Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 8, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
253601 10 危険 リアルネットワークス - RealNetworks RealPlayer における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2011-4254 2011-11-28 10:22 2011-11-18 Show GitHub Exploit DB Packet Storm
253602 9.3 危険 リアルネットワークス - RealNetworks RealPlayer における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2011-4251 2011-11-28 10:18 2011-11-18 Show GitHub Exploit DB Packet Storm
253603 9.3 危険 リアルネットワークス - RealNetworks RealPlayer における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2011-4248 2011-11-28 10:16 2011-11-18 Show GitHub Exploit DB Packet Storm
253604 10 危険 リアルネットワークス - RealNetworks RealPlayer におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2011-4244 2011-11-28 10:13 2011-11-18 Show GitHub Exploit DB Packet Storm
253605 4.3 警告 Beanbag - Review Board の commenting system におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-4312 2011-11-25 16:03 2011-11-15 Show GitHub Exploit DB Packet Storm
253606 3.2 注意 ヒューレット・パッカード - HP Operations Agent および Performance Agent におけるディレクトリアクセス制限を回避される脆弱性 CWE-noinfo
情報不足
CVE-2011-4160 2011-11-25 16:02 2011-11-22 Show GitHub Exploit DB Packet Storm
253607 7.5 危険 Technicolor - Thomson TG585 上の UPnP IGD の実装における任意のポートマッピングを確立される脆弱性 CWE-16
環境設定
CVE-2011-4506 2011-11-25 14:33 2011-11-22 Show GitHub Exploit DB Packet Storm
253608 7.5 危険 日本アルカテル・ルーセント - SpeedTouch 5x6 上の UPnP IGD の実装における任意のポートマッピングを確立される脆弱性 CWE-16
環境設定
CVE-2011-4505 2011-11-25 14:32 2011-11-22 Show GitHub Exploit DB Packet Storm
253609 7.5 危険 ZyXEL
Genmei Mori
- ZyXEL P-330W におけるポートマッピングによる通信を確立される脆弱性 CWE-16
環境設定
CVE-2011-4504 2011-11-25 14:31 2011-11-22 Show GitHub Exploit DB Packet Storm
253610 7.5 危険 Sitecom
Broadcom
- Sitecom WL-111 上で動作する Broadcom Linux の UPnP IGD 実装におけるポートマッピングを確立される脆弱性 CWE-16
環境設定
CVE-2011-4503 2011-11-25 14:31 2011-11-22 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 8, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
246351 9.8 CRITICAL
Network
qualcomm mdm9150_firmware
mdm9206_firmware
mdm9607_firmware
mdm9635m_firmware
mdm9650_firmware
mdm9655_firmware
msm8909w_firmware
qcs605_firmware
qm215_firmware
sd_210_firmware
s…
Untrusted header fields in GNSS XTRA3 function can lead to integer overflow in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon W… CWE-190
 Integer Overflow or Wraparound
CVE-2018-13887 2024-11-21 12:48 2019-05-25 Show GitHub Exploit DB Packet Storm
246352 9.8 CRITICAL
Network
qualcomm mdm9150_firmware
mdm9206_firmware
mdm9607_firmware
mdm9615_firmware
mdm9635m_firmware
mdm9640_firmware
mdm9650_firmware
mdm9655_firmware
msm8909w_firmware
msm8996au_firmwar…
Unchecked OTA field in GNSS XTRA3 lead to integer overflow and then buffer overflow in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snap… CWE-190
 Integer Overflow or Wraparound
CVE-2018-13886 2024-11-21 12:48 2019-05-25 Show GitHub Exploit DB Packet Storm
246353 5.5 MEDIUM
Local
qualcomm mdm9150_firmware
mdm9206_firmware
mdm9607_firmware
mdm9615_firmware
mdm9625_firmware
mdm9635m_firmware
mdm9650_firmware
mdm9655_firmware
qcs605_firmware
qm215_firmware
s…
Possible memory overread may be lead to access of sensitive data in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in… CWE-200
