Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 3, 2026, noon

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
256281 4.6 警告 シトリックス・システムズ - Citrix XenServer における認証を回避され Xen API (XAPI) を実行される脆弱性 CWE-noinfo
情報不足
CVE-2010-0633 2010-09-14 15:54 2010-02-12 Show GitHub Exploit DB Packet Storm
256282 4.3 警告 シトリックス・システムズ - 複数の Citrix XenServer 製品の XenAPI HTTP インターフェイスにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-3253 2010-09-14 15:54 2008-07-16 Show GitHub Exploit DB Packet Storm
256283 7.5 危険 シトリックス・システムズ - Citrix XenCenterWeb の XenServer Resource Kit における PHP コードを挿入される脆弱性 CWE-94
コード・インジェクション
CVE-2009-3760 2010-09-14 15:54 2009-10-22 Show GitHub Exploit DB Packet Storm
256284 6 警告 シトリックス・システムズ - Citrix XenCenterWeb の XenServer Resource Kit におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2009-3759 2010-09-14 15:54 2009-10-22 Show GitHub Exploit DB Packet Storm
256285 7.5 危険 シトリックス・システムズ - Citrix XenCenterWeb の XenServer Resource Kit における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-3758 2010-09-14 15:53 2009-10-22 Show GitHub Exploit DB Packet Storm
256286 4.3 警告 シトリックス・システムズ - Citrix XenCenterWeb の XenServer Resource Kit におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-3757 2010-09-14 15:53 2009-10-22 Show GitHub Exploit DB Packet Storm
256287 7.2 危険 シトリックス・システムズ - Xen の xend におけるサービス運用妨害 (DoS) の脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-5716 2010-09-14 15:53 2008-12-24 Show GitHub Exploit DB Packet Storm
256288 6 警告 VMware - VMware Studio の Virtual Appliance Management Infrastructure における任意のコマンドを実行される脆弱性 CWE-noinfo
情報不足
CVE-2010-2667 2010-09-13 16:05 2010-07-13 Show GitHub Exploit DB Packet Storm
256289 4.4 警告 VMware - VMware Studio における権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2010-2427 2010-09-13 16:05 2010-07-13 Show GitHub Exploit DB Packet Storm
256290 6.8 警告 VMware - VMware SpringSource tc Server Runtime における JMX インターフェイスへのアクセス権を取得される脆弱性 CWE-287
不適切な認証
CVE-2010-1454 2010-09-13 16:05 2010-05-13 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 3, 2026, 4:18 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
246491 7.5 HIGH
Network
substratum substratum In the mintToken function of a smart contract implementation for Substratum (SUB), an Ethereum ERC20 token, the administrator can control mintedAmount, leverage an integer overflow, and modify a user… CWE-190
 Integer Overflow or Wraparound
CVE-2018-12511 2024-11-21 12:45 2018-09-22 Show GitHub Exploit DB Packet Storm
246492 8.2 HIGH
Network
opcfoundation ua-.net-legacy
ua-java
An XXE vulnerability in the OPC UA Java and .NET Legacy Stack can allow remote attackers to trigger a denial of service. CWE-611
XXE
CVE-2018-12585 2024-11-21 12:45 2018-09-15 Show GitHub Exploit DB Packet Storm
246493 7.5 HIGH
Network
mobyproject moby An issue was discovered in Docker Moby before 17.06.0. The Docker engine validated a client TLS certificate using both the configured client CA root certificate and all system roots on non-Windows sy… CWE-295
Improper Certificate Validation 
CVE-2018-12608 2024-11-21 12:45 2018-09-11 Show GitHub Exploit DB Packet Storm
246494 8.0 HIGH
Adjacent
dlink dir-601_firmware An issue was discovered on D-Link DIR-601 2.02NA devices. Being local to the network and having only "User" account (which is a low privilege account) access, an attacker can intercept the response f… CWE-319
Cleartext Transmission of Sensitive Information
CVE-2018-12710 2024-11-21 12:45 2018-08-30 Show GitHub Exploit DB Packet Storm
246495 9.8 CRITICAL
Network
adobe creative_cloud Adobe Creative Cloud Desktop Application before 4.6.1 has an improper certificate validation vulnerability. Successful exploitation could lead to privilege escalation. CWE-295
Improper Certificate Validation 
CVE-2018-12829 2024-11-21 12:45 2018-08-29 Show GitHub Exploit DB Packet Storm
246496 9.8 CRITICAL
Network
adobe
redhat
flash_player
enterprise_linux_desktop
enterprise_linux_server
enterprise_linux_workstation
Adobe Flash Player 30.0.0.134 and earlier have a "use of a component with a known vulnerability" vulnerability. Successful exploitation could lead to privilege escalation. NVD-CWE-noinfo
CVE-2018-12828 2024-11-21 12:45 2018-08-29 Show GitHub Exploit DB Packet Storm
246497 7.5 HIGH
Network
adobe
redhat
flash_player
enterprise_linux_desktop
enterprise_linux_server
enterprise_linux_workstation
Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. CWE-125
Out-of-bounds Read
CVE-2018-12827 2024-11-21 12:45 2018-08-29 Show GitHub Exploit DB Packet Storm
246498 7.5 HIGH
Network
adobe
redhat
flash_player
enterprise_linux_desktop
enterprise_linux_server
enterprise_linux_workstation
Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. CWE-125
Out-of-bounds Read
CVE-2018-12826 2024-11-21 12:45 2018-08-29 Show GitHub Exploit DB Packet Storm
246499 9.8 CRITICAL
Network
adobe
redhat
flash_player
enterprise_linux_desktop
enterprise_linux_server
enterprise_linux_workstation
Adobe Flash Player 30.0.0.134 and earlier have a security bypass vulnerability. Successful exploitation could lead to security mitigation bypass. NVD-CWE-noinfo
CVE-2018-12825 2024-11-21 12:45 2018-08-29 Show GitHub Exploit DB Packet Storm
246500 5.9 MEDIUM
Network
adobe
redhat
flash_player_desktop_runtime
flash_player
enterprise_linux_desktop
enterprise_linux_server
enterprise_linux_workstation
Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. CWE-125
Out-of-bounds Read
CVE-2018-12824 2024-11-21 12:45 2018-08-29 Show GitHub Exploit DB Packet Storm