Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 20, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
255151 7.2 危険 マイクロソフト - 複数の Microsoft 製品の OpenType Font フォーマットドライバにおける権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2010-2741 2010-10-26 15:31 2010-10-12 Show GitHub Exploit DB Packet Storm
255152 7.2 危険 マイクロソフト - 複数の Microsoft 製品の OpenType Font フォーマットドライバにおける権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2010-2740 2010-10-26 15:29 2010-10-12 Show GitHub Exploit DB Packet Storm
255153 7.2 危険 マイクロソフト - 複数の Microsoft 製品のカーネルモードドライバにおける権限昇格の脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2010-2744 2010-10-26 15:28 2010-10-12 Show GitHub Exploit DB Packet Storm
255154 4.9 警告 マイクロソフト - 複数の Microsoft 製品のカーネルモードドライバにおける権限昇格の脆弱性 CWE-399
リソース管理の問題
CVE-2010-2549 2010-10-26 15:28 2010-10-12 Show GitHub Exploit DB Packet Storm
255155 6.5 警告 IBM - Linux 上で稼働する IBM DB2 におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2010-0462 2010-10-26 15:24 2010-01-28 Show GitHub Exploit DB Packet Storm
255156 9.3 危険 マイクロソフト - 64-bit プラットフォーム上で稼働している Microsoft .NET Framework の JIT コンパイラにおける任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2010-3228 2010-10-25 16:37 2010-10-12 Show GitHub Exploit DB Packet Storm
255157 9.3 危険 マイクロソフト - 複数の Microsoft 製品の Embedded OpenType Font Engine における整数オーバーフローの脆弱性 CWE-189
数値処理の問題
CVE-2010-1883 2010-10-25 16:37 2010-10-12 Show GitHub Exploit DB Packet Storm
255158 7.6 危険 マイクロソフト - 複数の Microsoft 製品の Media Player Network Sharing Service における任意のコードを実行される脆弱性 CWE-399
リソース管理の問題
CVE-2010-3225 2010-10-25 16:36 2010-10-12 Show GitHub Exploit DB Packet Storm
255159 9.3 危険 マイクロソフト - Microsoft Internet Explorer における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2010-3331 2010-10-25 16:35 2010-10-12 Show GitHub Exploit DB Packet Storm
255160 4.3 警告 マイクロソフト - Microsoft Internet Explorer における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2010-3330 2010-10-25 16:35 2010-10-12 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 20, 2026, 4:14 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
265091 5.3 MEDIUM
Network
miniprofiler rack-mini-profiler The rack-mini-profiler gem before 0.10.1 for Ruby allows remote attackers to obtain sensitive information about allocated strings and objects by leveraging incorrect ordering of security checks. CWE-200
Information Exposure
CVE-2016-4442 2024-11-21 11:52 2017-05-2 Show GitHub Exploit DB Packet Storm
265092 7.8 HIGH
Local
apple iphone_os
mac_os_x
tvos
Heap-based buffer overflow in IOHIDFamily in Apple iOS before 9.3.2, OS X before 10.11.5, and tvOS before 9.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2016-4650 2024-11-21 11:52 2017-04-21 Show GitHub Exploit DB Packet Storm
265093 3.3 LOW
Local
redhat enterprise_linux_desktop
enterprise_linux_workstation
enterprise_linux_server
enterprise_linux_hpc_node
subscription-manager
The Subscription Manager package (aka subscription-manager) before 1.17.7-1 for Candlepin uses weak permissions (755) for subscription-manager cache directories, which allows local users to obtain se… CWE-264
Permissions, Privileges, and Access Controls
CVE-2016-4455 2024-11-21 11:52 2017-04-15 Show GitHub Exploit DB Packet Storm
265094 7.5 HIGH
Network
redhat mod_cluster
enterprise_linux
Stack-based buffer overflow in native/mod_manager/node.c in mod_cluster 1.2.9. CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2016-4459 2024-11-21 11:52 2017-04-13 Show GitHub Exploit DB Packet Storm
265095 7.0 HIGH
Local
setroubleshoot_project
redhat
setroubleshoot
enterprise_linux_desktop
enterprise_linux_workstation
enterprise_linux_server
enterprise_linux_hpc_node
The allow_execstack plugin for setroubleshoot allows local users to execute arbitrary commands by triggering an execstack SELinux denial with a crafted filename, related to the commands.getoutput fun… CWE-77
Command Injection
CVE-2016-4446 2024-11-21 11:52 2017-04-12 Show GitHub Exploit DB Packet Storm
265096 7.0 HIGH
Local
setroubleshoot_project
redhat
setroubleshoot
enterprise_linux_desktop
enterprise_linux_workstation
enterprise_linux_server
enterprise_linux_hpc_node
The fix_lookup_id function in sealert in setroubleshoot before 3.2.23 allows local users to execute arbitrary commands as root by triggering an SELinux denial with a crafted file name, related to exe… CWE-77
Command Injection
CVE-2016-4445 2024-11-21 11:52 2017-04-12 Show GitHub Exploit DB Packet Storm
265097 7.0 HIGH
Local
setroubleshoot_project
redhat
setroubleshoot
enterprise_linux_desktop
enterprise_linux_workstation
enterprise_linux_server
enterprise_linux_hpc_node
The allow_execmod plugin for setroubleshoot before 3.2.23 allows local users to execute arbitrary commands by triggering an execmod SELinux denial with a crafted binary filename, related to the comma… CWE-77
Command Injection
CVE-2016-4444 2024-11-21 11:52 2017-04-12 Show GitHub Exploit DB Packet Storm
265098 7.5 HIGH
Network
xmlsoft
debian
oracle
libxml2
debian_linux
solaris
The xmlBufAttrSerializeTxtContent function in xmlsave.c in libxml2 allows context-dependent attackers to cause a denial of service (out-of-bounds read and application crash) via a non-UTF-8 attribute… CWE-502
 Deserialization of Untrusted Data
CVE-2016-4483 2024-11-21 11:52 2017-04-12 Show GitHub Exploit DB Packet Storm
265099 8.8 HIGH
Network
pivotal_software
cloudfoundry
cloud_foundry_elastic_runtime
cloud_foundry
cloud_foundry_uaa
cloud_foundry_ops_manager
cloud_foundry_uaa_bosh
SQL injection vulnerability in Pivotal Cloud Foundry (PCF) before 238; UAA 2.x before 2.7.4.4, 3.x before 3.3.0.2, and 3.4.x before 3.4.1; UAA BOSH before 11.2 and 12.x before 12.2; Elastic Runtime b… CWE-89
SQL Injection
CVE-2016-4468 2024-11-21 11:52 2017-04-12 Show GitHub Exploit DB Packet Storm
265100 8.8 HIGH
Network
meteocontrol weblog A Cross-Site Request Forgery issue was discovered in Meteocontrol WEB'log Basic 100 all versions, Light all versions, Pro all versions, and Pro Unlimited all versions. There is no CSRF Token generate… CWE-352
 Origin Validation Error
CVE-2016-4504 2024-11-21 11:52 2017-03-22 Show GitHub Exploit DB Packet Storm