Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 13, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
255341 2.6 注意 オラクル - Oracle Application Server におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
- 2010-01-14 15:01 2010-01-14 Show GitHub Exploit DB Packet Storm
255342 9.3 危険 マイクロソフト - Microsoft Internet Explorer に脆弱性 CWE-94
コード・インジェクション
CVE-2009-3672 2010-01-14 12:08 2009-11-25 Show GitHub Exploit DB Packet Storm
255343 9.3 危険 サン・マイクロシステムズ
VMware
- Sun Java SE の java.lang パッケージにおける脆弱性 CWE-362
競合状態
CVE-2009-2724 2010-01-14 12:08 2009-08-10 Show GitHub Exploit DB Packet Storm
255344 10 危険 サン・マイクロシステムズ
VMware
- Sun Java SE の Provider クラスにおける脆弱性 CWE-noinfo
情報不足
CVE-2009-2721 2010-01-14 12:08 2009-08-10 Show GitHub Exploit DB Packet Storm
255345 5 警告 有限会社シースリー - WebCalenderC3 におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2010-0348 2010-01-12 15:01 2010-01-12 Show GitHub Exploit DB Packet Storm
255346 4.3 警告 有限会社シースリー - WebCalenderC3 におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-0349 2010-01-12 15:00 2010-01-12 Show GitHub Exploit DB Packet Storm
255347 10 危険 サイバートラスト株式会社
XEmacs
- XEmacs の glyphs-eimage.c における整数オーバーフローの脆弱性 CWE-189
数値処理の問題
CVE-2009-2688 2010-01-12 14:48 2009-08-5 Show GitHub Exploit DB Packet Storm
255348 6.8 警告 IBM - IBM WebSphere Application Server (WAS) におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2009-2746 2010-01-12 14:48 2009-11-13 Show GitHub Exploit DB Packet Storm
255349 5 警告 アップル - Apple Safari におけるローカル HTML ファイルを読まれる脆弱性 CWE-Other
その他
CVE-2009-2842 2010-01-7 12:09 2009-11-11 Show GitHub Exploit DB Packet Storm
255350 5.5 警告 シックス・アパート株式会社 - Movable Type におけるアクセス制限回避の脆弱性 CWE-264
認可・権限・アクセス制御
- 2010-01-6 15:01 2010-01-6 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 13, 2026, 5:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
247261 7.1 HIGH
Local
artifex jbig2dec Artifex jbig2dec 0.13 has a heap-based buffer over-read leading to denial of service (application crash) or disclosure of sensitive information from process memory, because of an integer overflow in … CWE-190
 Integer Overflow or Wraparound
CVE-2017-7885 2024-11-21 12:32 2017-04-17 Show GitHub Exploit DB Packet Storm
247262 8.8 HIGH
Network
mantisbt mantisbt MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php. CWE-640
 Weak Password Recovery Mechanism for Forgotten Password
CVE-2017-7615 2024-11-21 12:32 2017-04-16 Show GitHub Exploit DB Packet Storm
247263 9.8 CRITICAL
Network
libreoffice libreoffice LibreOffice before 2017-03-14 has an out-of-bounds write related to the HWPFile::TagsRead function in hwpfilter/source/hwpfile.cxx. CWE-787
 Out-of-bounds Write
CVE-2017-7882 2024-11-21 12:32 2017-04-16 Show GitHub Exploit DB Packet Storm
247264 8.8 HIGH
Network
bigtreecms bigtree_cms BigTree CMS through 4.2.17 relies on a substring check for CSRF protection, which allows remote attackers to bypass this check by placing the required admin/developer/ URI within a query string in an… CWE-352
 Origin Validation Error
CVE-2017-7881 2024-11-21 12:32 2017-04-16 Show GitHub Exploit DB Packet Storm
247265 7.5 HIGH
Network
flatcore flatcore-cms SQL Injection vulnerability in flatCore version 1.4.6 allows an attacker to read the content database. CWE-89
SQL Injection
CVE-2017-7879 2024-11-21 12:32 2017-04-15 Show GitHub Exploit DB Packet Storm
247266 9.8 CRITICAL
Network
flatcore flatcore-cms SQL Injection vulnerability in flatCore version 1.4.6 allows an attacker to read and write to the users database. CWE-89
SQL Injection
CVE-2017-7878 2024-11-21 12:32 2017-04-15 Show GitHub Exploit DB Packet Storm
247267 8.8 HIGH
Network
flatcore flatcore-cms CSRF vulnerability in flatCore version 1.4.6 allows remote attackers to modify CMS configurations. CWE-352
 Origin Validation Error
CVE-2017-7877 2024-11-21 12:32 2017-04-15 Show GitHub Exploit DB Packet Storm
247268 9.8 CRITICAL
Network
feh_project feh In wallpaper.c in feh before v2.18.3, if a malicious client pretends to be the E17 window manager, it is possible to trigger an out-of-boundary heap write while receiving an IPC message. An integer o… CWE-787
 Out-of-bounds Write
CVE-2017-7875 2024-11-21 12:32 2017-04-15 Show GitHub Exploit DB Packet Storm
247269 6.1 MEDIUM
Network
tdm_project tdm trollepierre/tdm before 2017-04-13 is vulnerable to a reflected XSS in tdm-master/webhook.php (challenge parameter). CWE-79
Cross-site Scripting
CVE-2017-7871 2024-11-21 12:32 2017-04-15 Show GitHub Exploit DB Packet Storm
247270 8.8 HIGH
Network
sap netweaver_application_server_java SQL injection vulnerability in the getUserUddiElements method in the ES UDDI component in SAP NetWeaver AS Java 7.4 allows remote authenticated users to execute arbitrary SQL commands via unspecified… CWE-89
SQL Injection
CVE-2017-7717 2024-11-21 12:32 2017-04-15 Show GitHub Exploit DB Packet Storm