Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 30, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
251741 6.9 警告 マイクロソフト - Microsoft Visual Studio における権限昇格の脆弱性 CWE-Other
その他
CVE-2012-0008 2012-03-19 15:27 2012-03-13 Show GitHub Exploit DB Packet Storm
251742 4.3 警告 マイクロソフト - Microsoft Windows Server 2008 および Windows 7 の RDP サービスにおけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2012-0152 2012-03-19 15:27 2012-03-13 Show GitHub Exploit DB Packet Storm
251743 4.3 警告 マイクロソフト - 複数の Microsoft Windows 製品の DirectWrite におけるサービス運用妨害 (アプリケーションハング) の脆弱性 CWE-20
不適切な入力確認
CVE-2012-0156 2012-03-19 15:26 2012-03-13 Show GitHub Exploit DB Packet Storm
251744 7.2 危険 マイクロソフト - 複数の Microsoft Windows 製品の win32k.sys における権限昇格の脆弱性 CWE-20
不適切な入力確認
CVE-2012-0157 2012-03-19 15:25 2012-03-13 Show GitHub Exploit DB Packet Storm
251745 5 警告 マイクロソフト - Microsoft Windows Server 2003 および 2008 の DNS サーバにおけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2012-0006 2012-03-19 15:24 2012-03-13 Show GitHub Exploit DB Packet Storm
251746 10 危険 ACCESS - Android用 NetFront Life Browser アプリケーションにおける詳細不明な脆弱性 CWE-noinfo
情報不足
CVE-2012-1485 2012-03-19 14:17 2012-03-15 Show GitHub Exploit DB Packet Storm
251747 10 危険 WaliSMS - Android用 WaliSMS CN アプリケーションにおける詳細不明な脆弱性 CWE-noinfo
情報不足
CVE-2012-1484 2012-03-19 14:16 2012-03-15 Show GitHub Exploit DB Packet Storm
251748 10 危険 Zhou Bo - Android用 Message Forwarder アプリケーションにおける詳細不明な脆弱性 CWE-noinfo
情報不足
CVE-2012-1483 2012-03-19 14:15 2012-03-15 Show GitHub Exploit DB Packet Storm
251749 10 危険 CooTek - Android 用 TouchPal Contacts アプリケーションにおける詳細不明な脆弱性 CWE-noinfo
情報不足
CVE-2012-1482 2012-03-19 14:09 2012-03-15 Show GitHub Exploit DB Packet Storm
251750 10 危険 Kashif Masud - Android 用 Textdroid アプリケーションにおける詳細不明な脆弱性 CWE-noinfo
情報不足
CVE-2012-1481 2012-03-19 14:06 2012-03-15 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 30, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
247031 7.8 HIGH
Local
redhat virtualization_host
virtualization
ansible_engine
openstack
In ansible it was found that inventory variables are loaded from current working directory when running ad-hoc command which are under attacker's control, allowing to run arbitrary code as a result. - CVE-2018-10874 2024-11-21 12:42 2018-07-2 Show GitHub Exploit DB Packet Storm
247032 7.5 HIGH
Network
debian
canonical
perl-archive-zip_project
debian_linux
ubuntu_linux
perl-archive-zip
perl-archive-zip is vulnerable to a directory traversal in Archive::Zip. It was found that the Archive::Zip module did not properly sanitize paths while extracting zip files. An attacker able to prov… CWE-22
Path Traversal
CVE-2018-10860 2024-11-21 12:42 2018-06-30 Show GitHub Exploit DB Packet Storm
247033 6.5 MEDIUM
Network
dell emc_idrac_service_module Dell EMC iDRAC Service Module for all supported Linux and XenServer versions v3.0.1, v3.0.2, v3.1.0, v3.2.0, when started, changes the default file permission of the hosts file of the host operating … CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2018-11053 2024-11-21 12:42 2018-06-27 Show GitHub Exploit DB Packet Storm
247034 7.5 HIGH
Network
debian
fedoraproject
redhat
debian_linux
sssd
enterprise_linux_desktop
enterprise_linux_workstation
enterprise_linux_server
The UNIX pipe which sudo uses to contact SSSD and read the available sudo rules from SSSD has too wide permissions, which means that anyone who can send a message using the same raw protocol that sud… CWE-200
Information Exposure
CVE-2018-10852 2024-11-21 12:42 2018-06-26 Show GitHub Exploit DB Packet Storm
247035 6.5 MEDIUM
Network
pivotal_software operations_manager Pivotal Operations Manager, versions 2.1.x prior to 2.1.6 and version 2.0.14, includes NGINX packages that lacks security vulnerability patches. An attacker with access to the NGINX processes and kno… CWE-20
 Improper Input Validation 
CVE-2018-11046 2024-11-21 12:42 2018-06-26 Show GitHub Exploit DB Packet Storm
247036 6.1 MEDIUM
Network
pivotal_software cloud_foundry_uaa
cloud_foundry_uaa-release
Cloud Foundry UAA, versions later than 4.6.0 and prior to 4.19.0 except 4.10.1 and 4.7.5 and uaa-release versions later than v48 and prior to v60 except v55.1 and v52.9, does not validate redirect UR… CWE-601
Open Redirect
CVE-2018-11041 2024-11-21 12:42 2018-06-26 Show GitHub Exploit DB Packet Storm
247037 7.5 HIGH
Network
vmware
oracle
debian
spring_framework
flexcube_private_banking
retail_xstore_point_of_service
application_testing_suite
hospitality_guest_access
weblogic_server
enterprise_manager_ops_center
endeca_i…
Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web applications to enable cross-domain requests via JSONP (JSON with Padding) through… CWE-829
 Inclusion of Functionality from Untrusted Control Sphere
CVE-2018-11040 2024-11-21 12:42 2018-06-26 Show GitHub Exploit DB Packet Storm
247038 7.5 HIGH
Network
ipconfigure orchid_core_vms IPConfigure Orchid Core VMS 2.0.5 allows Directory Traversal. CWE-22
Path Traversal
CVE-2018-10956 2024-11-21 12:42 2018-06-26 Show GitHub Exploit DB Packet Storm
247039 5.9 MEDIUM
Network
vmware
oracle
debian
spring_framework
retail_xstore_point_of_service
weblogic_server
application_testing_suite
hospitality_guest_access
enterprise_manager_ops_center
primavera_p6_enterprise_project_port…
Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including… NVD-CWE-noinfo
CVE-2018-11039 2024-11-21 12:42 2018-06-26 Show GitHub Exploit DB Packet Storm
247040 8.8 HIGH
Network
gluster
debian
glusterfs
debian_linux
glusterfs is vulnerable to privilege escalation on gluster server nodes. An authenticated gluster client via TLS could use gluster cli with --remote-host command to add it self to trusted storage poo… - CVE-2018-10841 2024-11-21 12:42 2018-06-21 Show GitHub Exploit DB Packet Storm