Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 2, 2026, 2 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
253091 3.5 注意 オラクル - Oracle E-Business Suite の Oracle Applications Framework コンポーネントにおける脆弱性 CWE-noinfo
情報不足
CVE-2010-0909 2010-08-5 16:35 2010-07-13 Show GitHub Exploit DB Packet Storm
253092 4.3 警告 オラクル - Oracle E-Business Suite の Oracle Applications Manager コンポーネントにおける脆弱性 CWE-noinfo
情報不足
CVE-2010-0913 2010-08-5 16:35 2010-07-13 Show GitHub Exploit DB Packet Storm
253093 4.3 警告 オラクル - Oracle E-Business Suite の Oracle Applications Manager コンポーネントにおける脆弱性 CWE-noinfo
情報不足
CVE-2010-0905 2010-08-5 16:35 2010-07-13 Show GitHub Exploit DB Packet Storm
253094 4.3 警告 オラクル - Oracle E-Business Suite の Oracle Applications Framework コンポーネントにおける脆弱性 CWE-noinfo
情報不足
CVE-2010-0912 2010-08-5 16:35 2010-07-13 Show GitHub Exploit DB Packet Storm
253095 5.5 警告 オラクル - Oracle E-Business Suite の Oracle Advanced Product Catalog コンポーネントにおける脆弱性 CWE-noinfo
情報不足
CVE-2010-0915 2010-08-5 16:34 2010-07-13 Show GitHub Exploit DB Packet Storm
253096 7.5 危険 オラクル - Oracle E-Business Suite の Oracle Applications Framework コンポーネントにおける脆弱性 CWE-noinfo
情報不足
CVE-2010-0908 2010-08-5 16:34 2010-07-13 Show GitHub Exploit DB Packet Storm
253097 4.3 警告 オラクル - Oracle Enterprise Manager Grid Control の Console コンポーネントにおける脆弱性 CWE-noinfo
情報不足
CVE-2010-2373 2010-08-5 16:33 2010-07-13 Show GitHub Exploit DB Packet Storm
253098 4.3 警告 オラクル - Oracle Fusion Middleware の Oracle Business Process Management コンポーネントにおける脆弱性 CWE-noinfo
情報不足
CVE-2010-2370 2010-08-5 16:33 2010-07-13 Show GitHub Exploit DB Packet Storm
253099 5 警告 オラクル - Oracle Secure Backup における脆弱性 CWE-noinfo
情報不足
CVE-2010-0904 2010-08-5 16:33 2010-07-13 Show GitHub Exploit DB Packet Storm
253100 9 危険 オラクル - Oracle Secure Backup における脆弱性 CWE-noinfo
情報不足
CVE-2010-0906 2010-08-5 16:32 2010-07-13 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 2, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
266601 8.8 HIGH
Network
omniauth omniauth The request phase of the OmniAuth Ruby gem (1.9.1 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without … CWE-352
 Origin Validation Error
CVE-2015-9284 2024-11-21 11:40 2019-04-27 Show GitHub Exploit DB Packet Storm
266602 6.1 MEDIUM
Network
grafana piechart-panel The Pie Chart Panel plugin through 2019-01-02 for Grafana is vulnerable to XSS via legend data or tooltip data. When a chart is included in a Grafana dashboard, this vulnerability could allow an atta… CWE-79
Cross-site Scripting
CVE-2015-9282 2024-11-21 11:40 2019-02-7 Show GitHub Exploit DB Packet Storm
266603 6.1 MEDIUM
Network
sas web_infrastructure_platform Logon Manager in SAS Web Infrastructure Platform before 9.4M3 allows reflected XSS on the Timeout page. CWE-79
Cross-site Scripting
CVE-2015-9281 2024-11-21 11:40 2019-01-17 Show GitHub Exploit DB Packet Storm
266604 10.0 CRITICAL
Network
mailenable mailenable MailEnable before 8.60 allows XXE via an XML document in the request.aspx Options parameter. CWE-611
XXE
CVE-2015-9280 2024-11-21 11:40 2019-01-17 Show GitHub Exploit DB Packet Storm
266605 6.1 MEDIUM
Network
mailenable mailenable MailEnable before 8.60 allows Stored XSS via malformed use of "<img/src" with no ">" character in the body of an e-mail message. CWE-79
Cross-site Scripting
CVE-2015-9279 2024-11-21 11:40 2019-01-17 Show GitHub Exploit DB Packet Storm
266606 9.8 CRITICAL
Network
mailenable mailenable MailEnable before 8.60 allows Privilege Escalation because admin accounts could be created as a consequence of %0A mishandling in AUTH.TAB after a password-change request. CWE-255
Credentials Management
CVE-2015-9278 2024-11-21 11:40 2019-01-17 Show GitHub Exploit DB Packet Storm
266607 9.1 CRITICAL
Network
mailenable mailenable MailEnable before 8.60 allows Directory Traversal for reading the messages of other users, uploading files, and deleting files because "/../" and "/.. /" are mishandled. CWE-22
Path Traversal
CVE-2015-9277 2024-11-21 11:40 2019-01-17 Show GitHub Exploit DB Packet Storm
266608 6.1 MEDIUM
Network
smartertools smartermail SmarterTools SmarterMail before 13.3.5535 was vulnerable to stored XSS by bypassing the anti-XSS mechanisms. It was possible to run JavaScript code when a victim user opens or replies to the attacker… CWE-79
Cross-site Scripting
CVE-2015-9276 2024-11-21 11:40 2019-01-17 Show GitHub Exploit DB Packet Storm
266609 5.3 MEDIUM
Network
arc_project arc ARC 5.21q allows directory traversal via a full pathname in an archive file. CWE-22
Path Traversal
CVE-2015-9275 2024-11-21 11:40 2019-01-8 Show GitHub Exploit DB Packet Storm
266610 6.5 MEDIUM
Network
harfbuzz_project harfbuzz HarfBuzz before 1.0.4 allows remote attackers to cause a denial of service (invalid read of two bytes and application crash) because of GPOS and GSUB table mishandling, related to hb-ot-layout-gpos-t… CWE-125
Out-of-bounds Read
CVE-2015-9274 2024-11-21 11:40 2018-11-15 Show GitHub Exploit DB Packet Storm