Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 4, 2026, 12:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
251241 9.3 危険 crossftp - CrossFTP Pro におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2010-4153 2012-03-27 18:42 2010-11-3 Show GitHub Exploit DB Packet Storm
251242 7.5 危険 4site - 4site CMS の catalog/index.shtml における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-4152 2012-03-27 18:42 2010-11-3 Show GitHub Exploit DB Packet Storm
251243 6.8 警告 deluxebb - DeluxeBB における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-4151 2012-03-27 18:42 2010-11-3 Show GitHub Exploit DB Packet Storm
251244 9.3 危険 freshwebmaster - FreshWebMaster Fresh FTP におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2010-4149 2012-03-27 18:42 2010-11-1 Show GitHub Exploit DB Packet Storm
251245 9.3 危険 anyconnect - AnyConnect におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2010-4148 2012-03-27 18:42 2010-11-1 Show GitHub Exploit DB Packet Storm
251246 7.5 危険 avactis - Pentasoft Avactis Shopping Cart における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-4147 2012-03-27 18:42 2010-11-1 Show GitHub Exploit DB Packet Storm
251247 4.3 警告 Attachmate - Web 2008 の Attachmate Reflection におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-4146 2012-03-27 18:42 2010-11-1 Show GitHub Exploit DB Packet Storm
251248 5 警告 ASP indir - Kisisel Radyo Script におけるデータベースをダウンロードされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2010-4145 2012-03-27 18:42 2010-11-1 Show GitHub Exploit DB Packet Storm
251249 7.5 危険 ASP indir - Kisisel Radyo Script における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-4144 2012-03-27 18:42 2010-11-1 Show GitHub Exploit DB Packet Storm
251250 6.8 警告 phpcheckz - phpCheckZ の chart.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-4143 2012-03-27 18:42 2010-11-1 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 4, 2026, 4:17 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
247331 7.5 HIGH
Network
gnome epiphany libephymain.so in GNOME Web (aka Epiphany) through 3.28.2.1 allows remote attackers to cause a denial of service (application crash) via certain window.open and document.write calls. NVD-CWE-noinfo
CVE-2018-12016 2024-11-21 12:44 2018-06-7 Show GitHub Exploit DB Packet Storm
247332 7.5 HIGH
Network
canonical
debian
perl
archive\
apple
netapp
ubuntu_linux
debian_linux
perl
\
mac_os_x
snap_creator_framework
data_ontap_edge
snapdrive
oncommand_workflow_automation
In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary files, via an archive file containing a symlink a… CWE-59
Link Following
CVE-2018-12015 2024-11-21 12:44 2018-06-7 Show GitHub Exploit DB Packet Storm
247333 7.5 HIGH
Network
ijg libjpeg libjpeg 9c has a large loop because read_pixel in rdtarga.c mishandles EOF. CWE-834
 Excessive Iteration
CVE-2018-11813 2024-11-21 12:44 2018-06-6 Show GitHub Exploit DB Packet Storm
247334 9.1 CRITICAL
Network
zohocorp manageengine_applications_manager Incorrect Access Control in CustomFieldsFeedServlet in Zoho ManageEngine Applications Manager Version 13 before build 13740 allows an attacker to delete any file and read certain files on the server … CWE-20
 Improper Input Validation 
CVE-2018-11808 2024-11-21 12:44 2018-06-6 Show GitHub Exploit DB Packet Storm
247335 8.8 HIGH
Network
apache hadoop Web endpoint authentication check is broken in Apache Hadoop 3.0.0-alpha4, 3.0.0-beta1, and 3.0.0. Authenticated users may impersonate any user even if no proxy user is configured. CWE-306
Missing Authentication for Critical Function
CVE-2018-11764 2024-11-21 12:43 2020-10-22 Show GitHub Exploit DB Packet Storm
247336 7.5 HIGH
Network
apache hadoop In Apache Hadoop versions 3.0.0-alpha2 to 3.0.0, 2.9.0 to 2.9.2, 2.8.0 to 2.8.5, any users can access some servlets without authentication when Kerberos authentication is enabled and SPNEGO through H… CWE-287
Improper Authentication
CVE-2018-11765 2024-11-21 12:43 2020-10-1 Show GitHub Exploit DB Packet Storm
247337 5.4 MEDIUM
Adjacent
puppet puppet_server Previous versions of Puppet Agent didn't verify the peer in the SSL connection prior to downloading the CRL. This issue is resolved in Puppet Agent 6.4.0. CWE-295
Improper Certificate Validation 
CVE-2018-11751 2024-11-21 12:43 2019-12-17 Show GitHub Exploit DB Packet Storm
247338 7.5 HIGH
Network
apache hadoop In Apache Hadoop 3.1.0 to 3.1.1, 3.0.0-alpha1 to 3.0.3, 2.9.0 to 2.9.1, and 2.0.0-alpha to 2.8.4, the user/group information can be corrupted across storing in fsimage and reading back from fsimage. CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2018-11768 2024-11-21 12:43 2019-10-4 Show GitHub Exploit DB Packet Storm
247339 9.8 CRITICAL
Network
eventum_project eventum Controller/ListController.php in Eventum 3.5.0 is vulnerable to Deserialization of Untrusted Data. Fixed in version 3.5.2. CWE-502
 Deserialization of Untrusted Data
CVE-2018-11569 2024-11-21 12:43 2019-09-6 Show GitHub Exploit DB Packet Storm
247340 8.1 HIGH
Network
cloudera cloudera_manager Cloudera Manager through 5.15 has Incorrect Access Control. CWE-284
Improper Access Control
CVE-2018-11744 2024-11-21 12:43 2019-07-11 Show GitHub Exploit DB Packet Storm