Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":July 1, 2026, 4:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
259861 6.8 警告 アップル - Apple iOS の Telephony 内にある GSM 方式の通信管理の実装におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2010-3832 2010-12-20 14:39 2010-11-26 Show GitHub Exploit DB Packet Storm
259862 4.3 警告 アップル - Apple iOS の Photos における MobileMe アカウントのパスワードを読まれる脆弱性 CWE-200
情報漏えい
CVE-2010-3831 2010-12-20 14:32 2010-11-26 Show GitHub Exploit DB Packet Storm
259863 7.2 危険 アップル - Apple iOS の Networking における権限昇格の脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2010-3830 2010-12-20 14:30 2010-11-26 Show GitHub Exploit DB Packet Storm
259864 4.3 警告 アップル - Apple iOS の iAd Content Display における電話をかけられる脆弱性 CWE-Other
その他
CVE-2010-3828 2010-12-20 14:17 2010-11-26 Show GitHub Exploit DB Packet Storm
259865 4.3 警告 アップル - Apple iOS のプロファイルを偽装される脆弱性 CWE-20
不適切な入力確認
CVE-2010-3827 2010-12-20 14:11 2010-11-26 Show GitHub Exploit DB Packet Storm
259866 6.8 警告 アップル - Apple Mac OS X の QuickTime における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2010-3795 2010-12-17 14:29 2010-11-16 Show GitHub Exploit DB Packet Storm
259867 6.8 警告 アップル - Apple Mac OS X の QuickTime における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2010-3794 2010-12-17 14:29 2010-11-16 Show GitHub Exploit DB Packet Storm
259868 6.8 警告 アップル - Apple Mac OS X の QuickTime における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2010-3793 2010-12-17 14:28 2010-11-16 Show GitHub Exploit DB Packet Storm
259869 6.8 警告 アップル - Apple Mac OS X の QuickTime における整数符号エラーの脆弱性 CWE-189
数値処理の問題
CVE-2010-3792 2010-12-17 14:27 2010-11-16 Show GitHub Exploit DB Packet Storm
259870 6.8 警告 アップル - Apple Mac OS X の QuickTime におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2010-3791 2010-12-17 13:59 2010-11-16 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:July 1, 2026, 4:27 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
246321 9.8 CRITICAL
Network
crashfix_project crashfix CrashFix 1.0.4 has SQL Injection via the User[status] parameter. This is related to actionIndex in UserController.php, and the protected\models\User.php search() function. CWE-89
SQL Injection
CVE-2018-20508 2024-11-21 13:01 2018-12-27 Show GitHub Exploit DB Packet Storm
246322 6.5 MEDIUM
Network
axiosys bento4 An issue was discovered in Bento4 1.5.1-627. There is an attempt at excessive memory allocation in the AP4_DataBuffer class when called from AP4_HvccAtom::Create in Core/Ap4HvccAtom.cpp. CWE-400
 Uncontrolled Resource Consumption
CVE-2018-20502 2024-11-21 13:01 2018-12-27 Show GitHub Exploit DB Packet Storm
246323 7.5 HIGH
Network
viatech epia-e900_firmware ETK_E900.sys, a SmartETK driver for VIA Technologies EPIA-E900 system board, is vulnerable to denial of service attack via IOCTL 0x9C402048, which calls memmove and constantly fails on an arbitrary (… CWE-20
 Improper Input Validation 
CVE-2018-20404 2024-11-21 13:01 2018-12-27 Show GitHub Exploit DB Packet Storm
246324 5.3 MEDIUM
Network
mit
debian
kerberos
debian_linux
A Reachable Assertion issue was discovered in the KDC in MIT Kerberos 5 (aka krb5) before 1.17. If an attacker can obtain a krbtgt ticket using an older encryption type (single-DES, triple-DES, or RC… CWE-617
 Reachable Assertion
CVE-2018-20217 2024-11-21 13:01 2018-12-27 Show GitHub Exploit DB Packet Storm
246325 6.1 MEDIUM
Network
metinfo metinfo MetInfo 6.x through 6.1.3 has XSS via the /admin/login/login_check.php url_array[] parameter. CWE-79
Cross-site Scripting
CVE-2018-20486 2024-11-21 13:01 2018-12-27 Show GitHub Exploit DB Packet Storm
246326 6.1 MEDIUM
Network
zohocorp manageengine_adselfservice_plus Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the employee search feature. CWE-79
Cross-site Scripting
CVE-2018-20485 2024-11-21 13:01 2018-12-27 Show GitHub Exploit DB Packet Storm
246327 6.1 MEDIUM
Network
zohocorp manageengine_adselfservice_plus Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the self-update layout implementation. CWE-79
Cross-site Scripting
CVE-2018-20484 2024-11-21 13:01 2018-12-27 Show GitHub Exploit DB Packet Storm
246328 4.7 MEDIUM
Local
gnu
debian
opensuse
tar
debian_linux
leap
GNU Tar through 1.30, when --sparse is used, mishandles file shrinkage during read access, which allows local users to cause a denial of service (infinite read loop in sparse_dump_region in sparse.c)… CWE-835
 Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2018-20482 2024-11-21 13:01 2018-12-27 Show GitHub Exploit DB Packet Storm
246329 7.8 HIGH
Local
gnu wget set_file_metadata in xattr.c in GNU Wget before 1.20.1 stores a file's origin URL in the user.xdg.origin.url metadata attribute of the extended attributes of the downloaded file, which allows local u… CWE-200
Information Exposure
CVE-2018-20483 2024-11-21 13:01 2018-12-27 Show GitHub Exploit DB Packet Storm
246330 6.5 MEDIUM
Network
freedesktop
canonical
debian
poppler
ubuntu_linux
debian_linux
XRef::getEntry in XRef.cc in Poppler 0.72.0 mishandles unallocated XRef entries, which allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted PDF document, when… CWE-476
 NULL Pointer Dereference
CVE-2018-20481 2024-11-21 13:01 2018-12-26 Show GitHub Exploit DB Packet Storm