Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 31, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
254931 7.6 危険 アップル - 複数の Apple 製品の WebKit における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2011-0146 2011-04-1 15:20 2011-03-3 Show GitHub Exploit DB Packet Storm
254932 7.6 危険 アップル - 複数の Apple 製品の WebKit における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2011-0145 2011-04-1 15:18 2011-03-3 Show GitHub Exploit DB Packet Storm
254933 7.6 危険 アップル - 複数の Apple 製品の WebKit における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2011-0144 2011-04-1 15:11 2011-03-3 Show GitHub Exploit DB Packet Storm
254934 7.6 危険 アップル - 複数の Apple 製品の WebKit における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2011-0143 2011-04-1 15:08 2011-03-3 Show GitHub Exploit DB Packet Storm
254935 7.6 危険 アップル - 複数の Apple 製品の WebKit における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2011-0142 2011-04-1 15:05 2011-03-3 Show GitHub Exploit DB Packet Storm
254936 7.6 危険 アップル - 複数の Apple 製品の WebKit における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2011-0141 2011-04-1 15:04 2011-03-3 Show GitHub Exploit DB Packet Storm
254937 5 警告 The PHP Group
アップル
- PHP の fopen_wrappers.c における open_basedir 制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2010-3436 2011-04-1 14:59 2010-11-9 Show GitHub Exploit DB Packet Storm
254938 6.8 警告 The PHP Group
アップル
- PHP の phar 拡張における重要な情報を取得される脆弱性 CWE-134
書式文字列の問題
CVE-2010-2950 2011-04-1 14:51 2010-05-14 Show GitHub Exploit DB Packet Storm
254939 7.6 危険 アップル - 複数の Apple 製品の WebKit における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2011-0140 2011-03-31 14:39 2011-03-3 Show GitHub Exploit DB Packet Storm
254940 7.6 危険 アップル - 複数の Apple 製品の WebKit における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2011-0139 2011-03-31 14:38 2011-03-3 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 31, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
264701 9.8 CRITICAL
Network
joomla joomla\! The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4 allows remote attackers to gain privileges by leveraging incorrect use o… CWE-20
 Improper Input Validation 
CVE-2016-8869 2024-11-21 12:00 2016-11-5 Show GitHub Exploit DB Packet Storm
264702 7.8 HIGH
Local
python
debian
pillow
debian_linux
Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "crafted image file" approach, related to an "Insecure Sign Extension" issue affecting the ImagingNew in … CWE-284
Improper Access Control
CVE-2016-9190 2024-11-21 12:00 2016-11-4 Show GitHub Exploit DB Packet Storm
264703 5.5 MEDIUM
Local
python
debian
pillow
debian_linux
Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the "crafted image file" approach, related to an "Integer Overflow" issue affecting the Image.core.map_… CWE-190
 Integer Overflow or Wraparound
CVE-2016-9189 2024-11-21 12:00 2016-11-4 Show GitHub Exploit DB Packet Storm
264704 6.1 MEDIUM
Network
moodle moodle Cross-site scripting (XSS) vulnerabilities in Moodle CMS on or before 3.1.2 allow remote attackers to inject arbitrary web script or HTML via the s_additionalhtmlhead, s_additionalhtmltopofbody, and … CWE-79
Cross-site Scripting
CVE-2016-9188 2024-11-21 12:00 2016-11-4 Show GitHub Exploit DB Packet Storm
264705 8.8 HIGH
Network
moodle moodle Unrestricted file upload vulnerability in the double extension support in the "image" module in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an ex… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2016-9187 2024-11-21 12:00 2016-11-4 Show GitHub Exploit DB Packet Storm
264706 8.8 HIGH
Network
moodle moodle Unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an … CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2016-9186 2024-11-21 12:00 2016-11-4 Show GitHub Exploit DB Packet Storm
264707 4.3 MEDIUM
Network
openstack heat In OpenStack Heat, by launching a new Heat stack with a local URL an authenticated user may conduct network discovery revealing internal network configuration. Affected versions are <=5.0.3, >=6.0.0 … CWE-200
Information Exposure
CVE-2016-9185 2024-11-21 12:00 2016-11-4 Show GitHub Exploit DB Packet Storm
264708 7.5 HIGH
Network
exponentcms exponent_cms In /framework/modules/core/controllers/expHTMLEditorController.php of Exponent CMS 2.4.0, untrusted input is used to construct a table name, and in the selectObject method in mysqli class, table name… CWE-200
CWE-89
Information Exposure
SQL Injection
CVE-2016-9184 2024-11-21 12:00 2016-11-4 Show GitHub Exploit DB Packet Storm
264709 7.5 HIGH
Network
exponentcms exponent_cms In /framework/modules/ecommerce/controllers/orderController.php of Exponent CMS 2.4.0, untrusted input is passed into selectObjectsBySql. The method selectObjectsBySql of class mysqli_database uses t… CWE-200
Information Exposure
CVE-2016-9183 2024-11-21 12:00 2016-11-4 Show GitHub Exploit DB Packet Storm
264710 7.5 HIGH
Network
sparkjava spark Directory traversal vulnerability in Spark 2.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI. CWE-22
Path Traversal
CVE-2016-9177 2024-11-21 12:00 2016-11-4 Show GitHub Exploit DB Packet Storm