Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 20, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
256211 7.2 危険 VMware - VMware Fusion の vmx86 のカーネル拡張における権限昇格の脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2009-3281 2010-03-24 12:22 2009-10-1 Show GitHub Exploit DB Packet Storm
256212 9.3 危険 VMware - 複数の VMware 製品の VMnc media コーデックにおける任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2009-2628 2010-03-24 12:22 2009-09-4 Show GitHub Exploit DB Packet Storm
256213 9.3 危険 VMware - 複数の VMware 製品の VMnc media コーデックにおけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-0199 2010-03-24 12:22 2009-09-4 Show GitHub Exploit DB Packet Storm
256214 5 警告 VMware - VMware Studio の Web インターフェースにおけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2009-2968 2010-03-24 12:22 2009-08-31 Show GitHub Exploit DB Packet Storm
256215 4 警告 VMware - 複数の VMware 製品の Descheduled Time Accounting ドライバにおけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2009-1805 2010-03-24 12:22 2009-05-28 Show GitHub Exploit DB Packet Storm
256216 6.8 警告 VMware - 複数の VMware 製品の仮想マシン表示機能における任意のコードを実行される脆弱性 CWE-noinfo
情報不足
CVE-2009-1244 2010-03-24 12:21 2009-04-10 Show GitHub Exploit DB Packet Storm
256217 7.2 危険 VMware - 複数の VMware 製品の仮想マシン通信インターフェイスにおける権限昇格の脆弱性 CWE-noinfo
情報不足
CVE-2009-1147 2010-03-24 12:21 2009-04-3 Show GitHub Exploit DB Packet Storm
256218 4.9 警告 VMware - 複数の VMware 製品の ioctl におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2009-1146 2010-03-23 14:11 2010-04-3 Show GitHub Exploit DB Packet Storm
256219 6.8 警告 VMware - 複数の VMware 製品の VNnc コーデックにおけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-0910 2010-03-23 14:11 2010-04-3 Show GitHub Exploit DB Packet Storm
256220 9.3 危険 VMware - 複数の VMware 製品の VNnc コーデックにおけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-0909 2010-03-23 14:10 2010-04-3 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 20, 2026, 4:14 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
247141 7.5 HIGH
Network
novell edirectory The LDAP backend in Novell eDirectory before 9.0 SP4 when switched to EBA (Enhanced Background Authentication) kept open connections without EBA. NVD-CWE-noinfo
CVE-2017-9277 2024-11-21 12:35 2018-03-3 Show GitHub Exploit DB Packet Storm
247142 6.1 MEDIUM
Network
netiq access_manager Novell Access Manager iManager before 4.3.3 did not validate parameters so that cross site scripting content could be reflected back into the result page using the "a" parameter. CWE-79
Cross-site Scripting
CVE-2017-9276 2024-11-21 12:35 2018-03-3 Show GitHub Exploit DB Packet Storm
247143 7.5 HIGH
Network
novell edirectory In Novell eDirectory before 9.0.3.1 the LDAP interface was not strictly enforcing cipher restrictions allowing weaker ciphers to be used during SSL BIND operations. NVD-CWE-noinfo
CVE-2017-9267 2024-11-21 12:35 2018-03-3 Show GitHub Exploit DB Packet Storm
247144 8.8 HIGH
Network
opensuse leap The packaging of NextCloud in openSUSE used /srv/www/htdocs in an unsafe manner, which could have allowed scripts running as wwwrun user to escalate privileges to root during nextcloud package upgrad… NVD-CWE-noinfo
CVE-2017-9286 2024-11-21 12:35 2018-03-2 Show GitHub Exploit DB Packet Storm
247145 7.8 HIGH
Local
opensuse obs-service-source_validator A shell command injection in the obs-service-source_validator before 0.7 could be used to execute code as the packager when checking RPM SPEC files with specific macro constructs. CWE-78
OS Command 
CVE-2017-9274 2024-11-21 12:35 2018-03-2 Show GitHub Exploit DB Packet Storm
247146 3.3 LOW
Local
opensuse
fedoraproject
zypper
fedora
The commandline package update tool zypper writes HTTP proxy credentials into its logfile, allowing local attackers to gain access to proxies used. CWE-532
 Inclusion of Sensitive Information in Log Files
CVE-2017-9271 2024-11-21 12:35 2018-03-2 Show GitHub Exploit DB Packet Storm
247147 9.1 CRITICAL
Network
opensuse cryptctl In cryptctl before version 2.0 a malicious server could send RPC requests that could overwrite files outside of the cryptctl key database. CWE-20
 Improper Input Validation 
CVE-2017-9270 2024-11-21 12:35 2018-03-2 Show GitHub Exploit DB Packet Storm
247148 9.8 CRITICAL
Network
opensuse libzypp In libzypp before August 2018 GPG keys attached to YUM repositories were not correctly pinned, allowing malicious repository mirrors to silently downgrade to unsigned repositories with potential mali… CWE-20
 Improper Input Validation 
CVE-2017-9269 2024-11-21 12:35 2018-03-2 Show GitHub Exploit DB Packet Storm
247149 6.5 MEDIUM
Network
opensuse open_build_service In the open build service before 201707022 the wipetrigger and rebuild actions checked the wrong project for permissions, allowing authenticated users to cause operations on projects where they did n… CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2017-9268 2024-11-21 12:35 2018-03-2 Show GitHub Exploit DB Packet Storm
247150 5.4 MEDIUM
Network
microfocus project_and_portfolio_management A Remote Cross-Site Scripting vulnerability in HPE Project and Portfolio Management (PPM) version v9.30, v9.31, v9.32, v9.40 was found. CWE-79
Cross-site Scripting
CVE-2017-8993 2024-11-21 12:35 2018-02-16 Show GitHub Exploit DB Packet Storm