Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 22, 2026, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
256591 7.6 危険 アップル - Apple iTunes で使用される WebKit における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2011-2809 2011-10-21 11:43 2011-10-12 Show GitHub Exploit DB Packet Storm
256592 7.6 危険 アップル - Apple iTunes で使用される WebKit における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2011-2356 2011-10-21 11:43 2011-10-12 Show GitHub Exploit DB Packet Storm
256593 7.6 危険 アップル - Apple iTunes で使用される WebKit における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2011-2354 2011-10-21 11:43 2011-10-12 Show GitHub Exploit DB Packet Storm
256594 7.6 危険 アップル - Apple iTunes で使用される WebKit における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2011-2352 2011-10-21 11:42 2011-10-12 Show GitHub Exploit DB Packet Storm
256595 7.6 危険 アップル - Apple iTunes で使用される WebKit における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2011-2341 2011-10-21 11:42 2011-10-12 Show GitHub Exploit DB Packet Storm
256596 7.6 危険 アップル - Apple iTunes で使用される WebKit における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2011-2339 2011-10-21 11:41 2011-10-12 Show GitHub Exploit DB Packet Storm
256597 4.3 警告 マイクロソフト - 複数の Microsoft SharePoint 製品におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-1893 2011-10-20 16:20 2011-09-13 Show GitHub Exploit DB Packet Storm
256598 9.3 危険 マイクロソフト - Microsoft Office 2003 および 2007 における権限昇格の脆弱性 CWE-Other
その他
CVE-2011-1980 2011-10-20 16:19 2011-09-13 Show GitHub Exploit DB Packet Storm
256599 9.3 危険 マイクロソフト - Microsoft Office 2007 および 2010 における任意のコードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2011-1982 2011-10-20 16:19 2011-09-13 Show GitHub Exploit DB Packet Storm
256600 7.2 危険 マイクロソフト - Windows Server 2003 および 2008 の WINS における権限昇格の脆弱性性 CWE-264
認可・権限・アクセス制御
CVE-2011-1984 2011-10-20 16:19 2011-09-13 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 23, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
246241 6.5 MEDIUM
Network
uclouvain
debian
openjpeg
debian_linux
OpenJPEG 2.3.0 has a NULL pointer dereference for "red" in the imagetopnm function of jp2/convert.c CWE-476
 NULL Pointer Dereference
CVE-2018-18088 2024-11-21 12:55 2018-10-10 Show GitHub Exploit DB Packet Storm
246242 5.4 MEDIUM
Network
bixie portfolio The Bixie Portfolio plugin 1.2.0 for Pagekit has XSS: a logged-in user who has the "Manage portfolio" privilege can inject arbitrary web script or HTML via the Image URL field in the portfolio editor… CWE-79
Cross-site Scripting
CVE-2018-18087 2024-11-21 12:55 2018-10-10 Show GitHub Exploit DB Packet Storm
246243 8.8 HIGH
Network
phome empirecms EmpireCMS v7.5 has an arbitrary file upload vulnerability in the LoadInMod function in e/class/moddofun.php, exploitable by logged-in users. CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2018-18086 2024-11-21 12:55 2018-10-10 Show GitHub Exploit DB Packet Storm
246244 9.8 CRITICAL
Network
comsenz duomicms An issue was discovered in DuomiCMS 3.0. SQL injection exists in the ajax.php file, as demonstrated by the uid parameter. CWE-89
SQL Injection
CVE-2018-18084 2024-11-21 12:55 2018-10-10 Show GitHub Exploit DB Packet Storm
246245 9.8 CRITICAL
Network
comsenz duomicms An issue was discovered in DuomiCMS 3.0. Remote PHP code execution is possible via the search.php searchword parameter because "eval" is used during "if" processing. CWE-94
Code Injection
CVE-2018-18083 2024-11-21 12:55 2018-10-10 Show GitHub Exploit DB Packet Storm
246246 6.1 MEDIUM
Network
bijiadao waimai_super_cms XSS exists in Waimai Super Cms 20150505 via the fname parameter to the admin.php?m=Food&a=addsave or admin.php?m=Food&a=editsave URI. CWE-79
Cross-site Scripting
CVE-2018-18082 2024-11-21 12:55 2018-10-10 Show GitHub Exploit DB Packet Storm
246247 9.8 CRITICAL
Network
wikidforum_project wikidforum WikidForum 2.20 has SQL Injection via the rpc.php parent_post_id or num_records parameter, or the index.php?action=search select_sort parameter. CWE-89
SQL Injection
CVE-2018-18075 2024-11-21 12:55 2018-10-10 Show GitHub Exploit DB Packet Storm
246248 7.5 HIGH
Network
python
canonical
opensuse
redhat
requests
ubuntu_linux
leap
enterprise_linux_desktop
enterprise_linux_workstation
enterprise_linux_server
The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to di… CWE-522
 Insufficiently Protected Credentials
CVE-2018-18074 2024-11-21 12:55 2018-10-10 Show GitHub Exploit DB Packet Storm
246249 5.4 MEDIUM
Network
naviwebs navigate_cms Navigate CMS has Stored XSS via the navigate.php Title field in an edit action. CWE-79
Cross-site Scripting
CVE-2018-18029 2024-11-21 12:55 2018-10-10 Show GitHub Exploit DB Packet Storm
246250 7.5 HIGH
Network
mercedes-benz mercedes_me An issue was discovered in the Daimler Mercedes-Benz Me app 2.11.0-846 for iOS. The encrypted Connected Vehicle API data exchange between the app and a server might be intercepted. The app can be use… CWE-319
Cleartext Transmission of Sensitive Information
CVE-2018-18071 2024-11-21 12:55 2018-10-9 Show GitHub Exploit DB Packet Storm