Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 24, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
254651 4.3 警告 Pentaho Corporation - Pentaho BI Server の ViewAction におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-5099 2012-03-27 18:42 2011-09-13 Show GitHub Exploit DB Packet Storm
254652 5.4 警告 ヒューレット・パッカード - Palm Pre WebOS の LunaSysMgr プロセス におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2009-5098 2012-03-27 18:42 2011-09-13 Show GitHub Exploit DB Packet Storm
254653 6.3 警告 OpenFabrics Alliance - OFED の openibd における任意のファイルを上書きされる脆弱性 CWE-59
リンク解釈の問題
CVE-2010-1693 2012-03-27 18:42 2010-10-26 Show GitHub Exploit DB Packet Storm
254654 10 危険 The Tor Project - Tor におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2010-1676 2012-03-27 18:42 2010-12-20 Show GitHub Exploit DB Packet Storm
254655 9.3 危険 Nullsoft - Winamp の vp6.w5s におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2010-1523 2012-03-27 18:42 2010-10-8 Show GitHub Exploit DB Packet Storm
254656 9.3 危険 March Hare Pty Ltd - March Hare Software CVSNT の perms.cpp における任意のコードを実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2010-1326 2012-03-27 18:42 2010-09-15 Show GitHub Exploit DB Packet Storm
254657 4.3 警告 IBM - IBM WebSphere MQ における X.509 証明書の認証をなりすまされる脆弱性 CWE-Other
その他
CVE-2010-0782 2012-03-27 18:42 2010-10-20 Show GitHub Exploit DB Packet Storm
254658 5 警告 シスコシステムズ - Cisco WLC におけるアクセス制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2010-0575 2012-03-27 18:42 2010-09-8 Show GitHub Exploit DB Packet Storm
254659 7.8 危険 シスコシステムズ - Cisco WLC におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2010-0574 2012-03-27 18:42 2010-09-8 Show GitHub Exploit DB Packet Storm
254660 3.5 注意 IBM - IBM PNMSS の load.php における CRLF インジェクションの脆弱性 CWE-94
コード・インジェクション
CVE-2010-0155 2012-03-27 18:42 2010-09-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 24, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
246241 6.5 MEDIUM
Network
uclouvain
debian
openjpeg
debian_linux
OpenJPEG 2.3.0 has a NULL pointer dereference for "red" in the imagetopnm function of jp2/convert.c CWE-476
 NULL Pointer Dereference
CVE-2018-18088 2024-11-21 12:55 2018-10-10 Show GitHub Exploit DB Packet Storm
246242 5.4 MEDIUM
Network
bixie portfolio The Bixie Portfolio plugin 1.2.0 for Pagekit has XSS: a logged-in user who has the "Manage portfolio" privilege can inject arbitrary web script or HTML via the Image URL field in the portfolio editor… CWE-79
Cross-site Scripting
CVE-2018-18087 2024-11-21 12:55 2018-10-10 Show GitHub Exploit DB Packet Storm
246243 8.8 HIGH
Network
phome empirecms EmpireCMS v7.5 has an arbitrary file upload vulnerability in the LoadInMod function in e/class/moddofun.php, exploitable by logged-in users. CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2018-18086 2024-11-21 12:55 2018-10-10 Show GitHub Exploit DB Packet Storm
246244 9.8 CRITICAL
Network
comsenz duomicms An issue was discovered in DuomiCMS 3.0. SQL injection exists in the ajax.php file, as demonstrated by the uid parameter. CWE-89
SQL Injection
CVE-2018-18084 2024-11-21 12:55 2018-10-10 Show GitHub Exploit DB Packet Storm
246245 9.8 CRITICAL
Network
comsenz duomicms An issue was discovered in DuomiCMS 3.0. Remote PHP code execution is possible via the search.php searchword parameter because "eval" is used during "if" processing. CWE-94
Code Injection
CVE-2018-18083 2024-11-21 12:55 2018-10-10 Show GitHub Exploit DB Packet Storm
246246 6.1 MEDIUM
Network
bijiadao waimai_super_cms XSS exists in Waimai Super Cms 20150505 via the fname parameter to the admin.php?m=Food&a=addsave or admin.php?m=Food&a=editsave URI. CWE-79
Cross-site Scripting
CVE-2018-18082 2024-11-21 12:55 2018-10-10 Show GitHub Exploit DB Packet Storm
246247 9.8 CRITICAL
Network
wikidforum_project wikidforum WikidForum 2.20 has SQL Injection via the rpc.php parent_post_id or num_records parameter, or the index.php?action=search select_sort parameter. CWE-89
SQL Injection
CVE-2018-18075 2024-11-21 12:55 2018-10-10 Show GitHub Exploit DB Packet Storm
246248 7.5 HIGH
Network
python
canonical
opensuse
redhat
requests
ubuntu_linux
leap
enterprise_linux_desktop
enterprise_linux_workstation
enterprise_linux_server
The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to di… CWE-522
 Insufficiently Protected Credentials
CVE-2018-18074 2024-11-21 12:55 2018-10-10 Show GitHub Exploit DB Packet Storm
246249 5.4 MEDIUM
Network
naviwebs navigate_cms Navigate CMS has Stored XSS via the navigate.php Title field in an edit action. CWE-79
Cross-site Scripting
CVE-2018-18029 2024-11-21 12:55 2018-10-10 Show GitHub Exploit DB Packet Storm
246250 7.5 HIGH
Network
mercedes-benz mercedes_me An issue was discovered in the Daimler Mercedes-Benz Me app 2.11.0-846 for iOS. The encrypted Connected Vehicle API data exchange between the app and a server might be intercepted. The app can be use… CWE-319
Cleartext Transmission of Sensitive Information
CVE-2018-18071 2024-11-21 12:55 2018-10-9 Show GitHub Exploit DB Packet Storm