Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 5, 2026, 2 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
252201 4.3 警告 CA Technologies - CA Service Desk および CMDB におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-4119 2010-12-24 11:43 2008-09-24 Show GitHub Exploit DB Packet Storm
252202 10 危険 CA Technologies - CA ARCserve Backup for Laptops and Desktops の LGServer サービスにおける整数オーバーフローの脆弱性 CWE-189
数値処理の問題
CVE-2008-3175 2010-12-24 11:42 2008-07-31 Show GitHub Exploit DB Packet Storm
252203 7.2 危険 CA Technologies - CA Host-Based Intrusion Prevention System の kmxfw.sys ドライバにおける権限を取得される脆弱性 CWE-20
不適切な入力確認
CVE-2008-2926 2010-12-24 11:42 2008-08-12 Show GitHub Exploit DB Packet Storm
252204 10 危険 CA Technologies - CA eTrust Secure Content Manager の HTTP Gateway Service におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-2541 2010-12-24 11:41 2008-06-3 Show GitHub Exploit DB Packet Storm
252205 9.3 危険 CA Technologies - CA Internet Security Suite の UmxEventCli.dll におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-2511 2010-12-24 11:41 2008-06-2 Show GitHub Exploit DB Packet Storm
252206 7.5 危険 CA Technologies - CA BrightStor ARCServe Backup のサーバ内の xdr 関数におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-2242 2010-12-24 11:41 2008-05-19 Show GitHub Exploit DB Packet Storm
252207 10 危険 CA Technologies - CA BrightStor ARCServe Backup の caloggerd におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-2241 2010-12-24 11:40 2008-05-19 Show GitHub Exploit DB Packet Storm
252208 7.8 危険 CA Technologies - CA Secure Content Manager の eTrust Common Services Daemon におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2008-1984 2010-12-24 11:40 2008-04-27 Show GitHub Exploit DB Packet Storm
252209 10 危険 CA Technologies - 複数の CA 製品の NetBackup サービスにおける任意のコマンドを実行される脆弱性 CWE-noinfo
情報不足
CVE-2008-1329 2010-12-24 11:39 2008-04-11 Show GitHub Exploit DB Packet Storm
252210 9.3 危険 CA Technologies - 複数の CA 製品の LGServer サービスにおけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-1328 2010-12-24 11:39 2008-04-11 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 5, 2026, 4:51 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
249171 7.5 HIGH
Network
oauth2-server_project oauth2-server oauth2-server (aka node-oauth2-server) through 3.1.1 implements OAuth 2.0 without PKCE. It does not prevent authorization code injection. This is similar to CVE-2020-7692. NOTE: the vendor states 'As… CWE-94
Code Injection
CVE-2017-18924 2024-11-21 12:21 2020-10-4 Show GitHub Exploit DB Packet Storm
249172 7.5 HIGH
Network
beronet voice_over_internet_protocol_gateways_firmware beroNet VoIP Gateways before 3.0.16 have a PHP script that allows downloading arbitrary files, including ones with credentials. CWE-74
Injection
CVE-2017-18923 2024-11-21 12:21 2020-07-30 Show GitHub Exploit DB Packet Storm
249173 9.8 CRITICAL
Network
libvncserver_project
canonical
opensuse
fedoraproject
siemens
libvncserver
ubuntu_linux
leap
fedora
simatic_itc1500_firmware
simatic_itc1500_pro_firmware
simatic_itc1900_firmware
simatic_itc1900_pro_firmware
simatic_itc2200_firmware
s…
It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket fr… CWE-787
 Out-of-bounds Write
CVE-2017-18922 2024-11-21 12:21 2020-06-30 Show GitHub Exploit DB Packet Storm
249174 6.1 MEDIUM
Network
mattermost mattermost_server An issue was discovered in Mattermost Server before 3.6.0 and 3.5.2. XSS can occur via a link on an error page. CWE-79
Cross-site Scripting
CVE-2017-18921 2024-11-21 12:21 2020-06-20 Show GitHub Exploit DB Packet Storm
249175 9.8 CRITICAL
Network
mattermost mattermost_server An issue was discovered in Mattermost Server before 3.6.2. The WebSocket feature does not follow the Same Origin Policy. NVD-CWE-Other
CVE-2017-18920 2024-11-21 12:21 2020-06-20 Show GitHub Exploit DB Packet Storm
249176 5.3 MEDIUM
Network
mattermost mattermost_server An issue was discovered in Mattermost Server before 3.7.0 and 3.6.3. Attackers can use the API for unauthenticated team creation. CWE-287
Improper Authentication
CVE-2017-18919 2024-11-21 12:21 2020-06-20 Show GitHub Exploit DB Packet Storm
249177 4.9 MEDIUM
Network
mattermost mattermost_server An issue was discovered in Mattermost Server before 3.7.3 and 3.6.5. A System Administrator can place a SAML certificate at an arbitrary pathname. CWE-295
Improper Certificate Validation 
CVE-2017-18918 2024-11-21 12:21 2020-06-20 Show GitHub Exploit DB Packet Storm
249178 7.5 HIGH
Network
mattermost mattermost_server An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. Weak hashing was used for e-mail invitations, OAuth, and e-mail verification tokens. CWE-916
 Use of Password Hash With Insufficient Computational Effort
CVE-2017-18917 2024-11-21 12:21 2020-06-20 Show GitHub Exploit DB Packet Storm
249179 5.3 MEDIUM
Network
mattermost mattermost_server An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. API endpoint access control does not honor an integration permission restriction. CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2017-18916 2024-11-21 12:21 2020-06-20 Show GitHub Exploit DB Packet Storm
249180 9.8 CRITICAL
Network
mattermost mattermost_server An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. After a restart of a server, an attacker might suddenly gain API Endpoint access. CWE-276
Incorrect Default Permissions 
CVE-2017-18915 2024-11-21 12:21 2020-06-20 Show GitHub Exploit DB Packet Storm