Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":April 30, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
253761 6.8 警告 マイクロソフト - Microsoft Windows の kernel における権限を取得される脆弱性 CWE-20
不適切な入力確認
CVE-2009-1127 2010-01-4 15:24 2009-11-10 Show GitHub Exploit DB Packet Storm
253762 10 危険 マイクロソフト - Microsoft Windows の License Logging Server (llssrv.exe) における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2009-2523 2010-01-4 15:24 2009-11-10 Show GitHub Exploit DB Packet Storm
253763 9.3 危険 マイクロソフト - Microsoft Windows の Web Services on Devices API (WSDAPI) における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2009-2512 2010-01-4 15:23 2009-11-10 Show GitHub Exploit DB Packet Storm
253764 10 危険 アップル
VMware
サン・マイクロシステムズ
- Sun Java SE の Provider クラスにおける詳細不明な脆弱性 CWE-noinfo
情報不足
CVE-2009-2722 2010-01-4 14:56 2009-08-10 Show GitHub Exploit DB Packet Storm
253765 10 危険 アップル
VMware
サン・マイクロシステムズ
- Sun Java SE の Provider クラスにおける詳細不明な脆弱性 CWE-noinfo
情報不足
CVE-2009-2723 2010-01-4 14:55 2009-08-10 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 1, 2026, 4:54 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
280461 7.8 HIGH
Local
enlightenment enlightenment An unspecified setuid root helper in Enlightenment before 0.17.6 allows local users to gain privileges by leveraging failure to properly sanitize the environment. CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-1845 2024-11-21 11:05 2018-04-28 Show GitHub Exploit DB Packet Storm
280462 7.5 HIGH
Network
eshtery.she7ata eshtery_cms Absolute path traversal vulnerability in Eshtery CMS allows remote attackers to read arbitrary files via a full pathname in the file parameter to FileManager.aspx. CWE-22
Path Traversal
CVE-2014-2069 2024-11-21 11:05 2018-04-16 Show GitHub Exploit DB Packet Storm
280463 5.3 MEDIUM
Network
open-xchange open-xchange_appsuite The backend in Open-Xchange (OX) AppSuite 7.4.2 before 7.4.2-rev9 allows remote attackers to obtain sensitive information about user email addresses in opportunistic circumstances by leveraging a fai… CWE-200
Information Exposure
CVE-2014-2078 2024-11-21 11:05 2018-04-11 Show GitHub Exploit DB Packet Storm
280464 9.8 CRITICAL
Network
3ds catia Stack-based buffer overflow in Dassault Systemes CATIA V5-6R2013 allows remote attackers to execute arbitrary code via a crafted packet, related to "CATV5_Backbone_Bus." CWE-787
 Out-of-bounds Write
CVE-2014-2073 2024-11-21 11:05 2018-04-11 Show GitHub Exploit DB Packet Storm
280465 8.8 HIGH
Network
opendocman opendocman OpenDocMan 1.2.7 and earlier does not properly validate allowed actions, which allows remote authenticated users to bypass an intended access restrictions and assign administrative privileges to them… CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-1946 2024-11-21 11:05 2018-04-11 Show GitHub Exploit DB Packet Storm
280466 6.5 MEDIUM
Network
buddypress buddypress The Group creation process in the Buddypress plugin before 1.9.2 for WordPress allows remote authenticated users to gain control of arbitrary groups by leveraging a missing permissions check. CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-1889 2024-11-21 11:05 2018-04-11 Show GitHub Exploit DB Packet Storm
280467 9.8 CRITICAL
Network
owncloud owncloud The user_openid app in ownCloud Server before 5.0.15 allows remote attackers to obtain access by leveraging an insecure OpenID implementation. CWE-284
Improper Access Control
CVE-2014-2048 2024-11-21 11:05 2018-03-27 Show GitHub Exploit DB Packet Storm
280468 5.9 MEDIUM
Network
maradns_project
deadwood_project
maradns
deadwood
Deadwood before 2.3.09, 3.x before 3.2.05, and as used in MaraDNS before 1.4.14 and 2.x before 2.0.09, allow remote attackers to cause a denial of service (out-of-bounds read and crash) by leveraging… CWE-20
CWE-125
 Improper Input Validation 
Out-of-bounds Read
CVE-2014-2032 2024-11-21 11:05 2018-03-21 Show GitHub Exploit DB Packet Storm
280469 5.9 MEDIUM
Network
maradns_project
deadwood_project
maradns
deadwood
Deadwood before 2.3.09, 3.x before 3.2.05, and as used in MaraDNS before 1.4.14 and 2.x before 2.0.09, allow remote attackers to cause a denial of service (out-of-bounds read and crash) by leveraging… CWE-125
Out-of-bounds Read
CVE-2014-2031 2024-11-21 11:05 2018-03-21 Show GitHub Exploit DB Packet Storm
280470 8.8 HIGH
Network
subscribe_to_comments_reloaded_project subscribe_to_comments_reloaded Cross-site request forgery (CSRF) vulnerability in the Subscribe To Comments Reloaded plugin before 140219 for WordPress allows remote attackers to hijack the authentication of administrators for req… CWE-352
 Origin Validation Error
CVE-2014-2274 2024-11-21 11:05 2018-03-20 Show GitHub Exploit DB Packet Storm