Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 1, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
253121 7.5 危険 ターボリナックス
MySQL AB
- MySQL で使用される yaSSL における複数のスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-4484 2010-08-3 18:59 2009-12-30 Show GitHub Exploit DB Packet Storm
253122 2.1 注意 オラクル - Oracle Database Server の Export コンポーネントにおける脆弱性 CWE-noinfo
情報不足
CVE-2010-0901 2010-08-2 19:32 2010-07-13 Show GitHub Exploit DB Packet Storm
253123 2.6 注意 オラクル - Windows 上で稼働する Oracle Database Server の Network Layer コンポーネントにおける脆弱性 CWE-noinfo
情報不足
CVE-2010-0900 2010-08-2 19:32 2010-07-13 Show GitHub Exploit DB Packet Storm
253124 4.3 警告 オラクル - Oracle Database Server の Application Express コンポーネントにおける脆弱性 CWE-noinfo
情報不足
CVE-2010-0892 2010-08-2 19:32 2010-07-13 Show GitHub Exploit DB Packet Storm
253125 6 警告 オラクル - Oracle Database Server の Oracle OLAP コンポーネントにおける脆弱性 CWE-noinfo
情報不足
CVE-2010-0902 2010-08-2 19:31 2010-07-13 Show GitHub Exploit DB Packet Storm
253126 7.8 危険 オラクル - Windows 上で稼働する Oracle Database Server の Net Foundation Layer コンポーネントにおける脆弱性 CWE-noinfo
情報不足
CVE-2010-0903 2010-08-2 19:31 2010-07-13 Show GitHub Exploit DB Packet Storm
253127 7.8 危険 オラクル - Oracle Database Server の Listener コンポーネントにおける脆弱性 CWE-noinfo
情報不足
CVE-2010-0911 2010-08-2 19:30 2010-07-13 Show GitHub Exploit DB Packet Storm
253128 5.5 警告 PostgreSQL.org
サイバートラスト株式会社
サン・マイクロシステムズ
レッドハット
- PostgreSQL における任意のパラメータ設定を削除される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2010-1975 2010-08-2 17:13 2010-05-19 Show GitHub Exploit DB Packet Storm
253129 5 警告 MySQL AB - MySQL の mysql_uninstall_plugin 関数における任意のプラグインを削除される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2010-1621 2010-08-2 17:13 2010-04-6 Show GitHub Exploit DB Packet Storm
253130 3.5 注意 オラクル - Oracle Fusion Middleware の Application Server Control コンポーネントにおける脆弱性 CWE-noinfo
情報不足
CVE-2010-2381 2010-07-30 17:43 2010-07-13 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 1, 2026, 4:54 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
250531 5.5 MEDIUM
Local
kmplayer kmplayer KMPlayer 4.2.2.4 allows remote attackers to cause a denial of service via a crafted NSV file. CWE-20
 Improper Input Validation 
CVE-2017-16952 2024-11-21 12:17 2017-11-29 Show GitHub Exploit DB Packet Storm
250532 5.5 MEDIUM
Local
audiovalley winamp_pro Winamp Pro 5.66 Build 3512 allows remote attackers to cause a denial of service via a crafted WAV, WMV, AU, ASF, AIFF, or AIF file. CWE-20
 Improper Input Validation 
CVE-2017-16951 2024-11-21 12:17 2017-11-29 Show GitHub Exploit DB Packet Storm
250533 5.5 MEDIUM
Local
linux linux_kernel The walk_hugetlb_range function in mm/pagewalk.c in the Linux kernel before 4.14.2 mishandles holes in hugetlb ranges, which allows local users to obtain sensitive information from uninitialized kern… CWE-200
Information Exposure
CVE-2017-16994 2024-11-21 12:17 2017-11-28 Show GitHub Exploit DB Packet Storm
250534 6.1 MEDIUM
Network
communigate communigate_pro The WebMail components (Crystal, pronto, and pronto4) in CommuniGate Pro before 6.2.1 have stored XSS vulnerabilities via (1) the location or details field of a Google Calendar invitation, (2) a craf… CWE-79
Cross-site Scripting
CVE-2017-16962 2024-11-21 12:17 2017-11-27 Show GitHub Exploit DB Packet Storm
250535 6.5 MEDIUM
Network
bigtreecms bigtree_cms A SQL injection vulnerability in core/inc/auto-modules.php in BigTree CMS through 4.2.19 allows remote authenticated attackers to obtain information in the context of the user used by the application… CWE-89
SQL Injection
CVE-2017-16961 2024-11-21 12:17 2017-11-27 Show GitHub Exploit DB Packet Storm
250536 8.8 HIGH
Network
tp-link tl-wvr300
tl-wvr302
tl-wvr450g
tl-wvr900g
tl-er5510g
tl-er5520g
tl-er6120g
tl-er6520g
tl-r473
tl-r478
tl-r478\+
tl-r478g\+
tl-r483
tl-r483g
tl-r488
tl-r42…
TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bindif field of an admin/interface command to cgi-bin/… CWE-78
OS Command 
CVE-2017-16960 2024-11-21 12:17 2017-11-27 Show GitHub Exploit DB Packet Storm
250537 6.1 MEDIUM
Network
symphony_project symphony b3log Symphony (aka Sym) 2.2.0 allows an XSS attack by sending a private letter with a certain /article URI, and a second private letter with a modified title. CWE-79
Cross-site Scripting
CVE-2017-16956 2024-11-21 12:17 2017-11-27 Show GitHub Exploit DB Packet Storm
250538 8.8 HIGH
Network
inlinks_project inlinks SQL injection vulnerability in the InLinks plugin through 1.1 for WordPress allows authenticated users to execute arbitrary SQL commands via the "keyword" parameter to /wp-admin/options-general.php?p… CWE-89
SQL Injection
CVE-2017-16955 2024-11-21 12:17 2017-11-27 Show GitHub Exploit DB Packet Storm
250539 6.5 MEDIUM
Network
tp-link tl-wvr300_firmware
tl-wvr302_firmware
tl-wvr450_firmware
tl-wvr450l_firmware
tl-wvr450g_firmware
tl-wvr458_firmware
tl-wvr458l_firmware
tl-wvr458p_firmware
tl-wvr900g_firmware…
The locale feature in cgi-bin/luci on TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allows remote authenticated users to test for the existence of arbitrary files by making an operation=write;local… CWE-22
Path Traversal
CVE-2017-16959 2024-11-21 12:17 2017-11-27 Show GitHub Exploit DB Packet Storm
250540 8.8 HIGH
Network
tp-link tl-wvr300_firmware
tl-wvr302_firmware
tl-wvr450_firmware
tl-wvr450l_firmware
tl-wvr450g_firmware
tl-wvr458_firmware
tl-wvr458l_firmware
tl-wvr458p_firmware
tl-wvr900g_firmware…
TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bindif field of an admin/bridge command to cgi-bin/luc… CWE-78
OS Command 
CVE-2017-16958 2024-11-21 12:17 2017-11-27 Show GitHub Exploit DB Packet Storm