Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 11, 2026, 6:13 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
252031 6.8 警告 vamshop - VaM Shop におけるクロスサイトフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2011-0503 2012-03-27 18:42 2011-01-20 Show GitHub Exploit DB Packet Storm
252032 9.3 危険 musanim - Music Animation Machine MIDI Player におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2011-0502 2012-03-27 18:42 2011-01-20 Show GitHub Exploit DB Packet Storm
252033 9.3 危険 musanim - Music Animation Machine MIDI Player におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2011-0501 2012-03-27 18:42 2011-01-20 Show GitHub Exploit DB Packet Storm
252034 9.3 危険 verytools - VideoSpirit Pro および VideoSpirit Lite におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2011-0500 2012-03-27 18:42 2011-01-20 Show GitHub Exploit DB Packet Storm
252035 9.3 危険 verytools - VideoSpirit Pro および VideoSpirit Lite におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2011-0499 2012-03-27 18:42 2011-01-20 Show GitHub Exploit DB Packet Storm
252036 9.3 危険 ノキア - Nokia Multimedia Player におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2011-0498 2012-03-27 18:42 2011-01-20 Show GitHub Exploit DB Packet Storm
252037 7.8 危険 サイベース - Appeon などの製品で使用される Sybase EAServer におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2011-0497 2012-03-27 18:42 2011-01-11 Show GitHub Exploit DB Packet Storm
252038 10 危険 サイベース - Appeon などの製品で使用される Sybase EAServer における任意の Web サービスおよび任意のコードをインストールされる脆弱性 CWE-DesignError
CVE-2011-0496 2012-03-27 18:42 2011-01-11 Show GitHub Exploit DB Packet Storm
252039 5 警告 IBM - IBM Tivoli Access Manager for e-business の WebSEAL におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2011-0494 2012-03-27 18:42 2011-01-19 Show GitHub Exploit DB Packet Storm
252040 5 警告 The Tor Project - Tor におけるサービス運用妨害 (DoS) の脆弱性 CWE-189
数値処理の問題
CVE-2011-0493 2012-03-27 18:42 2011-01-17 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 12, 2026, 4:20 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
246321 5.9 MEDIUM
Network
axtls_project axtls In sig_verify() in x509.c in axTLS version 2.1.3 and before, the PKCS#1 v1.5 signature verification blindly trusts the declared lengths in the ASN.1 structure. Consequently, when small public exponen… CWE-347
 Improper Verification of Cryptographic Signature
CVE-2018-16149 2024-11-21 12:52 2018-11-8 Show GitHub Exploit DB Packet Storm
246322 7.5 HIGH
Network
knight_project knight A Path Traversal in Knightjs versions <= 0.0.1 allows an attacker to read content of arbitrary files on a remote server. CWE-22
Path Traversal
CVE-2018-16475 2024-11-21 12:52 2018-11-7 Show GitHub Exploit DB Packet Storm
246323 6.1 MEDIUM
Network
tianma-static_project tianma-static A stored xss in tianma-static module versions <=1.0.4 allows an attacker to execute arbitrary javascript. CWE-79
Cross-site Scripting
CVE-2018-16474 2024-11-21 12:52 2018-11-7 Show GitHub Exploit DB Packet Storm
246324 5.3 MEDIUM
Network
takeapeek_project takeapeek A path traversal in takeapeek module versions <=0.2.2 allows an attacker to list directory and files. CWE-22
Path Traversal
CVE-2018-16473 2024-11-21 12:52 2018-11-7 Show GitHub Exploit DB Packet Storm
246325 7.5 HIGH
Network
cached-path-relative_project
debian
cached-path-relative
debian_linux
A prototype pollution attack in cached-path-relative versions <=1.0.1 allows an attacker to inject properties on Object.prototype which are then inherited by all the JS objects through the prototype … CWE-20
 Improper Input Validation 
CVE-2018-16472 2024-11-21 12:52 2018-11-7 Show GitHub Exploit DB Packet Storm
246326 7.5 HIGH
Network
merge_project merge The merge.recursive function in the merge package <1.2.1 can be tricked into adding or modifying properties of the Object prototype. These properties will be present on all objects allowing for a den… CWE-20
 Improper Input Validation 
CVE-2018-16469 2024-11-21 12:52 2018-10-31 Show GitHub Exploit DB Packet Storm
246327 5.4 MEDIUM
Network
loofah_project
debian
loofah
debian_linux
In the Loofah gem for Ruby, through v2.2.2, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished. CWE-79
Cross-site Scripting
CVE-2018-16468 2024-11-21 12:52 2018-10-31 Show GitHub Exploit DB Packet Storm
246328 5.3 MEDIUM
Network
nextcloud nextcloud_server A missing check in Nextcloud Server prior to 14.0.0 could give unauthorized access to the previews of single file password protected shares. CWE-287
Improper Authentication
CVE-2018-16467 2024-11-21 12:52 2018-10-31 Show GitHub Exploit DB Packet Storm
246329 8.1 HIGH
Network
nextcloud nextcloud_server Improper revalidation of permissions in Nextcloud Server prior to 14.0.0, 13.0.6 and 12.0.11 lead to not accepting access restrictions by acess tokens. CWE-273
 Improper Check for Dropped Privileges
CVE-2018-16466 2024-11-21 12:52 2018-10-31 Show GitHub Exploit DB Packet Storm
246330 5.3 MEDIUM
Network
nextcloud nextcloud_server Missing state in Nextcloud Server prior to 14.0.0 would not enforce the use of a second factor at login if the the provider of the second factor failed to load. CWE-287
Improper Authentication
CVE-2018-16465 2024-11-21 12:52 2018-10-31 Show GitHub Exploit DB Packet Storm