:42 2011-03-2 Show GitHub Exploit DB Packet Storm
251100 4 警告 OpenBSD
FreeBSD
NetBSD
- OpenSSH の remote_glob 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2010-4755 2012-03-27 18:42 2011-03-2 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 6, 2026, 4:18 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
247591 7.1 HIGH
Local
civetweb_project civetweb Out-of-bounds Read in the send_ssi_file function in civetweb.c in CivetWeb through 1.10 allows attackers to cause a Denial of Service or Information Disclosure via a crafted SSI file. CWE-200
CWE-125
Information Exposure
Out-of-bounds Read
CVE-2018-12684 2024-11-21 12:45 2018-06-23 Show GitHub Exploit DB Packet Storm
247592 9.8 CRITICAL
Network
portainer portainer Portainer before 1.18.0 supports unauthenticated requests to the websocket endpoint with an unvalidated id query parameter for the /websocket/exec endpoint, which allows remote attackers to bypass in… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2018-12678 2024-11-21 12:45 2018-06-23 Show GitHub Exploit DB Packet Storm
247593 8.8 HIGH
Network
eclipse
netapp
jetty
e-series_santricity_os_controller
snap_creator_framework
hyper_converged_infrastructure
element_software
santricity_cloud_connector
snapcenter
oncommand_unified_manager
In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details, it is possible for a malicious user to access… CWE-384
 Session Fixation
CVE-2018-12538 2024-11-21 12:45 2018-06-23 Show GitHub Exploit DB Packet Storm
247594 7.2 HIGH
Network
ithemes security The iThemes Security (better-wp-security) plugin before 7.0.3 for WordPress allows SQL Injection (by attackers with Admin privileges) via the logs page. CWE-89
SQL Injection
CVE-2018-12636 2024-11-21 12:45 2018-06-23 Show GitHub Exploit DB Packet Storm
247595 8.8 HIGH
Network
slims_akasia_project slims_akasia SLiMS 8 Akasia 8.3.1 allows remote attackers to bypass the CSRF protection mechanism and obtain admin access by omitting the csrf_token parameter. CWE-352
 Origin Validation Error
CVE-2018-12659 2024-11-21 12:45 2018-06-23 Show GitHub Exploit DB Packet Storm
247596 6.1 MEDIUM
Network
slims_project slims Reflected Cross-Site Scripting (XSS) exists in the Stock Take module in SLiMS 8 Akasia 8.3.1 via an admin/modules/stock_take/index.php?keywords= URI. CWE-79
Cross-site Scripting
CVE-2018-12658 2024-11-21 12:45 2018-06-23 Show GitHub Exploit DB Packet Storm
247597 6.1 MEDIUM
Network
slims_akasia_project slims_akasia Reflected Cross-Site Scripting (XSS) exists in the Master File module in SLiMS 8 Akasia 8.3.1 via an admin/modules/master_file/rda_cmc.php?keywords= URI. CWE-79
Cross-site Scripting
CVE-2018-12657 2024-11-21 12:45 2018-06-23 Show GitHub Exploit DB Packet Storm
247598 6.1 MEDIUM
Network
slims_akasia_project slims_akasia Reflected Cross-Site Scripting (XSS) exists in the Membership module in SLiMS 8 Akasia 8.3.1 via an admin/modules/membership/index.php?keywords= URI. CWE-79
Cross-site Scripting
CVE-2018-12656 2024-11-21 12:45 2018-06-23 Show GitHub Exploit DB Packet Storm
247599 6.1 MEDIUM
Network
slims_akasia_project slims_akasia Reflected Cross-Site Scripting (XSS) exists in the Circulation module in SLiMS 8 Akasia 8.3.1 via an admin/modules/circulation/loan_rules.php?keywords= URI, a related issue to CVE-2017-7242. CWE-79
Cross-site Scripting
CVE-2018-12655 2024-11-21 12:45 2018-06-23 Show GitHub Exploit DB Packet Storm
247600 6.1 MEDIUM
Network
slims_akasia_project slims_akasia Reflected Cross-Site Scripting (XSS) exists in the Bibliography module in SLiMS 8 Akasia 8.3.1 via an admin/modules/bibliography/index.php?keywords= URI. CWE-79
Cross-site Scripting
CVE-2018-12654 2024-11-21 12:45 2018-06-23 Show GitHub Exploit DB Packet Storm