Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 21, 2026, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
255421 9.3 危険 Google - Google Chrome の src/jsregexp.cc におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-2555 2010-10-19 14:50 2009-07-16 Show GitHub Exploit DB Packet Storm
255422 4.3 警告 Google - Google Chrome における javascript: URI をブロックしない脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-2352 2010-10-19 14:50 2009-02-3 Show GitHub Exploit DB Packet Storm
255423 9.3 危険 Google - Google Chrome の browser kernel におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-2121 2010-10-19 14:50 2009-06-22 Show GitHub Exploit DB Packet Storm
255424 6.8 警告 Google - Google Chrome における任意の https サイトになりすまされる脆弱性 CWE-287
不適切な認証
CVE-2009-2071 2010-10-19 14:49 2009-03-23 Show GitHub Exploit DB Packet Storm
255425 6.4 警告 The PHP Group - PHP の zend_ini.c 内にある zend_restore_ini_entry_cb 関数における重要な情報を取得される脆弱性 CWE-Other
その他
CVE-2009-2626 2010-10-18 15:22 2009-12-1 Show GitHub Exploit DB Packet Storm
255426 4 警告 オラクル - Oracle iPlanet Web Server におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2010-3544 2010-10-18 12:03 2010-10-18 Show GitHub Exploit DB Packet Storm
255427 5 警告 ISC, Inc. - BIND の ACL の処理に問題 CWE-264
認可・権限・アクセス制御
CVE-2010-0218 2010-10-15 13:24 2010-10-1 Show GitHub Exploit DB Packet Storm
255428 5.1 警告 K2 Software - K2Editor における実行ファイル読み込みに関する脆弱性 CWE-Other
その他
CVE-2010-3156 2010-10-15 11:22 2010-10-15 Show GitHub Exploit DB Packet Storm
255429 6.8 警告 kMonos.NET - XacRett における実行ファイル読み込みに関する脆弱性 CWE-Other
その他
CVE-2010-3157 2010-10-15 11:22 2010-10-15 Show GitHub Exploit DB Packet Storm
255430 5 警告 The PHP Group - PHP における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2010-2101 2010-10-14 16:20 2010-05-26 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 21, 2026, 4:10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
264931 9.8 CRITICAL
Network
sierrawireless aleos_firmware Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 use guessable session tokens, which are in the URL. CWE-613
 Insufficient Session Expiration
CVE-2016-5069 2024-11-21 11:53 2017-04-10 Show GitHub Exploit DB Packet Storm
264932 9.8 CRITICAL
Network
sierrawireless aleos_firmware Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 do not require authentication for Embedded_Ace_Get_Task.cgi requests. CWE-287
Improper Authentication
CVE-2016-5068 2024-11-21 11:53 2017-04-10 Show GitHub Exploit DB Packet Storm
264933 8.8 HIGH
Network
sierrawireless aleos_firmware Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 allow Hayes AT command injection. CWE-77
Command Injection
CVE-2016-5067 2024-11-21 11:53 2017-04-10 Show GitHub Exploit DB Packet Storm
264934 9.8 CRITICAL
Network
sierrawireless aleos_firmware Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 have weak passwords for admin, rauser, sconsole, and user. CWE-255
Credentials Management
CVE-2016-5066 2024-11-21 11:53 2017-04-10 Show GitHub Exploit DB Packet Storm
264935 9.8 CRITICAL
Network
sierrawireless aleos_firmware Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 allow Embedded_Ace_Set_Task.cgi command injection. CWE-77
Command Injection
CVE-2016-5065 2024-11-21 11:53 2017-04-10 Show GitHub Exploit DB Packet Storm
264936 6.5 MEDIUM
Network
osram lightify_pro OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 allows attackers to obtain sensitive information by reading screenshots under /private/var/mobile/Containers/Data/Application. CWE-200
Information Exposure
CVE-2016-5059 2024-11-21 11:53 2017-04-10 Show GitHub Exploit DB Packet Storm
264937 7.5 HIGH
Network
osram lightify_pro OSRAM SYLVANIA Osram Lightify Pro through 2016-07-26 allows Zigbee replay. CWE-284
Improper Access Control
CVE-2016-5058 2024-11-21 11:53 2017-04-10 Show GitHub Exploit DB Packet Storm
264938 7.5 HIGH
Network
osram lightify_pro OSRAM SYLVANIA Osram Lightify Pro through 2016-07-26 does not use SSL pinning. CWE-254
 7PK - Security Features
CVE-2016-5057 2024-11-21 11:53 2017-04-10 Show GitHub Exploit DB Packet Storm
264939 7.5 HIGH
Network
osram lightify_pro OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 uses only 8 hex digits for a PSK. CWE-326
Inadequate Encryption Strength
CVE-2016-5056 2024-11-21 11:53 2017-04-10 Show GitHub Exploit DB Packet Storm
264940 6.1 MEDIUM
Network
osram lightify_pro OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 has XSS in the username field and Wireless Client Mode configuration page. CWE-79
Cross-site Scripting
CVE-2016-5055 2024-11-21 11:53 2017-04-10 Show GitHub Exploit DB Packet Storm