Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 19, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
253301 4.3 警告 wellsfargo - Android 用の Wells Fargo Mobile アプリケーションにおける重要な情報を取得される脆弱性 CWE-310
暗号の問題
CVE-2010-4214 2012-03-27 18:42 2010-11-8 Show GitHub Exploit DB Packet Storm
253302 4.3 警告 bankofamerica - Android のバンク・オブ・アメリカのアプリケーションにおける重要な情報を取得される脆弱性 CWE-310
暗号の問題
CVE-2010-4213 2012-03-27 18:42 2010-11-8 Show GitHub Exploit DB Packet Storm
253303 1.9 注意 USAA - USAA application for Android における重要なオンラインバンキングの情報を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2010-4212 2012-03-27 18:42 2010-11-8 Show GitHub Exploit DB Packet Storm
253304 2.9 注意 ebay - PayPal app における Paypal Web サーバになりすまされる脆弱性 CWE-287
不適切な認証
CVE-2010-4211 2012-03-27 18:42 2010-11-8 Show GitHub Exploit DB Packet Storm
253305 7.2 危険 FreeBSD - FreeBSD の pfs_getextattr 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2010-4210 2012-03-27 18:42 2010-11-10 Show GitHub Exploit DB Packet Storm
253306 4.3 警告 Mozilla Foundation
Yahoo!
- Bugzilla で使用される YUI の Flash コンポーネント構造におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-4209 2012-03-27 18:42 2010-11-7 Show GitHub Exploit DB Packet Storm
253307 4.3 警告 Moodle
Yahoo!
Mozilla Foundation
- Bugzilla などの製品で使用される YUI の Flash コンポーネント構造におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-4208 2012-03-27 18:42 2010-11-7 Show GitHub Exploit DB Packet Storm
253308 4.9 警告 Linux - Linux kernel の net/rds/rdma.c における整数オーバーフローの脆弱性 CWE-189
数値処理の問題
CVE-2010-4175 2012-03-27 18:42 2011-01-10 Show GitHub Exploit DB Packet Storm
253309 7.8 危険 Linux - Linux kernel の x25_parse_facilities 関数における整数アンダーフローの脆弱性 CWE-189
数値処理の問題
CVE-2010-4164 2012-03-27 18:42 2011-01-3 Show GitHub Exploit DB Packet Storm
253310 4.3 警告 Moodle
Yahoo!
Mozilla Foundation
- Bugzilla などの製品で使用される YUI の Flash コンポーネント構造におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-4207 2012-03-27 18:42 2010-11-7 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 19, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
245791 7.5 HIGH
Network
lulucms lulu_cms An issue was discovered in LuLu CMS through 2015-05-14. backend\modules\filemanager\controllers\DefaultController.php allows arbitrary file upload by entering a filename, directory name, and PHP code… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2018-18771 2024-11-21 12:56 2018-10-29 Show GitHub Exploit DB Packet Storm
245792 9.1 CRITICAL
Network
cesanta mongoose An exploitable arbitrary memory read vulnerability exists in the MQTT packet-parsing functionality of Cesanta Mongoose 6.13. It is a heap-based buffer over-read in mg_mqtt_next_subscribe_topic. A spe… CWE-125
Out-of-bounds Read
CVE-2018-18765 2024-11-21 12:56 2018-10-29 Show GitHub Exploit DB Packet Storm
245793 9.1 CRITICAL
Network
cesanta mongoose An exploitable arbitrary memory read vulnerability exists in the MQTT packet-parsing functionality of Cesanta Mongoose 6.13. It is a heap-based buffer over-read in a parse_mqtt getu16 call. A special… CWE-125
Out-of-bounds Read
CVE-2018-18764 2024-11-21 12:56 2018-10-29 Show GitHub Exploit DB Packet Storm
245794 9.8 CRITICAL
Network
zyxel vmg3312-b10b_firmware ZyXEL VMG3312-B10B 1.00(AAPP.7) devices have a backdoor root account with the tTn3+Z@!Sr0O+ password hash in the etc/default.cfg file. CWE-522
 Insufficiently Protected Credentials
CVE-2018-18754 2024-11-21 12:56 2018-10-29 Show GitHub Exploit DB Packet Storm
245795 9.8 CRITICAL
Network
typecho typecho Typecho V1.1 allows remote attackers to send shell commands via base64-encoded serialized data, as demonstrated by SSRF. CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2018-18753 2024-11-21 12:56 2018-10-29 Show GitHub Exploit DB Packet Storm
245796 9.8 CRITICAL
Network
webiness_project webiness_inventory Webiness Inventory 2.3 suffers from an Arbitrary File upload vulnerability via PHP code in the protected/library/ajax/WsSaveToModel.php logo parameter. CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2018-18752 2024-11-21 12:56 2018-10-29 Show GitHub Exploit DB Packet Storm
245797 9.8 CRITICAL
Network
gnu
canonical
redhat
gettext
ubuntu_linux
enterprise_linux
An issue was discovered in GNU gettext 0.19.8. There is a double free in default_add_message in read-catalog.c, related to an invalid free in po_gram_parse in po-gram-gen.y, as demonstrated by lt-msg… CWE-415
 Double Free
CVE-2018-18751 2024-11-21 12:56 2018-10-29 Show GitHub Exploit DB Packet Storm
245798 5.5 MEDIUM
Local
data_tools_project data_tools data-tools through 2017-07-26 has an Integer Overflow leading to an incorrect end value for the write_wchars function. CWE-190
 Integer Overflow or Wraparound
CVE-2018-18749 2024-11-21 12:56 2018-10-29 Show GitHub Exploit DB Packet Storm
245799 10.0 CRITICAL
Network
sandboxie sandboxie Sandboxie 5.26 allows a Sandbox Escape via an "import os" statement, followed by os.system("cmd") or os.system("powershell"), within a .py file. NOTE: the vendor disputes this issue because the obser… NVD-CWE-noinfo
CVE-2018-18748 2024-11-21 12:56 2018-10-29 Show GitHub Exploit DB Packet Storm
245800 4.8 MEDIUM
Network
sem-cms semcms An XSS issue was discovered in SEMCMS 3.4 via admin/SEMCMS_Menu.php?lgid=1 during editing. CWE-79
Cross-site Scripting
CVE-2018-18745 2024-11-21 12:56 2018-10-29 Show GitHub Exploit DB Packet Storm