Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":April 30, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
253761 6.8 警告 マイクロソフト - Microsoft Windows の kernel における権限を取得される脆弱性 CWE-20
不適切な入力確認
CVE-2009-1127 2010-01-4 15:24 2009-11-10 Show GitHub Exploit DB Packet Storm
253762 10 危険 マイクロソフト - Microsoft Windows の License Logging Server (llssrv.exe) における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2009-2523 2010-01-4 15:24 2009-11-10 Show GitHub Exploit DB Packet Storm
253763 9.3 危険 マイクロソフト - Microsoft Windows の Web Services on Devices API (WSDAPI) における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2009-2512 2010-01-4 15:23 2009-11-10 Show GitHub Exploit DB Packet Storm
253764 10 危険 アップル
VMware
サン・マイクロシステムズ
- Sun Java SE の Provider クラスにおける詳細不明な脆弱性 CWE-noinfo
情報不足
CVE-2009-2722 2010-01-4 14:56 2009-08-10 Show GitHub Exploit DB Packet Storm
253765 10 危険 アップル
VMware
サン・マイクロシステムズ
- Sun Java SE の Provider クラスにおける詳細不明な脆弱性 CWE-noinfo
情報不足
CVE-2009-2723 2010-01-4 14:55 2009-08-10 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 30, 2026, 4:58 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
289041 - razorcms razorcms razorCMS 1.2 allows remote authenticated users to access administrator directories and files by creating and deleting a directory. CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-5918 2024-11-21 10:45 2012-11-19 Show GitHub Exploit DB Packet Storm
289042 - flashtux weechat Heap-based buffer overflow in WeeChat 0.3.6 through 0.3.9 allows remote attackers to cause a denial of service (crash or hang) and possibly execute arbitrary code via crafted IRC colors that are not … CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2012-5854 2024-11-21 10:45 2012-11-19 Show GitHub Exploit DB Packet Storm
289043 - tom_wilkason snackamp SnackAmp 3.1.3 allows remote attackers to cause a denial of service (application crash) via a long string in an aiff file. CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2012-5917 2024-11-21 10:45 2012-11-18 Show GitHub Exploit DB Packet Storm
289044 - neocrome seditio Neocrome Seditio build 161 allows remote attackers to obtain sensitive information via a direct request to (1) docs/new/seditio-createnew-160.sql, (2) docs/upgrade/sedito_convert_to_utf8.optional.sql… CWE-200
Information Exposure
CVE-2012-5916 2024-11-21 10:45 2012-11-18 Show GitHub Exploit DB Packet Storm
289045 - neocrome seditio Neocrome Seditio build 161 and earlier allows remote attackers to obtain sensitive information via direct request to (1) view.php, (2) plugins/contact/lang/contact.en.lang.php, (3) system/lang/en/mai… CWE-200
Information Exposure
CVE-2012-5915 2024-11-21 10:45 2012-11-18 Show GitHub Exploit DB Packet Storm
289046 - neocrome seditio Multiple cross-site scripting (XSS) vulnerabilities in the sed_import function in system/functions.php in Neocrome Seditio build 160 and 161 allow remote attackers to inject arbitrary web script or H… CWE-79
Cross-site Scripting
CVE-2012-5914 2024-11-21 10:45 2012-11-18 Show GitHub Exploit DB Packet Storm
289047 - wordpress_integrator_project wordpress_integrator Cross-site scripting (XSS) vulnerability in wp-integrator.php in the WordPress Integrator module 1.32 for WordPress allows remote attackers to inject arbitrary web script or HTML via the redirect_to … CWE-79
Cross-site Scripting
CVE-2012-5913 2024-11-21 10:45 2012-11-18 Show GitHub Exploit DB Packet Storm
289048 - pico picopublisher Multiple SQL injection vulnerabilities in PicoPublisher 2.0 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) page.php or (2) single.php. CWE-89
SQL Injection
CVE-2012-5912 2024-11-21 10:45 2012-11-18 Show GitHub Exploit DB Packet Storm
289049 - b2evolution b2evolution Cross-site scripting (XSS) vulnerability in blogs/blog1.php in b2evolution 4.1.3 allows remote attackers to inject arbitrary web script or HTML via the message body. CWE-79
Cross-site Scripting
CVE-2012-5911 2024-11-21 10:45 2012-11-18 Show GitHub Exploit DB Packet Storm
289050 - b2evolution b2evolution SQL injection vulnerability in blogs/htsrv/viewfile.php in b2evolution 4.1.3 allows remote authenticated users to execute arbitrary SQL commands via the root parameter. CWE-89
SQL Injection
CVE-2012-5910 2024-11-21 10:45 2012-11-18 Show GitHub Exploit DB Packet Storm