Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 31, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
255251 5 警告 レッドハット - IcedTea における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2010-3860 2011-02-21 16:53 2010-12-8 Show GitHub Exploit DB Packet Storm
255252 6.8 警告 レッドハット - IcedTea の JNLP SecurityManager におけるセキュリティポリシーを回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2010-4351 2011-02-21 14:58 2011-01-20 Show GitHub Exploit DB Packet Storm
255253 4.3 警告 シマンテック - Symantec Norton Mobile Security for Android における重要な情報を取得される脆弱性 CWE-255
証明書・パスワード管理
CVE-2010-0113 2011-02-21 14:55 2010-11-15 Show GitHub Exploit DB Packet Storm
255254 4.3 警告 Google - Android の Dalvik API におけるサービス運用妨害 (DoS) 脆弱性 CWE-noinfo
情報不足
CVE-2009-3698 2011-02-21 14:54 2009-10-14 Show GitHub Exploit DB Packet Storm
255255 5 警告 CollabNet, Inc. - CollabNet ScrumWorks Basic Server における認証情報取り扱いに関する問題 CWE-310
暗号の問題
CVE-2011-0410 2011-02-21 14:54 2011-01-24 Show GitHub Exploit DB Packet Storm
255256 5 警告 The PHP Group
レッドハット
- Libmbfl の mb_strcut 関数における重要な情報を取得される脆弱性 CWE-20
不適切な入力確認
CVE-2010-4156 2011-02-18 15:07 2010-11-10 Show GitHub Exploit DB Packet Storm
255257 6.8 警告 The PHP Group
サイバートラスト株式会社
レッドハット
- PHP の xml_utf8_decode 関数における整数オーバーフローの脆弱性 CWE-189
数値処理の問題
CVE-2009-5016 2011-02-18 15:03 2010-11-12 Show GitHub Exploit DB Packet Storm
255258 6.8 警告 The PHP Group - PHP の set_magic_quotes_runtime 関数における SQL インジェクション攻撃を誘導される脆弱性 CWE-89
SQLインジェクション
CVE-2010-4700 2011-02-18 14:42 2010-07-1 Show GitHub Exploit DB Packet Storm
255259 7.5 危険 The PHP Group - PHP の iconv_mime_decode_headers 関数におけるスパムの検出を回避される脆弱性 CWE-189
数値処理の問題
CVE-2010-4699 2011-02-18 14:40 2010-09-28 Show GitHub Exploit DB Packet Storm
255260 5 警告 The PHP Group - PHP の GD 拡張モジュールにおけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2010-4698 2011-02-18 14:38 2010-12-7 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 31, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
246601 7.8 HIGH
Local
google android In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, there is a possible Use-after-free issue in Media Codec process. Any application using codec… CWE-416
 Use After Free
CVE-2018-11261 2024-11-21 12:43 2018-11-28 Show GitHub Exploit DB Packet Storm
246602 7.8 HIGH
Local
google android In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while processing a fast Initial link setup (FILS) connection request, integer overflow may l… CWE-190
 Integer Overflow or Wraparound
CVE-2018-11260 2024-11-21 12:43 2018-11-28 Show GitHub Exploit DB Packet Storm
246603 8.8 HIGH
Network
apache hadoop In Apache Hadoop 2.7.4 to 2.7.6, the security fix for CVE-2016-6811 is incomplete. A user who can escalate to yarn user can possibly run arbitrary commands as root user. NVD-CWE-noinfo
CVE-2018-11766 2024-11-21 12:43 2018-11-27 Show GitHub Exploit DB Packet Storm
246604 7.5 HIGH
Network
apache
debian
redhat
tomcat_jk_connector
debian_linux
jboss_core_services
The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK (mod_jk) Connector 1.2.0 to 1.2.44 did not handle some edge… CWE-22
Path Traversal
CVE-2018-11759 2024-11-21 12:43 2018-11-1 Show GitHub Exploit DB Packet Storm
246605 7.8 HIGH
Local
qualcomm mdm9206_firmware
mdm9607_firmware
mdm9640_firmware
mdm9650_firmware
msm8909w_firmware
msm8996au_firmware
sd_210_firmware
sd_212_firmware
sd_205_firmware
sd_425_firmware
When a series of FDAL messages are sent to the modem, a Use After Free condition can occur in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in version MDM9206, MDM9607, MDM9640, MDM9650, … CWE-416
 Use After Free
CVE-2018-11305 2024-11-21 12:43 2018-10-26 Show GitHub Exploit DB Packet Storm
246606 5.5 MEDIUM
Local
puppet cisco_ios Previous releases of the Puppet cisco_ios module output SSH session debug information including login credentials to a world readable file on every run. These issues have been resolved in the 0.4.0 r… CWE-522
 Insufficiently Protected Credentials
CVE-2018-11752 2024-11-21 12:43 2018-10-3 Show GitHub Exploit DB Packet Storm
246607 6.5 MEDIUM
Network
puppet cisco_ios_module Previous releases of the Puppet cisco_ios module did not validate a host's identity before starting a SSH connection. As of the 0.4.0 release of cisco_ios, host key checking is enabled by default. CWE-20
 Improper Input Validation 
CVE-2018-11750 2024-11-21 12:43 2018-10-3 Show GitHub Exploit DB Packet Storm
246608 7.8 HIGH
Local
puppet device_manager Previous releases of the Puppet device_manager module creates configuration files containing credentials that are world readable. This issue has been resolved as of device_manager 2.7.0. CWE-522
 Insufficiently Protected Credentials
CVE-2018-11748 2024-11-21 12:43 2018-10-3 Show GitHub Exploit DB Packet Storm
246609 5.9 MEDIUM
Network
apache
canonical
redhat
oracle
netapp
http_server
ubuntu_linux
enterprise_linux
retail_xstore_point_of_service
hospitality_guest_access
enterprise_manager_ops_center
secure_global_desktop
instantis_enterprisetrack
In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS frames a client can occupy a connection, server thread and CPU time without any connection timeout coming to effect. This… NVD-CWE-noinfo
CVE-2018-11763 2024-11-21 12:43 2018-09-26 Show GitHub Exploit DB Packet Storm
246610 8.8 HIGH
Network
samsung samsung_members This vulnerability allows remote attackers to escalate privileges on vulnerable installations of Samsung Members Fixed in version 2.4.25. An attacker must first obtain the ability to execute low-priv… NVD-CWE-noinfo
CVE-2018-11614 2024-11-21 12:43 2018-09-25 Show GitHub Exploit DB Packet Storm