Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":July 1, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
257061 9.3 危険 マイクロソフト - Microsoft Windows XP および Windows Server 2003 における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2011-3397 2011-12-16 11:16 2011-12-13 Show GitHub Exploit DB Packet Storm
257062 9.3 危険 マイクロソフト - 複数の Microsoft Office 製品における任意のコードを実行される脆弱性 CWE-399
リソース管理の問題
CVE-2011-1983 2011-12-16 11:15 2011-12-13 Show GitHub Exploit DB Packet Storm
257063 7.2 危険 マイクロソフト - 複数の Microsoft 製品の簡体字中国語版 Microsoft Office IME における権限昇格の脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2011-2010 2011-12-16 11:09 2011-12-13 Show GitHub Exploit DB Packet Storm
257064 4.3 警告 Dolibarr ERP & CRM - Dolibarr におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-4814 2011-12-16 10:52 2011-11-3 Show GitHub Exploit DB Packet Storm
257065 6.5 警告 Dolibarr ERP & CRM - Dolibarr における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2011-4802 2011-12-16 10:50 2011-11-3 Show GitHub Exploit DB Packet Storm
257066 4.3 警告 Jextensions - Joomla! 用 HM Community コンポーネントにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-4809 2011-12-16 10:44 2011-12-14 Show GitHub Exploit DB Packet Storm
257067 7.5 危険 Jextensions - Joomla! 用 HM Community コンポーネントにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2011-4808 2011-12-16 10:41 2011-12-14 Show GitHub Exploit DB Packet Storm
257068 5 警告 foobla - Joomla! 用の obSuggest コンポーネントにおけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2011-4804 2011-12-16 10:19 2011-12-14 Show GitHub Exploit DB Packet Storm
257069 7.5 危険 BraveNewCode - WordPress 用の WPTouch プラグインにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2011-4803 2011-12-16 10:18 2011-12-14 Show GitHub Exploit DB Packet Storm
257070 6.8 警告 DELL EMC (旧 EMC Corporation) - EMC RSA AAOP におけるアプリケーション制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2011-2742 2011-12-15 16:59 2011-12-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:July 1, 2026, 4:27 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
246441 5.3 MEDIUM
Network
stackstorm stackstorm Incorrect access control in StackStorm API (st2api) in StackStorm before 2.9.2 and 2.10.x before 2.10.1 allows an attacker (who has a StackStorm account and is authenticated against the StackStorm AP… NVD-CWE-noinfo
CVE-2018-20345 2024-11-21 13:01 2018-12-22 Show GitHub Exploit DB Packet Storm
246442 6.8 MEDIUM
Physics
floureon sp012 The Floureon IP Camera SP012 provides a root terminal on a UART serial interface without proper access control. This allows attackers with physical access to execute arbitrary commands with root priv… CWE-287
Improper Authentication
CVE-2018-20342 2024-11-21 13:01 2018-12-22 Show GitHub Exploit DB Packet Storm
246443 6.1 MEDIUM
Network
zohocorp manageengine_opmanager Zoho ManageEngine OpManager 12.3 before build 123239 allows XSS in the Notes column of the Alarms section. CWE-79
Cross-site Scripting
CVE-2018-20339 2024-11-21 13:01 2018-12-21 Show GitHub Exploit DB Packet Storm
246444 9.8 CRITICAL
Network
zohocorp manageengine_opmanager Zoho ManageEngine OpManager 12.3 before build 123239 allows SQL injection in the Alarms section. CWE-89
SQL Injection
CVE-2018-20338 2024-11-21 13:01 2018-12-21 Show GitHub Exploit DB Packet Storm
246445 8.8 HIGH
Network
libraw libraw There is a stack-based buffer overflow in the parse_makernote function of dcraw_common.cpp in LibRaw 0.19.1. Crafted input will lead to a denial of service or possibly unspecified other impact. CWE-787
 Out-of-bounds Write
CVE-2018-20337 2024-11-21 13:01 2018-12-21 Show GitHub Exploit DB Packet Storm
246446 7.5 HIGH
Network
openwebif_project openwebif An issue has been discovered in the OpenWebif plugin through 1.2.4 for Enigma2 based devices. Reading of arbitrary files is possible with /file?action=download&file= followed by a full pathname, and … CWE-22
Path Traversal
CVE-2018-20332 2024-11-21 13:01 2018-12-21 Show GitHub Exploit DB Packet Storm
246447 8.8 HIGH
Network
libjpeg-turbo libjpeg-turbo The tjLoadImage function in libjpeg-turbo 2.0.1 has an integer overflow with a resultant heap-based buffer overflow via a BMP image because multiplication of pitch and height is mishandled, as demons… CWE-787
CWE-190
 Out-of-bounds Write
 Integer Overflow or Wraparound
CVE-2018-20330 2024-11-21 13:01 2018-12-21 Show GitHub Exploit DB Packet Storm
246448 8.1 HIGH
Network
chamilo chamilo_lms Chamilo LMS version 1.11.8 contains a main/inc/lib/CoursesAndSessionsCatalog.class.php SQL injection, allowing users with access to the sessions catalogue (which may optionally be made public) to ext… CWE-89
SQL Injection
CVE-2018-20329 2024-11-21 13:01 2018-12-21 Show GitHub Exploit DB Packet Storm
246449 5.4 MEDIUM
Network
chamilo chamilo_lms Chamilo LMS version 1.11.8 contains XSS in main/social/group_view.php in the social groups tool, allowing authenticated users to affect other users, under specific conditions of permissions granted b… CWE-79
Cross-site Scripting
CVE-2018-20328 2024-11-21 13:01 2018-12-21 Show GitHub Exploit DB Packet Storm
246450 5.4 MEDIUM
Network
chamilo chamilo_lms Chamilo LMS version 1.11.8 contains XSS in main/template/default/admin/gradebook_list.tpl in the gradebook dependencies tool, allowing authenticated users to affect other users, under specific condit… CWE-79
Cross-site Scripting
CVE-2018-20327 2024-11-21 13:01 2018-12-21 Show GitHub Exploit DB Packet Storm