Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 20, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
252241 7.5 危険 日本電気
アップル
アライドテレシス
サン・マイクロシステムズ
BEAシステムズ
レッドハット
- Java Web Start において許可されていないシステムクラスが実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2007-2435 2011-11-28 16:52 2007-04-30 Show GitHub Exploit DB Packet Storm
252242 4 警告 サイボウズ - サイボウズ Office におけるアクセス制限不備の脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2011-2677 2011-11-28 16:45 2011-10-7 Show GitHub Exploit DB Packet Storm
252243 6.8 警告 Zenprise Inc. - Zenprise Device Manager にクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2011-4498 2011-11-28 14:56 2011-11-21 Show GitHub Exploit DB Packet Storm
252244 7.5 危険 アップル - Apple iTunes における脆弱性に対するアップデート CWE-94
コード・インジェクション
CVE-2008-3434 2011-11-28 14:56 2011-11-15 Show GitHub Exploit DB Packet Storm
252245 7.5 危険 アップル - Apple Time Capsule および AirPort Base Station (802.11n) における複数の脆弱性に対するアップデート CWE-20
不適切な入力確認
CVE-2011-0997 2011-11-28 14:52 2011-11-11 Show GitHub Exploit DB Packet Storm
252246 9.3 危険 Aviosoft - Aviosoft DTV Player にバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2011-4496 2011-11-28 14:49 2011-10-11 Show GitHub Exploit DB Packet Storm
252247 5 警告 デル - Dell KACE K2000 System Deployment Appliance に不正ログイン可能な脆弱性 CWE-310
暗号の問題
CVE-2011-4046 2011-11-28 14:49 2011-11-9 Show GitHub Exploit DB Packet Storm
252248 4.3 警告 デル - Dell KACE K2000 System Deployment Appliance に情報漏えいの脆弱性 CWE-255
証明書・パスワード管理
CVE-2011-4048 2011-11-28 14:48 2011-11-9 Show GitHub Exploit DB Packet Storm
252249 3.5 注意 デル - Dell KACE K2000 System Deployment Appliance にクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-4436 2011-11-28 14:47 2011-11-9 Show GitHub Exploit DB Packet Storm
252250 9.3 危険 デル - Dell KACE K2000 System Deployment Appliance にコマンドインジェクションの脆弱性 CWE-94
コード・インジェクション
CVE-2011-4047 2011-11-28 14:46 2011-11-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 20, 2026, 4:14 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
247141 7.5 HIGH
Network
novell edirectory The LDAP backend in Novell eDirectory before 9.0 SP4 when switched to EBA (Enhanced Background Authentication) kept open connections without EBA. NVD-CWE-noinfo
CVE-2017-9277 2024-11-21 12:35 2018-03-3 Show GitHub Exploit DB Packet Storm
247142 6.1 MEDIUM
Network
netiq access_manager Novell Access Manager iManager before 4.3.3 did not validate parameters so that cross site scripting content could be reflected back into the result page using the "a" parameter. CWE-79
Cross-site Scripting
CVE-2017-9276 2024-11-21 12:35 2018-03-3 Show GitHub Exploit DB Packet Storm
247143 7.5 HIGH
Network
novell edirectory In Novell eDirectory before 9.0.3.1 the LDAP interface was not strictly enforcing cipher restrictions allowing weaker ciphers to be used during SSL BIND operations. NVD-CWE-noinfo
CVE-2017-9267 2024-11-21 12:35 2018-03-3 Show GitHub Exploit DB Packet Storm
247144 8.8 HIGH
Network
opensuse leap The packaging of NextCloud in openSUSE used /srv/www/htdocs in an unsafe manner, which could have allowed scripts running as wwwrun user to escalate privileges to root during nextcloud package upgrad… NVD-CWE-noinfo
CVE-2017-9286 2024-11-21 12:35 2018-03-2 Show GitHub Exploit DB Packet Storm
247145 7.8 HIGH
Local
opensuse obs-service-source_validator A shell command injection in the obs-service-source_validator before 0.7 could be used to execute code as the packager when checking RPM SPEC files with specific macro constructs. CWE-78
OS Command 
CVE-2017-9274 2024-11-21 12:35 2018-03-2 Show GitHub Exploit DB Packet Storm
247146 3.3 LOW
Local
opensuse
fedoraproject
zypper
fedora
The commandline package update tool zypper writes HTTP proxy credentials into its logfile, allowing local attackers to gain access to proxies used. CWE-532
 Inclusion of Sensitive Information in Log Files
CVE-2017-9271 2024-11-21 12:35 2018-03-2 Show GitHub Exploit DB Packet Storm
247147 9.1 CRITICAL
Network
opensuse cryptctl In cryptctl before version 2.0 a malicious server could send RPC requests that could overwrite files outside of the cryptctl key database. CWE-20
 Improper Input Validation 
CVE-2017-9270 2024-11-21 12:35 2018-03-2 Show GitHub Exploit DB Packet Storm
247148 9.8 CRITICAL
Network
opensuse libzypp In libzypp before August 2018 GPG keys attached to YUM repositories were not correctly pinned, allowing malicious repository mirrors to silently downgrade to unsigned repositories with potential mali… CWE-20
 Improper Input Validation 
CVE-2017-9269 2024-11-21 12:35 2018-03-2 Show GitHub Exploit DB Packet Storm
247149 6.5 MEDIUM
Network
opensuse open_build_service In the open build service before 201707022 the wipetrigger and rebuild actions checked the wrong project for permissions, allowing authenticated users to cause operations on projects where they did n… CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2017-9268 2024-11-21 12:35 2018-03-2 Show GitHub Exploit DB Packet Storm
247150 5.4 MEDIUM
Network
microfocus project_and_portfolio_management A Remote Cross-Site Scripting vulnerability in HPE Project and Portfolio Management (PPM) version v9.30, v9.31, v9.32, v9.40 was found. CWE-79
Cross-site Scripting
CVE-2017-8993 2024-11-21 12:35 2018-02-16 Show GitHub Exploit DB Packet Storm