Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 14, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
257151 4.9 警告 オラクル - Oracle Database Server の Oracle Spatial コンポーネントにおける脆弱性 CWE-noinfo
情報不足
CVE-2010-3590 2011-02-9 16:43 2011-01-18 Show GitHub Exploit DB Packet Storm
257152 6.9 警告 オラクル - Windows 上で稼働する Oracle Database Server の Cluster Verify Utility コンポーネントにおける脆弱性 CWE-noinfo
情報不足
CVE-2010-4423 2011-02-9 16:42 2011-01-18 Show GitHub Exploit DB Packet Storm
257153 6.8 警告 オラクル - Oracle Database Server の Database Vault コンポーネントにおける脆弱性 CWE-noinfo
情報不足
CVE-2010-4421 2011-02-9 16:42 2011-01-18 Show GitHub Exploit DB Packet Storm
257154 7.5 危険 オラクル - 複数の Oracle 製品の Client System Analyzer コンポーネントにおける脆弱性 CWE-noinfo
情報不足
CVE-2010-3600 2011-02-9 16:41 2011-01-18 Show GitHub Exploit DB Packet Storm
257155 7.2 危険 マイクロソフト - 複数の Microsoft 製品の kernel-mode ドライバにおける権限を取得される脆弱性 CWE-Other
その他
CVE-2010-2743 2011-02-9 16:39 2010-10-12 Show GitHub Exploit DB Packet Storm
257156 5 警告 LibTIFF
オラクル
- LibTIFF の OJPEGReadBufferFill 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2010-2443 2011-02-8 15:27 2010-06-24 Show GitHub Exploit DB Packet Storm
257157 6.8 警告 LibTIFF
オラクル
- LibTIFF の TIFFroundup マクロにおける整数オーバーフローの脆弱性 CWE-189
数値処理の問題
CVE-2010-2065 2011-02-8 15:27 2010-06-24 Show GitHub Exploit DB Packet Storm
257158 4 警告 サイバートラスト株式会社
MySQL AB
レッドハット
- MySQL におけるサービス運用妨害 (DoS) の脆弱性 CWE-DesignError
CVE-2010-3839 2011-02-8 15:13 2010-09-10 Show GitHub Exploit DB Packet Storm
257159 9.3 危険 アップル
レッドハット
- Apple Safari の WebKit における任意のコードを実行される脆弱性 CWE-399
リソース管理の問題
CVE-2010-1793 2011-02-7 15:36 2010-07-30 Show GitHub Exploit DB Packet Storm
257160 9.3 危険 アップル
レッドハット
- Apple Safari の WebKit における任意のコードを実行される脆弱性 CWE-Other
その他
CVE-2010-1790 2011-02-7 15:34 2010-07-30 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 14, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
246351 8.8 HIGH
Network
ultimatefosters ultimatepos UltimatePOS 2.5 allows users to upload arbitrary files, which leads to remote command execution by posting to a /products URI with PHP code in a .php file with the image/jpeg content type. CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2018-17139 2024-11-21 12:53 2018-09-17 Show GitHub Exploit DB Packet Storm
246352 5.4 MEDIUM
Network
nickelpro jibu_pro The Jibu Pro plugin through 1.7 for WordPress is prone to Stored XSS via the wp-content/plugins/jibu-pro/quiz_action.php name (aka Quiz Name) field. CWE-79
Cross-site Scripting
CVE-2018-17138 2024-11-21 12:53 2018-09-17 Show GitHub Exploit DB Packet Storm
246353 9.8 CRITICAL
Network
prezi next Prezi Next 1.3.101.11 has a documented purpose of creating HTML5 presentations but has SE_DEBUG_PRIVILEGE on Windows, which might allow attackers to bypass intended access restrictions. NVD-CWE-noinfo
CVE-2018-17137 2024-11-21 12:53 2018-09-17 Show GitHub Exploit DB Packet Storm
246354 9.8 CRITICAL
Network
zzcms zzcms zzcms 8.3 contains a SQL Injection vulnerability in /user/check.php via a Client-Ip HTTP header. CWE-89
SQL Injection
CVE-2018-17136 2024-11-21 12:53 2018-09-17 Show GitHub Exploit DB Packet Storm
246355 7.2 HIGH
Network
phpmywind phpmywind admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the cfg_author field in conjunction with a crafted cfg_webpath field. CWE-94
Code Injection
CVE-2018-17134 2024-11-21 12:53 2018-09-17 Show GitHub Exploit DB Packet Storm
246356 7.2 HIGH
Network
phpmywind phpmywind admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the rewrite url setting. CWE-94
Code Injection
CVE-2018-17133 2024-11-21 12:53 2018-09-17 Show GitHub Exploit DB Packet Storm
246357 7.2 HIGH
Network
phpmywind phpmywind admin/goods_update.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the attrvalue[] array parameter. CWE-94
Code Injection
CVE-2018-17132 2024-11-21 12:53 2018-09-17 Show GitHub Exploit DB Packet Storm
246358 7.2 HIGH
Network
phpmywind phpmywind admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the varvalue field. CWE-94
Code Injection
CVE-2018-17131 2024-11-21 12:53 2018-09-17 Show GitHub Exploit DB Packet Storm
246359 5.4 MEDIUM
Network
phpmywind phpmywind PHPMyWind 5.5 has XSS in member.php via an HTTP Referer header, CWE-79
Cross-site Scripting
CVE-2018-17130 2024-11-21 12:53 2018-09-17 Show GitHub Exploit DB Packet Storm
246360 4.9 MEDIUM
Network
metinfo metinfo MetInfo 6.1.0 has SQL injection in doexport() in app/system/feedback/admin/feedback_admin.class.php via the class1 field. CWE-89
SQL Injection
CVE-2018-17129 2024-11-21 12:53 2018-09-17 Show GitHub Exploit DB Packet Storm