Information Exposure
CVE-2018-13885 2024-11-21 12:48 2019-05-25 Show GitHub Exploit DB Packet Storm
246354 7.5 HIGH
Network
phoenixcontact fl_switch_3005_firmware
fl_switch_3005t_firmware
fl_switch_3004t-fx_firmware
fl_switch_3004t-fx_st_firmware
fl_switch_3008_firmware
fl_switch_3008t_firmware
fl_switch_3006t-2fx_firm…
The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 is vulnerable to a denial-of-service attack by making more than 120 connections. CWE-400
 Uncontrolled Resource Consumption
CVE-2018-13994 2024-11-21 12:48 2019-05-8 Show GitHub Exploit DB Packet Storm
246355 8.8 HIGH
Network
phoenixcontact fl_switch_3005_firmware
fl_switch_3005t_firmware
fl_switch_3004t-fx_firmware
fl_switch_3004t-fx_st_firmware
fl_switch_3008_firmware
fl_switch_3008t_firmware
fl_switch_3006t-2fx_firm…
The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 is prone to CSRF. CWE-352
 Origin Validation Error
CVE-2018-13993 2024-11-21 12:48 2019-05-8 Show GitHub Exploit DB Packet Storm
246356 9.8 CRITICAL
Network
phoenixcontact fl_switch_3005_firmware
fl_switch_3005t_firmware
fl_switch_3004t-fx_firmware
fl_switch_3004t-fx_st_firmware
fl_switch_3008_firmware
fl_switch_3008t_firmware
fl_switch_3006t-2fx_firm…
The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 allows for plaintext transmission (HTTP) of user credentials by default. CWE-311
Missing Encryption of Sensitive Data
CVE-2018-13992 2024-11-21 12:48 2019-05-8 Show GitHub Exploit DB Packet Storm
246357 5.3 MEDIUM
Network
phoenixcontact fl_switch_3005_firmware
fl_switch_3005t_firmware
fl_switch_3004t-fx_firmware
fl_switch_3004t-fx_st_firmware
fl_switch_3008_firmware
fl_switch_3008t_firmware
fl_switch_3006t-2fx_firm…
The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions 1.0 to 1.34 leaks private information in firmware images. CWE-200
Information Exposure
CVE-2018-13991 2024-11-21 12:48 2019-05-8 Show GitHub Exploit DB Packet Storm
246358 6.1 MEDIUM
Network
impresscms impresscms ImpressCMS 1.3.10 has XSS via the PATH_INFO to htdocs/install/index.php, htdocs/install/page_langselect.php, or htdocs/install/page_modcheck.php. CWE-79
Cross-site Scripting
CVE-2018-13983 2024-11-21 12:48 2019-05-7 Show GitHub Exploit DB Packet Storm
246359 9.8 CRITICAL
Network
phoenixcontact fl_switch_3005_firmware
fl_switch_3005t_firmware
fl_switch_3004t-fx_firmware
fl_switch_3004t-fx_st_firmware
fl_switch_3008_firmware
fl_switch_3008t_firmware
fl_switch_3006t-2fx_firm…
The WebUI of PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, 48xx versions prior to 1.35 is vulnerable to brute-force attacks, because of Improper Restriction of Excessive Authentication Attempts. CWE-287
Improper Authentication
CVE-2018-13990 2024-11-21 12:48 2019-05-7 Show GitHub Exploit DB Packet Storm
246360 6.5 MEDIUM
Network
siemens cp_1604_firmware
cp_1616_firmware
A vulnerability has been identified in CP 1604 (All versions), CP 1616 (All versions). The integrated configuration web server of the affected CP devices could allow a Cross-Site Request Forgery (CSR… CWE-352
 Origin Validation Error
CVE-2018-13810 2024-11-21 12:48 2019-04-17 Show GitHub Exploit DB Packet Storm