Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 5, 2026, 2 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
252081 6.9 警告 マイクロソフト - Microsoft Windows における権限昇格の脆弱性 CWE-Other
その他
CVE-2010-3966 2011-01-14 15:42 2010-12-14 Show GitHub Exploit DB Packet Storm
252082 6.9 警告 マイクロソフト - Windows Media Encoder における権限昇格の脆弱性 CWE-Other
その他
CVE-2010-3965 2011-01-14 15:39 2010-12-14 Show GitHub Exploit DB Packet Storm
252083 6.9 警告 マイクロソフト - Microsoft Windows Movie Maker における権限昇格の脆弱性 CWE-Other
その他
CVE-2010-3967 2011-01-14 15:36 2010-12-14 Show GitHub Exploit DB Packet Storm
252084 7.2 危険 マイクロソフト - Microsoft Windows の Windows Task Scheduler における権限昇格の脆弱性 CWE-20
不適切な入力確認
CVE-2010-3338 2011-01-14 15:31 2010-12-14 Show GitHub Exploit DB Packet Storm
252085 6.9 警告 マイクロソフト - Microsoft Windows の OpenType Font ドライバにおける権限昇格の脆弱性 CWE-94
コード・インジェクション
CVE-2010-3959 2011-01-14 15:27 2010-12-14 Show GitHub Exploit DB Packet Storm
252086 5 警告 アップル
サイバートラスト株式会社
OpenLDAP Foundation
ターボリナックス
VMware
レッドハット
- OpenLDAP の IA5StringNormalize 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2010-0212 2011-01-14 14:45 2010-06-30 Show GitHub Exploit DB Packet Storm
252087 5 警告 アップル
サイバートラスト株式会社
OpenLDAP Foundation
ターボリナックス
VMware
レッドハット
- OpenLDAP の slap_modrdn2mods 関数における任意のコードを実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2010-0211 2011-01-14 14:45 2010-06-30 Show GitHub Exploit DB Packet Storm
252088 6.2 警告 サイバートラスト株式会社
VMware
Todd C. Miller
レッドハット
- sudo における権限昇格の脆弱性 CWE-DesignError
CVE-2010-2956 2011-01-14 14:44 2010-09-7 Show GitHub Exploit DB Packet Storm
252089 - - GNU Project
VMware
サイバートラスト株式会社
レッドハット
- glibc に権限昇格の脆弱性 - CVE-2010-3847 2011-01-14 14:42 2010-10-26 Show GitHub Exploit DB Packet Storm
252090 7.8 危険 マイクロソフト
アドビシステムズ
日本電気
- Microsoft Visual Studio の ATL における終端文字列の処理に関する重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2009-2495 2011-01-14 14:33 2009-07-28 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 5, 2026, 4:51 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
307181 7.8 HIGH
Local
microsoft windows_server_2008
windows_server_2012
windows_10_1507
windows_server_2016
windows_server_2022_23h2
windows_10_1809
windows_server_2022
windows_10_1607
windows_server_2019
Windows Common Log File System Driver Elevation of Privilege Vulnerability NVD-CWE-noinfo
CVE-2024-43501 2024-10-18 06:06 2024-10-9 Show GitHub Exploit DB Packet Storm
307182 5.3 MEDIUM
Network
hcltech bigfix_platform A dynamic search for a prerequisite library could allow the possibility for an attacker to replace the correct file under some circumstances. CWE-427
 Uncontrolled Search Path Element
CVE-2024-30117 2024-10-18 06:01 2024-10-15 Show GitHub Exploit DB Packet Storm
307183 5.5 MEDIUM
Local
microsoft windows_server_2022_23h2
windows_11_22h2
windows_11_23h2
windows_11_24h2
Windows Resilient File System (ReFS) Information Disclosure Vulnerability NVD-CWE-noinfo
CVE-2024-43500 2024-10-18 06:01 2024-10-9 Show GitHub Exploit DB Packet Storm
307184 4.9 MEDIUM
Network
cert vince A potential denial-of-service (DoS) vulnerability exists in CERT VINCE software versions prior to 3.0.8. An authenticated administrative user can inject an arbitrary pickle object into a user’s profi… CWE-502
 Deserialization of Untrusted Data
CVE-2024-9953 2024-10-18 05:59 2024-10-15 Show GitHub Exploit DB Packet Storm
307185 7.1 HIGH
Local
microsoft windows_10_1809
windows_server_2019
windows_10_21h2
windows_10_22h2
Windows Kernel Elevation of Privilege Vulnerability NVD-CWE-noinfo
CVE-2024-43502 2024-10-18 05:58 2024-10-9 Show GitHub Exploit DB Packet Storm
307186 5.4 MEDIUM
Network
zaytech smart_online_order_for_clover The Smart Online Order for Clover plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's moo_receipt_link shortcode in all versions up to, and including, 1.5.7 due to insu… CWE-79
Cross-site Scripting
CVE-2024-9895 2024-10-18 05:50 2024-10-15 Show GitHub Exploit DB Packet Storm
307187 6.1 MEDIUM
Network
woocommerce woocommerce The WooCommerce plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 9.0.2. This is due to the plugin not properly neutralizing HTML elements from submitted orde… CWE-79
Cross-site Scripting
CVE-2024-9944 2024-10-18 05:47 2024-10-15 Show GitHub Exploit DB Packet Storm
307188 6.1 MEDIUM
Network
quantizor markdown-to-jsx Versions of the package markdown-to-jsx before 7.4.0 are vulnerable to Cross-site Scripting (XSS) via the src property due to improper input sanitization. An attacker can execute arbitrary code by in… CWE-79
Cross-site Scripting
CVE-2024-21535 2024-10-18 05:36 2024-10-15 Show GitHub Exploit DB Packet Storm
307189 8.8 HIGH
Network
newtype flowmaster_bpm_plus The specific query functionality in the FlowMaster BPM Plus from NewType does not properly restrict user input, allowing remote attackers with regular privileges to inject SQL commands to read, modif… CWE-89
SQL Injection
CVE-2024-9971 2024-10-18 05:34 2024-10-15 Show GitHub Exploit DB Packet Storm
307190 8.8 HIGH
Network
newtype flowmaster_bpm_plus The FlowMaster BPM Plus system from NewType has a privilege escalation vulnerability. Remote attackers with regular privileges can elevate their privileges to administrator by tampering with a specif… NVD-CWE-noinfo
CVE-2024-9970 2024-10-18 05:33 2024-10-15 Show GitHub Exploit DB Packet Storm