Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":July 1, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
259651 4.3 警告 CA Technologies - CA Service Desk の Web インターフェイスにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4149 2010-12-27 11:38 2009-12-8 Show GitHub Exploit DB Packet Storm
259652 4.3 警告 CA Technologies - 複数の CA 製品の Anti-Virus エンジン内にある arclib コンポーネントおけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2009-3588 2010-12-27 11:36 2009-10-8 Show GitHub Exploit DB Packet Storm
259653 9.3 危険 CA Technologies - 複数の CA 製品の Anti-Virus エンジン内にある arclib コンポーネントにおける任意のコードを実行される脆弱性 CWE-noinfo
情報不足
CVE-2009-3587 2010-12-27 11:32 2009-10-8 Show GitHub Exploit DB Packet Storm
259654 5 警告 CA Technologies - CA Host-Based Intrusion Prevention System の kmxIds.sys におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2009-2740 2010-12-27 11:24 2009-08-18 Show GitHub Exploit DB Packet Storm
259655 4.3 警告 CA Technologies - CA SiteMinder における J2EE アプリケーションのクロスサイトスクリプティングに対する保護を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2009-2705 2010-12-27 11:19 2009-08-11 Show GitHub Exploit DB Packet Storm
259656 4.3 警告 CA Technologies - CA SiteMinder における J2EE アプリケーションのクロスサイトスクリプティングに対する保護を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2009-2704 2010-12-27 10:47 2009-08-11 Show GitHub Exploit DB Packet Storm
259657 10 危険 CA Technologies - 複数の CA 製品の Data Transport Services におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-2026 2010-12-27 10:45 2009-08-6 Show GitHub Exploit DB Packet Storm
259658 5 警告 CA Technologies - CA ARCserve Backup のメッセージエンジンにおけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2009-1761 2010-12-27 10:41 2009-06-15 Show GitHub Exploit DB Packet Storm
259659 2.1 注意 CA Technologies - CA Internet Security Suite の vetmonnt.sys におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2009-0682 2010-12-27 10:36 2009-08-18 Show GitHub Exploit DB Packet Storm
259660 10 危険 CA Technologies - CA Service Metric Analysis および Service Level Management の smmsnmpd サービスにおける任意のコマンドを実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2009-0043 2010-12-27 10:34 2009-01-7 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:July 1, 2026, 4:27 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
250121 6.1 MEDIUM
Network
morningstarsecurity whatweb MorningStar WhatWeb 0.4.9 has XSS via JSON report files. CWE-79
Cross-site Scripting
CVE-2018-16234 2024-11-21 12:52 2018-08-31 Show GitHub Exploit DB Packet Storm
250122 6.1 MEDIUM
Network
1234n minicms MiniCMS V1.10 has XSS via the mc-admin/post-edit.php tags parameter. CWE-79
Cross-site Scripting
CVE-2018-16233 2024-11-21 12:52 2018-08-31 Show GitHub Exploit DB Packet Storm
250123 7.5 HIGH
Network
michael-roth-software pftp Michael Roth Software Personal FTP Server (PFTP) through 8.4f allows remote attackers to cause a denial of service (daemon crash) via an unspecified sequence of FTP commands. CWE-20
 Improper Input Validation 
CVE-2018-16231 2024-11-21 12:52 2018-08-31 Show GitHub Exploit DB Packet Storm
250124 9.8 CRITICAL
Network
codemenschen gift_vouchers The Gift Vouchers plugin through 2.0.1 for WordPress allows SQL Injection via the template_id parameter in a wp-admin/admin-ajax.php wpgv_doajax_front_template request. CWE-89
SQL Injection
CVE-2018-16159 2024-11-21 12:52 2018-08-31 Show GitHub Exploit DB Packet Storm
250125 5.3 MEDIUM
Network
bijiadao waimai_super_cms waimai Super Cms 20150505 has a logic flaw allowing attackers to modify a price, before form submission, by observing data in a packet capture. By setting the index.php?m=cart&a=save item_totals para… NVD-CWE-noinfo
CVE-2018-16157 2024-11-21 12:52 2018-08-30 Show GitHub Exploit DB Packet Storm
250126 7.5 HIGH
Network
lightbend akka_http The decodeRequest and decodeRequestWith directives in Lightbend Akka HTTP 10.1.x through 10.1.4 and 10.0.x through 10.0.13 allow remote attackers to cause a denial of service (memory consumption and … CWE-400
 Uncontrolled Resource Consumption
CVE-2018-16131 2024-11-21 12:52 2018-08-30 Show GitHub Exploit DB Packet Storm
250127 9.8 CRITICAL
Network
eaton power_xpert_meter_4000_firmware
power_xpert_meter_6000_firmware
power_xpert_meter_8000_firmware
Eaton Power Xpert Meter 4000, 6000, and 8000 devices before 13.4.0.10 have a single SSH private key across different customers' installations and do not properly restrict access to this key, which ma… CWE-798
 Use of Hard-coded Credentials
CVE-2018-16158 2024-11-21 12:52 2018-08-30 Show GitHub Exploit DB Packet Storm
250128 6.1 MEDIUM
Network
phpok phpok PHPOK 4.8.278 has a Reflected XSS vulnerability in framework/www/login_control.php via the _back parameter to the ok_f function. CWE-79
Cross-site Scripting
CVE-2018-16142 2024-11-21 12:52 2018-08-30 Show GitHub Exploit DB Packet Storm
250129 6.5 MEDIUM
Network
thinkcmf thinkcmfx ThinkCMF X2.2.3 has an arbitrary file deletion vulnerability in do_avatar in \application\User\Controller\ProfileController.class.php via an imgurl parameter with a ..\ sequence. A member user can de… CWE-22
Path Traversal
CVE-2018-16141 2024-11-21 12:52 2018-08-30 Show GitHub Exploit DB Packet Storm
250130 7.8 HIGH
Local
canonical
fig2dev_project
ubuntu_linux
fig2dev
A buffer underwrite vulnerability in get_line() (read.c) in fig2dev 3.2.7a allows an attacker to write prior to the beginning of the buffer via a crafted .fig file. CWE-787
 Out-of-bounds Write
CVE-2018-16140 2024-11-21 12:52 2018-08-30 Show GitHub Exploit DB Packet Storm