Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 12, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
258711 9.3 危険 マイクロソフト - Microsoft Windows の Media Services におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2010-0478 2010-05-10 19:10 2010-04-13 Show GitHub Exploit DB Packet Storm
258712 10 危険 マイクロソフト - Microsoft Windows の SMB クライアントにおける任意のコードを実行される脆弱性 CWE-399
リソース管理の問題
CVE-2010-0477 2010-05-10 19:10 2010-04-13 Show GitHub Exploit DB Packet Storm
258713 10 危険 マイクロソフト - Microsoft Windows の SMB クライアントにおける任意のコードを実行される脆弱性 CWE-399
リソース管理の問題
CVE-2010-0476 2010-05-10 19:10 2010-04-13 Show GitHub Exploit DB Packet Storm
258714 10 危険 マイクロソフト - Microsoft Windows の SMB クライアントにおける任意のコードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2010-0270 2010-05-10 19:10 2010-04-13 Show GitHub Exploit DB Packet Storm
258715 10 危険 マイクロソフト - Microsoft Windows の SMB クライアントにおける任意のコードを実行される脆弱性 CWE-399
リソース管理の問題
CVE-2010-0269 2010-05-10 19:09 2010-04-13 Show GitHub Exploit DB Packet Storm
258716 9.3 危険 マイクロソフト - Microsoft Windows の Cabinet File Viewer Shell Extension における任意のコードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2010-0487 2010-05-10 19:09 2010-04-13 Show GitHub Exploit DB Packet Storm
258717 9.3 危険 マイクロソフト - Microsoft Windows の Authenticode Signature Verification における任意のコードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2010-0486 2010-05-10 19:09 2010-04-13 Show GitHub Exploit DB Packet Storm
258718 4.7 警告 サイバートラスト株式会社
Linux
レッドハット
- x86_64 および amd64 プラットフォーム上 Linux Kernel におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2009-4271 2010-05-10 18:25 2010-03-16 Show GitHub Exploit DB Packet Storm
258719 5 警告 VMware - VMware Authorization Service の VMware Authentication Daemon におけるサービス運用妨害 (DoS) の脆弱性 CWE-134
書式文字列の問題
CVE-2009-3707 2010-05-7 17:26 2009-10-16 Show GitHub Exploit DB Packet Storm
258720 9.3 危険 VMware - VMnc メディアコーデックおよびムービーデコーダにおける任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2009-1565 2010-05-7 17:26 2010-04-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 12, 2026, 4:20 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
249461 6.7 MEDIUM
Local
intel extreme_tuning_utility Escalation of privilege in Installer for Intel Extreme Tuning Utility before 6.4.1.21 may allow an authenticated user to potentially execute code or disclose information as administrator via local ac… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2018-12150 2024-11-21 12:44 2018-09-13 Show GitHub Exploit DB Packet Storm
249462 5.5 MEDIUM
Local
intel extreme_tuning_utility Buffer overflow in input handling in Intel Extreme Tuning Utility before 6.4.1.21 may allow an authenticated user to potentially deny service to the application via local access. CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2018-12149 2024-11-21 12:44 2018-09-13 Show GitHub Exploit DB Packet Storm
249463 7.8 HIGH
Local
intel driver_\&_support_assistant Privilege escalation in file permissions in Intel Driver and Support Assistant before 3.5.0.1 may allow an authenticated user to potentially execute code as administrator via local access. CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2018-12148 2024-11-21 12:44 2018-09-13 Show GitHub Exploit DB Packet Storm
249464 7.4 HIGH
Network
apache
oracle
activemq
flexcube_private_banking
enterprise_repository
TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 was missing which could make the client vulnerable to a MITM attack between a Java application using the ActiveMQ client … CWE-295
Improper Certificate Validation 
CVE-2018-11775 2024-11-21 12:44 2018-09-11 Show GitHub Exploit DB Packet Storm
249465 6.1 MEDIUM
Network
myadrenalin adrenalin A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Adrenalin 5.4.0 HRMS Software. The user supplied input containing JavaScript is echoed back in JavaScript code in an HTML respon… CWE-79
Cross-site Scripting
CVE-2018-12234 2024-11-21 12:44 2018-09-7 Show GitHub Exploit DB Packet Storm
249466 5.9 MEDIUM
Network
symantec norton_password_manager The Norton Identity Safe product prior to 5.3.0.976 may be susceptible to a privilege escalation issue via a hard coded IV, which is a type of vulnerability that can potentially increase the likeliho… CWE-798
 Use of Hard-coded Credentials
CVE-2018-12240 2024-11-21 12:44 2018-08-30 Show GitHub Exploit DB Packet Storm
249467 8.1 HIGH
Network
apache
netapp
oracle
struts
snapcenter
oncommand_workflow_automation
oncommand_insight
active_iq_unified_manager
mysql_enterprise_monitor
enterprise_manager_base_platform
communications_policy_manage…
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: … NVD-CWE-noinfo
CVE-2018-11776 2024-11-21 12:44 2018-08-22 Show GitHub Exploit DB Packet Storm
249468 7.5 HIGH
Network
nodejs
redhat
node.js
openshift_container_platform
In all versions of Node.js prior to 6.14.4, 8.11.4 and 10.9.0 when used with UCS-2 encoding (recognized by Node.js under the names `'ucs2'`, `'ucs-2'`, `'utf16le'` and `'utf-16le'`), `Buffer#write()`… CWE-787
 Out-of-bounds Write
CVE-2018-12115 2024-11-21 12:44 2018-08-21 Show GitHub Exploit DB Packet Storm
249469 8.8 HIGH
Network
litecart litecart admin/vqmods.app/vqmods.inc.php in LiteCart before 2.1.3 allows remote authenticated attackers to upload a malicious file (resulting in remote code execution) by using the text/xml or application/xml… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2018-12256 2024-11-21 12:44 2018-08-17 Show GitHub Exploit DB Packet Storm
249470 7.5 HIGH
Network
all-for-one all_for_one The maxRandom function of a smart contract implementation for All For One, an Ethereum gambling game, generates a random value with publicly readable variables because the _seed value can be retrieve… CWE-338
 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
CVE-2018-12056 2024-11-21 12:44 2018-08-16 Show GitHub Exploit DB Packet Storm