Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 24, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
252271 7.5 危険 SugarCRM - SugarCRM の Leads モジュールにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2011-4833 2011-12-19 15:08 2011-12-15 Show GitHub Exploit DB Packet Storm
252272 7.5 危険 Moxiecode Systems AB
phpMyFAQ
PHPletter
- 複数の製品で使用される inc/function.base.php における PHP コードを挿入される脆弱性 CWE-94
コード・インジェクション
CVE-2011-4825 2011-12-19 15:07 2011-10-25 Show GitHub Exploit DB Packet Storm
252273 7.5 危険 The Cacti Group - Cacti の auth_login.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2011-4824 2011-12-19 15:06 2011-09-26 Show GitHub Exploit DB Packet Storm
252274 4.3 警告 Atlassian - Atlassian FishEye のユーザプロファイル機能におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-4822 2011-12-19 15:05 2011-10-24 Show GitHub Exploit DB Packet Storm
252275 3.6 注意 Artsoft Entertainment - Artsoft Entertainment の Rocks'n'Diamonds における任意のファイルを上書きされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2011-4606 2011-12-19 15:05 2011-12-15 Show GitHub Exploit DB Packet Storm
252276 4.3 警告 Digium - Asterisk の channels/chan_sip.c におけるサービス運用妨害 (DoS) の脆弱性 CWE-200
情報漏えい
CVE-2011-4598 2011-12-19 15:03 2011-11-2 Show GitHub Exploit DB Packet Storm
252277 5 警告 Digium - Asterisk の UDP 実装での SIP におけるユーザ名を列挙される脆弱性 CWE-200
情報漏えい
CVE-2011-4597 2011-12-19 15:01 2011-07-18 Show GitHub Exploit DB Packet Storm
252278 7.5 危険 Caupo.Net - CaupoShop Pro および CaupoShop Classic におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2011-4832 2011-12-19 13:44 2011-12-15 Show GitHub Exploit DB Packet Storm
252279 4 警告 David Azoulay - Web File Browser の webFileBrowser.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2011-4831 2011-12-19 13:43 2011-12-15 Show GitHub Exploit DB Packet Storm
252280 7.5 危険 e4j Extensions for Joomla - Joomla! 用 Vik Real Estate コンポーネントにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2011-4823 2011-12-19 11:52 2011-12-15 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 24, 2026, 4:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
254481 7.8 HIGH
Local
lcdf gifsicle A double-free bug in the read_gif function in gifread.c in gifsicle 1.90 allows a remote attacker to cause a denial-of-service attack or unspecified other impact via a maliciously crafted file, becau… CWE-415
 Double Free
CVE-2017-18120 2024-11-21 12:19 2018-02-2 Show GitHub Exploit DB Packet Storm
254482 5.5 MEDIUM
Local
qemu
debian
canonical
qemu
debian_linux
ubuntu_linux
Integer overflow in the macro ROUND_UP (n, d) in Quick Emulator (Qemu) allows a user to cause a denial of service (Qemu process crash). CWE-190
 Integer Overflow or Wraparound
CVE-2017-18043 2024-11-21 12:19 2018-02-1 Show GitHub Exploit DB Packet Storm
254483 7.8 HIGH
Local
7-zip
debian
7-zip
p7zip
debian_linux
Heap-based buffer overflow in the NCompress::NShrink::CDecoder::CodeReal method in 7-Zip before 18.00 and p7zip allows remote attackers to cause a denial of service (out-of-bounds write) or potential… CWE-787
 Out-of-bounds Write
CVE-2017-17969 2024-11-21 12:19 2018-01-31 Show GitHub Exploit DB Packet Storm
254484 7.8 HIGH
Local
linux
canonical
linux_kernel
ubuntu_linux
drivers/input/serio/i8042.c in the Linux kernel before 4.12.4 allows attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact becau… CWE-476
 NULL Pointer Dereference
CVE-2017-18079 2024-11-21 12:19 2018-01-29 Show GitHub Exploit DB Packet Storm
254485 7.8 HIGH
Local
systemd_project
debian
opensuse
systemd
debian_linux
leap
systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the fs.protected_hardlinks sysctl is turned off, which allows local users to bypass… CWE-59
Link Following
CVE-2017-18078 2024-11-21 12:19 2018-01-29 Show GitHub Exploit DB Packet Storm
254486 7.5 HIGH
Network
brace_expansion_project brace_expansion index.js in brace-expansion before 1.1.7 is vulnerable to Regular Expression Denial of Service (ReDoS) attacks, as demonstrated by an expand argument containing many comma characters. CWE-20
 Improper Input Validation 
CVE-2017-18077 2024-11-21 12:19 2018-01-27 Show GitHub Exploit DB Packet Storm
254487 9.8 CRITICAL
Network
perfexcrm perfex_crm In Utilities.php in Perfex CRM 1.9.7, Unrestricted file upload can lead to remote code execution. CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2017-17976 2024-11-21 12:19 2018-01-27 Show GitHub Exploit DB Packet Storm
254488 7.5 HIGH
Network
omniauth
debian
omniauth
debian_linux
In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value is improperly protected because POST (in addition to GET) parameters are stored in the session and become available in the enviro… NVD-CWE-noinfo
CVE-2017-18076 2024-11-21 12:19 2018-01-27 Show GitHub Exploit DB Packet Storm
254489 7.8 HIGH
Local
linux
canonical
linux_kernel
ubuntu_linux
crypto/pcrypt.c in the Linux kernel before 4.14.13 mishandles freeing instances, allowing a local user able to access the AF_ALG-based AEAD interface (CONFIG_CRYPTO_USER_API_AEAD) and pcrypt (CONFIG_… CWE-763
 Release of Invalid Pointer or Reference
CVE-2017-18075 2024-11-21 12:19 2018-01-24 Show GitHub Exploit DB Packet Storm
254490 4.4 MEDIUM
Local
qemu
debian
qemu
debian_linux
The cirrus_invalidate_region function in hw/display/cirrus_vga.c in Qemu allows local OS guest privileged users to cause a denial of service (out-of-bounds array access and QEMU process crash) via ve… CWE-125
Out-of-bounds Read
CVE-2017-18030 2024-11-21 12:19 2018-01-24 Show GitHub Exploit DB Packet Storm