Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 20, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
255971 2.4 注意 オラクル - Oracle Solaris における xscreensaver の処理に関する脆弱性 CWE-noinfo
情報不足
CVE-2011-2292 2011-10-27 09:48 2011-10-18 Show GitHub Exploit DB Packet Storm
255972 2.1 注意 オラクル - Oracle Solaris における ZFS の処理に関する脆弱性 CWE-noinfo
情報不足
CVE-2011-2286 2011-10-27 09:47 2011-10-18 Show GitHub Exploit DB Packet Storm
255973 7.8 危険 オラクル - Oracle Sun Products Suite の複数の製品における Web Container の処理に関する脆弱性 CWE-noinfo
情報不足
CVE-2011-3559 2011-10-26 16:43 2011-10-18 Show GitHub Exploit DB Packet Storm
255974 6.5 警告 オラクル - Oracle Database Server の Application Express コンポーネントにおける脆弱性 CWE-noinfo
情報不足
CVE-2011-3525 2011-10-26 16:42 2011-10-18 Show GitHub Exploit DB Packet Storm
255975 5.5 警告 オラクル - Oracle Database Server の Core RDBMS コンポーネントおける脆弱性 CWE-noinfo
情報不足
CVE-2011-3512 2011-10-26 16:42 2011-10-18 Show GitHub Exploit DB Packet Storm
255976 3.6 注意 オラクル - Oracle Database Server の Database Vault コンポーネントにおける脆弱性 CWE-noinfo
情報不足
CVE-2011-3511 2011-10-26 16:40 2011-10-18 Show GitHub Exploit DB Packet Storm
255977 3.6 注意 オラクル - Oracle Database Server の Database Vault コンポーネントにおける脆弱性 CWE-noinfo
情報不足
CVE-2011-2322 2011-10-26 16:40 2011-10-18 Show GitHub Exploit DB Packet Storm
255978 4.1 警告 オラクル - Oracle Database Server の Oracle Text コンポーネントにおける脆弱性 CWE-noinfo
情報不足
CVE-2011-2301 2011-10-26 16:39 2011-10-18 Show GitHub Exploit DB Packet Storm
255979 3.5 注意 オラクル - Oracle E-Business Suite の Oracle Applications Framework コンポーネントにおける脆弱性 CWE-noinfo
情報不足
CVE-2011-3519 2011-10-26 16:38 2011-10-18 Show GitHub Exploit DB Packet Storm
255980 4.3 警告 オラクル - Oracle E-Business Suite の Oracle Application Object Library コンポーネントにおける脆弱性 CWE-noinfo
情報不足
CVE-2011-3513 2011-10-26 16:37 2011-10-18 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 21, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
246241 6.5 MEDIUM
Network
uclouvain
debian
openjpeg
debian_linux
OpenJPEG 2.3.0 has a NULL pointer dereference for "red" in the imagetopnm function of jp2/convert.c CWE-476
 NULL Pointer Dereference
CVE-2018-18088 2024-11-21 12:55 2018-10-10 Show GitHub Exploit DB Packet Storm
246242 5.4 MEDIUM
Network
bixie portfolio The Bixie Portfolio plugin 1.2.0 for Pagekit has XSS: a logged-in user who has the "Manage portfolio" privilege can inject arbitrary web script or HTML via the Image URL field in the portfolio editor… CWE-79
Cross-site Scripting
CVE-2018-18087 2024-11-21 12:55 2018-10-10 Show GitHub Exploit DB Packet Storm
246243 8.8 HIGH
Network
phome empirecms EmpireCMS v7.5 has an arbitrary file upload vulnerability in the LoadInMod function in e/class/moddofun.php, exploitable by logged-in users. CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2018-18086 2024-11-21 12:55 2018-10-10 Show GitHub Exploit DB Packet Storm
246244 9.8 CRITICAL
Network
comsenz duomicms An issue was discovered in DuomiCMS 3.0. SQL injection exists in the ajax.php file, as demonstrated by the uid parameter. CWE-89
SQL Injection
CVE-2018-18084 2024-11-21 12:55 2018-10-10 Show GitHub Exploit DB Packet Storm
246245 9.8 CRITICAL
Network
comsenz duomicms An issue was discovered in DuomiCMS 3.0. Remote PHP code execution is possible via the search.php searchword parameter because "eval" is used during "if" processing. CWE-94
Code Injection
CVE-2018-18083 2024-11-21 12:55 2018-10-10 Show GitHub Exploit DB Packet Storm
246246 6.1 MEDIUM
Network
bijiadao waimai_super_cms XSS exists in Waimai Super Cms 20150505 via the fname parameter to the admin.php?m=Food&a=addsave or admin.php?m=Food&a=editsave URI. CWE-79
Cross-site Scripting
CVE-2018-18082 2024-11-21 12:55 2018-10-10 Show GitHub Exploit DB Packet Storm
246247 9.8 CRITICAL
Network
wikidforum_project wikidforum WikidForum 2.20 has SQL Injection via the rpc.php parent_post_id or num_records parameter, or the index.php?action=search select_sort parameter. CWE-89
SQL Injection
CVE-2018-18075 2024-11-21 12:55 2018-10-10 Show GitHub Exploit DB Packet Storm
246248 7.5 HIGH
Network
python
canonical
opensuse
redhat
requests
ubuntu_linux
leap
enterprise_linux_desktop
enterprise_linux_workstation
enterprise_linux_server
The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to di… CWE-522
 Insufficiently Protected Credentials
CVE-2018-18074 2024-11-21 12:55 2018-10-10 Show GitHub Exploit DB Packet Storm
246249 5.4 MEDIUM
Network
naviwebs navigate_cms Navigate CMS has Stored XSS via the navigate.php Title field in an edit action. CWE-79
Cross-site Scripting
CVE-2018-18029 2024-11-21 12:55 2018-10-10 Show GitHub Exploit DB Packet Storm
246250 7.5 HIGH
Network
mercedes-benz mercedes_me An issue was discovered in the Daimler Mercedes-Benz Me app 2.11.0-846 for iOS. The encrypted Connected Vehicle API data exchange between the app and a server might be intercepted. The app can be use… CWE-319
Cleartext Transmission of Sensitive Information
CVE-2018-18071 2024-11-21 12:55 2018-10-9 Show GitHub Exploit DB Packet Storm