Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":July 1, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
254551 6.4 警告 Vanilla Forums - Vanilla Forums のクッキーの実装における署名されたリクエストを偽造される脆弱性 CWE-Other
その他
CVE-2011-0910 2012-03-27 18:43 2011-02-8 Show GitHub Exploit DB Packet Storm
254552 4.3 警告 Vanilla Forums - Vanilla Forums におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-0909 2012-03-27 18:43 2011-02-8 Show GitHub Exploit DB Packet Storm
254553 5.8 警告 Vanilla Forums - Vanilla Forums におけるオープンリダイレクトの脆弱性 CWE-20
不適切な入力確認
CVE-2011-0908 2012-03-27 18:43 2011-02-8 Show GitHub Exploit DB Packet Storm
254554 6.8 警告 awcm - AWCM におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2011-0903 2012-03-27 18:43 2011-02-7 Show GitHub Exploit DB Packet Storm
254555 6.9 警告 オラクル - Sun Microsystems SunScreen Firewall の Java Service における任意のコードを実行される脆弱性 CWE-Other
その他
CVE-2011-0902 2012-03-27 18:43 2011-02-7 Show GitHub Exploit DB Packet Storm
254556 6.8 警告 erick woods - tsclient の tsc_launch_remote 関数におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2011-0901 2012-03-27 18:43 2011-02-7 Show GitHub Exploit DB Packet Storm
254557 6.8 警告 erick woods - tsclient の tsc_launch_remote 関数におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2011-0900 2012-03-27 18:43 2011-02-7 Show GitHub Exploit DB Packet Storm
254558 5 警告 johan lindskog - AES 暗号モジュール における最後にログインしたユーザの権限を取得される脆弱性 CWE-DesignError
CVE-2011-0899 2012-03-27 18:43 2011-02-2 Show GitHub Exploit DB Packet Storm
254559 4.3 警告 ヒューレット・パッカード - HP NNMi におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-0898 2012-03-27 18:43 2011-04-14 Show GitHub Exploit DB Packet Storm
254560 4.6 警告 ヒューレット・パッカード - HP NNMi における任意のファイルを読まれる脆弱性 CWE-noinfo
情報不足
CVE-2011-0897 2012-03-27 18:43 2011-04-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:July 1, 2026, 4:27 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
246321 9.8 CRITICAL
Network
crashfix_project crashfix CrashFix 1.0.4 has SQL Injection via the User[status] parameter. This is related to actionIndex in UserController.php, and the protected\models\User.php search() function. CWE-89
SQL Injection
CVE-2018-20508 2024-11-21 13:01 2018-12-27 Show GitHub Exploit DB Packet Storm
246322 6.5 MEDIUM
Network
axiosys bento4 An issue was discovered in Bento4 1.5.1-627. There is an attempt at excessive memory allocation in the AP4_DataBuffer class when called from AP4_HvccAtom::Create in Core/Ap4HvccAtom.cpp. CWE-400
 Uncontrolled Resource Consumption
CVE-2018-20502 2024-11-21 13:01 2018-12-27 Show GitHub Exploit DB Packet Storm
246323 7.5 HIGH
Network
viatech epia-e900_firmware ETK_E900.sys, a SmartETK driver for VIA Technologies EPIA-E900 system board, is vulnerable to denial of service attack via IOCTL 0x9C402048, which calls memmove and constantly fails on an arbitrary (… CWE-20
 Improper Input Validation 
CVE-2018-20404 2024-11-21 13:01 2018-12-27 Show GitHub Exploit DB Packet Storm
246324 5.3 MEDIUM
Network
mit
debian
kerberos
debian_linux
A Reachable Assertion issue was discovered in the KDC in MIT Kerberos 5 (aka krb5) before 1.17. If an attacker can obtain a krbtgt ticket using an older encryption type (single-DES, triple-DES, or RC… CWE-617
 Reachable Assertion
CVE-2018-20217 2024-11-21 13:01 2018-12-27 Show GitHub Exploit DB Packet Storm
246325 6.1 MEDIUM
Network
metinfo metinfo MetInfo 6.x through 6.1.3 has XSS via the /admin/login/login_check.php url_array[] parameter. CWE-79
Cross-site Scripting
CVE-2018-20486 2024-11-21 13:01 2018-12-27 Show GitHub Exploit DB Packet Storm
246326 6.1 MEDIUM
Network
zohocorp manageengine_adselfservice_plus Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the employee search feature. CWE-79
Cross-site Scripting
CVE-2018-20485 2024-11-21 13:01 2018-12-27 Show GitHub Exploit DB Packet Storm
246327 6.1 MEDIUM
Network
zohocorp manageengine_adselfservice_plus Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the self-update layout implementation. CWE-79
Cross-site Scripting
CVE-2018-20484 2024-11-21 13:01 2018-12-27 Show GitHub Exploit DB Packet Storm
246328 4.7 MEDIUM
Local
gnu
debian
opensuse
tar
debian_linux
leap
GNU Tar through 1.30, when --sparse is used, mishandles file shrinkage during read access, which allows local users to cause a denial of service (infinite read loop in sparse_dump_region in sparse.c)… CWE-835
 Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2018-20482 2024-11-21 13:01 2018-12-27 Show GitHub Exploit DB Packet Storm
246329 7.8 HIGH
Local
gnu wget set_file_metadata in xattr.c in GNU Wget before 1.20.1 stores a file's origin URL in the user.xdg.origin.url metadata attribute of the extended attributes of the downloaded file, which allows local u… CWE-200
Information Exposure
CVE-2018-20483 2024-11-21 13:01 2018-12-27 Show GitHub Exploit DB Packet Storm
246330 6.5 MEDIUM
Network
freedesktop
canonical
debian
poppler
ubuntu_linux
debian_linux
XRef::getEntry in XRef.cc in Poppler 0.72.0 mishandles unallocated XRef entries, which allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted PDF document, when… CWE-476
 NULL Pointer Dereference
CVE-2018-20481 2024-11-21 13:01 2018-12-26 Show GitHub Exploit DB Packet Storm