Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 20, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
253411 6.4 警告 Ruby on Rails project - Ruby on Rails における任意のレコードを変更される脆弱性 CWE-20
不適切な入力確認
CVE-2010-3933 2012-03-27 18:42 2010-10-15 Show GitHub Exploit DB Packet Storm
253412 4.3 警告 Vtiger - vtiger CRM におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-3911 2012-03-27 18:42 2010-11-26 Show GitHub Exploit DB Packet Storm
253413 6.8 警告 Vtiger - vtiger CRM の return_application_language 関数におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2010-3910 2012-03-27 18:42 2010-11-26 Show GitHub Exploit DB Packet Storm
253414 6.8 警告 FFmpeg
mplayerhq
- MPlayer などの製品で使用される FFmpeg におけるサービス運用妨害 (DoS) 状態の脆弱性 CWE-119
バッファエラー
CVE-2010-3908 2012-03-27 18:42 2011-05-20 Show GitHub Exploit DB Packet Storm
253415 6 警告 Vtiger - vtiger CRM の config.template.php における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2010-3909 2012-03-27 18:42 2010-11-26 Show GitHub Exploit DB Packet Storm
253416 9.3 危険 VideoLAN - VideoLAN VLC Media Player の Real demuxer プラグインにおける整数オーバーフローの脆弱性 CWE-189
数値処理の問題
CVE-2010-3907 2012-03-27 18:42 2010-12-14 Show GitHub Exploit DB Packet Storm
253417 7.5 危険 Eucalyptus Systems - Eucalyptus の管理者のインターフェース のパスワードリセット機能における権限を取得される脆弱性 CWE-287
不適切な認証
CVE-2010-3905 2012-03-27 18:42 2010-12-16 Show GitHub Exploit DB Packet Storm
253418 5 警告 infradead - OpenConnect におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2010-3903 2012-03-27 18:42 2010-10-14 Show GitHub Exploit DB Packet Storm
253419 5 警告 infradead - OpenConnect における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2010-3902 2012-03-27 18:42 2010-10-14 Show GitHub Exploit DB Packet Storm
253420 6.4 警告 infradead - OpenConnect における任意の AnyConnect SSL VPN サーバを偽装される脆弱性 CWE-20
不適切な入力確認
CVE-2010-3901 2012-03-27 18:42 2010-10-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 20, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
246171 9.8 CRITICAL
Network
control-webpanel webpanel CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Command Injection via shell metacharacters in the admin/index.php service_start, service_restart, service_fullstatus, or service_stop para… CWE-78
OS Command 
CVE-2018-18322 2024-11-21 12:55 2018-10-15 Show GitHub Exploit DB Packet Storm
246172 7.5 HIGH
Network
qiku 360_mobile_phone_n6_pro_firmware The /dev/block/mmcblk0rpmb driver kernel module on Qiku 360 Phone N6 Pro 1801-A01 devices allows attackers to cause a denial of service (NULL pointer dereference and device crash) via a crafted 0xc0d… CWE-476
 NULL Pointer Dereference
CVE-2018-18318 2024-11-21 12:55 2018-10-15 Show GitHub Exploit DB Packet Storm
246173 8.8 HIGH
Network
dscms_project dscms DESHANG DSCMS 1.1 has CSRF via the public/index.php/admin/admin/add.html URI. CWE-352
 Origin Validation Error
CVE-2018-18317 2024-11-21 12:55 2018-10-15 Show GitHub Exploit DB Packet Storm
246174 8.8 HIGH
Network
emlog emlog emlog v6.0.0 has CSRF via the admin/user.php?action=new URI. CWE-352
 Origin Validation Error
CVE-2018-18316 2024-11-21 12:55 2018-10-15 Show GitHub Exploit DB Packet Storm
246175 7.5 HIGH
Network
mossle lemon com/mossle/cdn/CdnController.java in lemon 1.9.0 allows attackers to upload arbitrary files because the copyMultipartFileToFile method in CdnUtils only checks for a ../ substring, and does not valida… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2018-18315 2024-11-21 12:55 2018-10-15 Show GitHub Exploit DB Packet Storm
246176 5.5 MEDIUM
Local
elfutils_project
debian
redhat
opensuse
canonical
elfutils
debian_linux
enterprise_linux_desktop
enterprise_linux_workstation
enterprise_linux_server
leap
ubuntu_linux
An invalid memory address dereference was discovered in dwfl_segment_report_module.c in libdwfl in elfutils through v0.174. The vulnerability allows attackers to cause a denial of service (applicatio… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2018-18310 2024-11-21 12:55 2018-10-15 Show GitHub Exploit DB Packet Storm
246177 5.5 MEDIUM
Local
gnu binutils An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. An invalid memory address dereference was discovered in read_reloc in reloc.c. T… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2018-18309 2024-11-21 12:55 2018-10-15 Show GitHub Exploit DB Packet Storm
246178 6.1 MEDIUM
Network
metinfo metinfo MetInfo 6.1.2 has XSS via the /admin/index.php bigclass parameter in an n=column&a=doadd action. CWE-79
Cross-site Scripting
CVE-2018-18296 2024-11-21 12:55 2018-10-15 Show GitHub Exploit DB Packet Storm
246179 6.1 MEDIUM
Network
asus rt-ac58u_firmware A cross site scripting (XSS) vulnerability on ASUS RT-AC58U 3.0.0.4.380_6516 devices allows remote attackers to inject arbitrary web script or HTML via Advanced_ASUSDDNS_Content.asp, Advanced_WSecuri… CWE-79
Cross-site Scripting
CVE-2018-18291 2024-11-21 12:55 2018-10-15 Show GitHub Exploit DB Packet Storm
246180 4.8 MEDIUM
Network
nconsulting nc-cms An issue was discovered in nc-cms through 2017-03-10. index.php?action=edit_html&name=home_content allows XSS via the HTML Source Editor. NOTE: the vendor disputes this because the form requires admi… CWE-79
Cross-site Scripting
CVE-2018-18290 2024-11-21 12:55 2018-10-15 Show GitHub Exploit DB Packet Storm