Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 15, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
255541 4.3 警告 シュナイダーエレクトリック株式会社 (旧社名株式会社エーピーシー・ジャパン) - APC Switched Rack PDU におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4406 2010-03-12 15:13 2009-12-23 Show GitHub Exploit DB Packet Storm
255542 4.3 警告 シュナイダーエレクトリック株式会社 (旧社名株式会社エーピーシー・ジャパン) - APC Network Management Card におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-1798 2010-03-12 15:13 2009-12-28 Show GitHub Exploit DB Packet Storm
255543 6.8 警告 シュナイダーエレクトリック株式会社 (旧社名株式会社エーピーシー・ジャパン) - APC Network Management Card におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2009-1797 2010-03-12 15:12 2009-12-28 Show GitHub Exploit DB Packet Storm
255544 6.6 警告 日立 - JP1/Cm2/Network Node Manager のリモートコンソールにおけるファイルパーミッションの脆弱性 CWE-264
認可・権限・アクセス制御
- 2010-03-12 15:12 2010-02-26 Show GitHub Exploit DB Packet Storm
255545 9.3 危険 Panda Security - Panda Security ActiveScan におけるコンポーネントのデジタル署名を検証しない問題 CWE-94
コード・インジェクション
CVE-2009-3735 2010-03-12 15:12 2010-02-12 Show GitHub Exploit DB Packet Storm
255546 5 警告 サイバートラスト株式会社
OpenSSL Project
IBM
レッドハット
- OpenSSL の dtls1_retrieve_buffered_fragment 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2009-1379 2010-03-12 14:44 2009-05-19 Show GitHub Exploit DB Packet Storm
255547 5 警告 サイバートラスト株式会社
OpenSSL Project
IBM
レッドハット
- OpenSSL の dtls1_process_out_of_seq_message 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2009-1378 2010-03-12 14:44 2009-05-19 Show GitHub Exploit DB Packet Storm
255548 5 警告 サイバートラスト株式会社
OpenSSL Project
IBM
レッドハット
- OpenSSL の dtls1_buffer_record 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2009-1377 2010-03-12 14:43 2009-05-19 Show GitHub Exploit DB Packet Storm
255549 5 警告 アップル
サイバートラスト株式会社
OpenSSL Project
Apache Software Foundation
レッドハット
- OpenSSL の zlib_stateful_init 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2008-1678 2010-03-12 14:43 2008-07-10 Show GitHub Exploit DB Packet Storm
255550 5.8 警告 OpenPNEプロジェクト - OpenPNE におけるアクセス制限回避の脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2010-1040 2010-03-11 12:39 2010-03-5 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 15, 2026, 4:28 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
249291 5.5 MEDIUM
Local
sophos hitmanpro A kernel pool overflow in the driver hitmanpro37.sys in Sophos SurfRight HitmanPro before 3.7.20 Build 286 (included in the HitmanPro.Alert solution and Sophos Clean) allows local users to crash the … CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2017-6007 2024-11-21 12:28 2017-09-13 Show GitHub Exploit DB Packet Storm
249292 4.4 MEDIUM
Local
intel manageability_engine_firmware
active_management_technology_firmware
small_business_technology_firmware
Intel Active Management Technology, Intel Standard Manageability, and Intel Small Business Technology firmware versions 11.0.25.3001 and 11.0.26.3000 anti-rollback will not prevent upgrading to firmw… NVD-CWE-noinfo
CVE-2017-5698 2024-11-21 12:28 2017-09-6 Show GitHub Exploit DB Packet Storm
249293 4.6 MEDIUM
Physics
intel ssd_540s_2.5\"_firmware
ssd_540s_series_m.2_firmware
ssd_pro_5400s_2.5\"_firmware
ssd_pro_5400s_m.2_firmware
ssd_e_5400s_2.5\"_firmware
ssd_e_5400s_m.2_firmware
ssd_d…
Data corruption vulnerability in firmware in Intel Solid-State Drive Consumer, Professional, Embedded, Data Center affected firmware versions LSBG200, LSF031C, LSF036C, LBF010C, LSBG100, LSF031C, LSF… CWE-20
 Improper Input Validation 
CVE-2017-5695 2024-11-21 12:28 2017-08-9 Show GitHub Exploit DB Packet Storm
249294 4.6 MEDIUM
Physics
intel ssd_pro_6000p_firmware Data corruption vulnerability in firmware in Intel Solid-State Drive Professional PSF104P, PSF109P allows local users to cause a denial of service via unspecified vectors. NVD-CWE-noinfo
CVE-2017-5694 2024-11-21 12:28 2017-08-9 Show GitHub Exploit DB Packet Storm
249295 9.0 CRITICAL
Network
intel nuc7i3bnk_bios
nuc7i5bnk_bios
nuc7i7bnh_bios
stk2mv64cc_bios
stk2m3w64cc_bios
nuc6i7kyk_bios
nuc6i3syk_bios
nuc6i5syk_bios
r1304sposhor_bios
r1304sposhorr_bios
r1208spos…
Incorrect check in Intel processors from 6th and 7th Generation Intel Core Processor Families, Intel Xeon E3-1500M v5 and v6 Product Families, and Intel Xeon E3-1200 v5 and v6 Product Families allows… NVD-CWE-noinfo
CVE-2017-5691 2024-11-21 12:28 2017-07-27 Show GitHub Exploit DB Packet Storm
249296 7.0 HIGH
Local
waves maxxaudio Waves MaxxAudio, as installed on Dell laptops, adds a "WavesSysSvc" Windows service with File Version 1.1.6.0. This service has a vulnerability known as Unquoted Service Path. This could potentially … NVD-CWE-noinfo
CVE-2017-6005 2024-11-21 12:28 2017-07-26 Show GitHub Exploit DB Packet Storm
249297 7.5 HIGH
Network
apache impala During a routine security analysis, it was found that one of the ports in Apache Impala (incubating) 2.7.0 to 2.8.0 sent data in plaintext even when the cluster was configured to use TLS. The port in… CWE-319
Cleartext Transmission of Sensitive Information
CVE-2017-5652 2024-11-21 12:28 2017-07-11 Show GitHub Exploit DB Packet Storm
249298 9.8 CRITICAL
Network
apache impala It was noticed that a malicious process impersonating an Impala daemon in Apache Impala (incubating) 2.7.0 to 2.8.0 could cause Impala daemons to skip authentication checks when Kerberos is enabled (… CWE-287
Improper Authentication
CVE-2017-5640 2024-11-21 12:28 2017-07-11 Show GitHub Exploit DB Packet Storm
249299 8.8 HIGH
Network
bestpractical request_tracker The dashboard subscription interface in Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 might allow remote authenticated users with certain privileges to execute a… CWE-20
 Improper Input Validation 
CVE-2017-5944 2024-11-21 12:28 2017-07-4 Show GitHub Exploit DB Packet Storm
249300 8.8 HIGH
Network
bestpractical request_tracker Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 allows remote attackers to obtain sensitive information about cross-site request forgery (CSRF) verification tokens… CWE-352
 Origin Validation Error
CVE-2017-5943 2024-11-21 12:28 2017-07-4 Show GitHub Exploit DB Packet Storm