Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 26, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
253291 10 危険 ioquake3
smokin-guns
openarena
worldofpadman
urbanterror
tremulous
- World of Padman などの製品で使用される ioQuake3 エンジンの FS_CheckFilenameIsNotExecutable 関数における任意のコードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2011-2764 2012-03-27 18:43 2011-08-3 Show GitHub Exploit DB Packet Storm
253292 5 警告 IBM - IBM TDS の IDSWebApp のログインページにおけるアクセス権を取得される脆弱性 CWE-200
情報漏えい
CVE-2011-2759 2012-03-27 18:43 2011-05-10 Show GitHub Exploit DB Packet Storm
253293 5 警告 IBM - IBM TDS の IDSWebApp における重要な情報を取得される脆弱性 CWE-287
不適切な認証
CVE-2011-2758 2012-03-27 18:43 2011-06-27 Show GitHub Exploit DB Packet Storm
253294 5 警告 Zoho Corporation - ManageEngine ServiceDesk Plus の FileDownload.jsp におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2011-2757 2012-03-27 18:43 2011-07-17 Show GitHub Exploit DB Packet Storm
253295 5 警告 Zoho Corporation - ManageEngine ServiceDesk Plus の FileDownload.jsp における特定のディレクトリからファイルを読まれる脆弱性 CWE-287
不適切な認証
CVE-2011-2756 2012-03-27 18:43 2011-07-17 Show GitHub Exploit DB Packet Storm
253296 5 警告 Zoho Corporation - ManageEngine ServiceDesk Plus の FileDownload.jsp におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2011-2755 2012-03-27 18:43 2011-07-17 Show GitHub Exploit DB Packet Storm
253297 4.3 警告 IBM - IBM WCM および他の製品で使用される IBM WebSphere Portal の PageBuilder2 テーマにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-2754 2012-03-27 18:43 2011-07-17 Show GitHub Exploit DB Packet Storm
253298 6.8 警告 SquirrelMail Project - SquirrelMail におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2011-2753 2012-03-27 18:43 2011-07-12 Show GitHub Exploit DB Packet Storm
253299 5.8 警告 SquirrelMail Project - SquirrelMail における CRLF インジェクションの脆弱性 CWE-94
コード・インジェクション
CVE-2011-2752 2012-03-27 18:43 2011-07-11 Show GitHub Exploit DB Packet Storm
253300 7.5 危険 parodia - Parodia における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2011-2751 2012-03-27 18:43 2011-07-17 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 26, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
245471 7.2 HIGH
Network
pbootcms pbootcms PbootCMS 1.2.2 allows remote attackers to execute arbitrary PHP code by specifying a .php filename in a "SET GLOBAL general_log_file" statement, followed by a SELECT statement containing this PHP cod… CWE-94
Code Injection
CVE-2018-19053 2024-11-21 12:57 2018-11-7 Show GitHub Exploit DB Packet Storm
245472 7.5 HIGH
Network
lighttpd
suse
opensuse
debian
lighttpd
suse_linux_enterprise_server
leap
backports_sle
debian_linux
An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50. There is potential ../ path traversal of a single directory above an alias target, with a specific mod_… CWE-22
Path Traversal
CVE-2018-19052 2024-11-21 12:57 2018-11-7 Show GitHub Exploit DB Packet Storm
245473 10.0 CRITICAL
Network
mpdf_project mpdf mPDF through 7.1.6, if deployed as a web application that accepts arbitrary HTML, allows SSRF, as demonstrated by a '<img src="http://192.168' substring that triggers a call to getImage in Image/Imag… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2018-19047 2024-11-21 12:57 2018-11-7 Show GitHub Exploit DB Packet Storm
245474 6.1 MEDIUM
Network
metinfo metinfo MetInfo 6.1.3 has XSS via the admin/index.php?a=dogetpassword abt_type parameter. CWE-79
Cross-site Scripting
CVE-2018-19051 2024-11-21 12:57 2018-11-7 Show GitHub Exploit DB Packet Storm
245475 6.1 MEDIUM
Network
metinfo metinfo MetInfo 6.1.3 has XSS via the admin/index.php?a=dogetpassword langset parameter. CWE-79
Cross-site Scripting
CVE-2018-19050 2024-11-21 12:57 2018-11-7 Show GitHub Exploit DB Packet Storm
245476 6.5 MEDIUM
Network
jenkins jenkins A improper authorization vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in UpdateCenter.java that allows attackers to cancel a Jenkins restart scheduled through the update cen… CWE-863
 Incorrect Authorization
CVE-2018-1999047 2024-11-21 12:57 2018-08-24 Show GitHub Exploit DB Packet Storm
245477 4.3 MEDIUM
Network
jenkins jenkins A exposure of sensitive information vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in Computer.java that allows attackers With Overall/Read permission to access the connection… CWE-200
Information Exposure
CVE-2018-1999046 2024-11-21 12:57 2018-08-24 Show GitHub Exploit DB Packet Storm
245478 5.4 MEDIUM
Network
jenkins jenkins A improper authentication vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in SecurityRealm.java, TokenBasedRememberMeServices2.java that allows attackers with a valid cookie to… CWE-287
Improper Authentication
CVE-2018-1999045 2024-11-21 12:57 2018-08-24 Show GitHub Exploit DB Packet Storm
245479 6.5 MEDIUM
Network
jenkins jenkins A denial of service vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in CronTab.java that allows attackers with Overall/Read permission to have a request handling thread enter a… CWE-835
 Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2018-1999044 2024-11-21 12:57 2018-08-24 Show GitHub Exploit DB Packet Storm
245480 7.5 HIGH
Network
jenkins jenkins A denial of service vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in BasicAuthenticationFilter.java, BasicHeaderApiTokenAuthenticator.java that allows attackers to create eph… CWE-772
 Missing Release of Resource after Effective Lifetime
CVE-2018-1999043 2024-11-21 12:57 2018-08-24 Show GitHub Exploit DB Packet Storm