Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 22, 2026, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
253101 7.5 危険 openarena
ioquake3
worldofpadman
- World of Padman および OpenArena で使用される ioQuake3 エンジンの sys/sys_unix.c における任意のコマンドを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2011-1412 2012-03-27 18:43 2011-08-3 Show GitHub Exploit DB Packet Storm
253102 5 警告 Ulli Horlacher - F*EX におけるファイルをアップロードされる脆弱性 CWE-287
不適切な認証
CVE-2011-1409 2012-03-27 18:43 2011-06-24 Show GitHub Exploit DB Packet Storm
253103 7.5 危険 Exim Development - Exim の DKIM 実装における任意のコードを実行させる脆弱性 CWE-20
不適切な入力確認
CVE-2011-1407 2012-03-27 18:43 2011-05-16 Show GitHub Exploit DB Packet Storm
253104 4.3 警告 Mahara - Mahara における資格情報を取得される脆弱性 CWE-16
環境設定
CVE-2011-1406 2012-03-27 18:43 2011-05-13 Show GitHub Exploit DB Packet Storm
253105 3.5 注意 Mahara - Mahara におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-1405 2012-03-27 18:43 2011-05-13 Show GitHub Exploit DB Packet Storm
253106 4 警告 Mahara - Mahara における重要な情報を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2011-1404 2012-03-27 18:43 2011-05-13 Show GitHub Exploit DB Packet Storm
253107 6.8 警告 Mahara - Mahara の pieforms の実装におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2011-1403 2012-03-27 18:43 2011-05-13 Show GitHub Exploit DB Packet Storm
253108 6.5 警告 Mahara - Mahara におけるアクセスをブロックされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2011-1402 2012-03-27 18:43 2011-05-13 Show GitHub Exploit DB Packet Storm
253109 3.5 注意 ikiwiki - ikiwiki におけるクロスサイトスクリプティング攻撃をされる脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-1401 2012-03-27 18:43 2011-04-11 Show GitHub Exploit DB Packet Storm
253110 6.8 警告 Debian
Canonical
- Debian GNU/Linux squeeze などの製品で使用される shell_escape_commands 命令の初期設定における任意のコードを実行される脆弱性 CWE-16
環境設定
CVE-2011-1400 2012-03-27 18:43 2011-03-22 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 23, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
245791 7.5 HIGH
Network
lulucms lulu_cms An issue was discovered in LuLu CMS through 2015-05-14. backend\modules\filemanager\controllers\DefaultController.php allows arbitrary file upload by entering a filename, directory name, and PHP code… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2018-18771 2024-11-21 12:56 2018-10-29 Show GitHub Exploit DB Packet Storm
245792 9.1 CRITICAL
Network
cesanta mongoose An exploitable arbitrary memory read vulnerability exists in the MQTT packet-parsing functionality of Cesanta Mongoose 6.13. It is a heap-based buffer over-read in mg_mqtt_next_subscribe_topic. A spe… CWE-125
Out-of-bounds Read
CVE-2018-18765 2024-11-21 12:56 2018-10-29 Show GitHub Exploit DB Packet Storm
245793 9.1 CRITICAL
Network
cesanta mongoose An exploitable arbitrary memory read vulnerability exists in the MQTT packet-parsing functionality of Cesanta Mongoose 6.13. It is a heap-based buffer over-read in a parse_mqtt getu16 call. A special… CWE-125
Out-of-bounds Read
CVE-2018-18764 2024-11-21 12:56 2018-10-29 Show GitHub Exploit DB Packet Storm
245794 9.8 CRITICAL
Network
zyxel vmg3312-b10b_firmware ZyXEL VMG3312-B10B 1.00(AAPP.7) devices have a backdoor root account with the tTn3+Z@!Sr0O+ password hash in the etc/default.cfg file. CWE-522
 Insufficiently Protected Credentials
CVE-2018-18754 2024-11-21 12:56 2018-10-29 Show GitHub Exploit DB Packet Storm
245795 9.8 CRITICAL
Network
typecho typecho Typecho V1.1 allows remote attackers to send shell commands via base64-encoded serialized data, as demonstrated by SSRF. CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2018-18753 2024-11-21 12:56 2018-10-29 Show GitHub Exploit DB Packet Storm
245796 9.8 CRITICAL
Network
webiness_project webiness_inventory Webiness Inventory 2.3 suffers from an Arbitrary File upload vulnerability via PHP code in the protected/library/ajax/WsSaveToModel.php logo parameter. CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2018-18752 2024-11-21 12:56 2018-10-29 Show GitHub Exploit DB Packet Storm
245797 9.8 CRITICAL
Network
gnu
canonical
redhat
gettext
ubuntu_linux
enterprise_linux
An issue was discovered in GNU gettext 0.19.8. There is a double free in default_add_message in read-catalog.c, related to an invalid free in po_gram_parse in po-gram-gen.y, as demonstrated by lt-msg… CWE-415
 Double Free
CVE-2018-18751 2024-11-21 12:56 2018-10-29 Show GitHub Exploit DB Packet Storm
245798 5.5 MEDIUM
Local
data_tools_project data_tools data-tools through 2017-07-26 has an Integer Overflow leading to an incorrect end value for the write_wchars function. CWE-190
 Integer Overflow or Wraparound
CVE-2018-18749 2024-11-21 12:56 2018-10-29 Show GitHub Exploit DB Packet Storm
245799 10.0 CRITICAL
Network
sandboxie sandboxie Sandboxie 5.26 allows a Sandbox Escape via an "import os" statement, followed by os.system("cmd") or os.system("powershell"), within a .py file. NOTE: the vendor disputes this issue because the obser… NVD-CWE-noinfo
CVE-2018-18748 2024-11-21 12:56 2018-10-29 Show GitHub Exploit DB Packet Storm
245800 4.8 MEDIUM
Network
sem-cms semcms An XSS issue was discovered in SEMCMS 3.4 via admin/SEMCMS_Menu.php?lgid=1 during editing. CWE-79
Cross-site Scripting
CVE-2018-18745 2024-11-21 12:56 2018-10-29 Show GitHub Exploit DB Packet Storm