NVD Vulnerability Information Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
In descending order of publication date
In descending order of update date
Number of items displayed

You can search the list of vulnerabilities managed by the NVD (National Vulnerability Database).
Since vulnerability information is often updated before JVN (Japan Vulnerability Note), vulnerabilities that are not listed in JVN may be updated.

If there is a vulnerability related to JVN (Japan Vulnerability Note), the information will be displayed on the detail page.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW

Update Date:June 25, 2026, 4:04 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
310851 9.3 HIGH
google chrome Google Chrome before 7.0.517.41 does not properly perform autofill operations for forms, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified ot… CWE-20
 Improper Input Validation 
CVE-2010-4035 2024-11-21 10:20 2010-10-22 Show GitHub Exploit DB Packet Storm
310852 9.3 HIGH
google chrome Google Chrome before 7.0.517.41 does not properly handle forms, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted … CWE-20
 Improper Input Validation 
CVE-2010-4034 2024-11-21 10:20 2010-10-22 Show GitHub Exploit DB Packet Storm
310853 5.0 MEDIUM
google chrome Google Chrome before 7.0.517.41 does not properly implement the autofill and autocomplete functionality, which allows remote attackers to conduct "profile spamming" attacks via unspecified vectors. NVD-CWE-Other
CVE-2010-4033 2024-11-21 10:20 2010-10-22 Show GitHub Exploit DB Packet Storm
310854 5.0 MEDIUM
oracle mojarra Oracle Mojarra uses an encrypted View State without a Message Authentication Code (MAC), which makes it easier for remote attackers to perform successful modifications of the View State via a padding… CWE-310
Cryptographic Issues
CVE-2010-4007 2024-11-21 10:20 2010-10-21 Show GitHub Exploit DB Packet Storm
310855 9.0 HIGH
sap businessobjects CmcApp in SAP BusinessObjects Enterprise XI 3.2 allows remote authenticated users to gain privileges via vectors involving the Program Job Server and the Program Login property. CWE-264
Permissions, Privileges, and Access Controls
CVE-2010-3983 2024-11-21 10:20 2010-10-19 Show GitHub Exploit DB Packet Storm
310856 5.0 MEDIUM
sap businessobjects SAP BusinessObjects Enterprise XI 3.2 allows remote attackers to trigger TCP connections to arbitrary intranet hosts on any port, and obtain potentially sensitive information about open ports, via th… CWE-200
Information Exposure
CVE-2010-3982 2024-11-21 10:20 2010-10-19 Show GitHub Exploit DB Packet Storm
310857 4.3 MEDIUM
sap businessobjects Cross-site scripting (XSS) vulnerability in SAP BusinessObjects Enterprise XI 3.2 allows remote attackers to inject arbitrary web script or HTML via the ServiceClass field to the Edit Service Paramet… CWE-79
Cross-site Scripting
CVE-2010-3981 2024-11-21 10:20 2010-10-19 Show GitHub Exploit DB Packet Storm
310858 4.0 MEDIUM
sap businessobjects Dswsbobje in SAP BusinessObjects Enterprise XI 3.2 does not limit the number of CUIDs that may be requested, which allows remote authenticated users to cause a denial of service via a large numCuids … NVD-CWE-Other
CVE-2010-3980 2024-11-21 10:20 2010-10-19 Show GitHub Exploit DB Packet Storm
310859 5.0 MEDIUM
sap businessobjects Dswsbobje in SAP BusinessObjects Enterprise XI 3.2 generates different error messages depending on whether the Login field corresponds to a valid username, which allows remote attackers to enumerate … CWE-200
Information Exposure
CVE-2010-3979 2024-11-21 10:20 2010-10-19 Show GitHub Exploit DB Packet Storm
310860 7.8 HIGH
Local
ettercap-project ettercap The GTK version of ettercap uses a global settings file at /tmp/.ettercap_gtk and does not verify ownership of this file. When parsing this file for settings in gtkui_conf_read() (src/interfacesgtk/e… - CVE-2010-3843 2024-11-21 10:19 2021-05-28 Show GitHub Exploit DB Packet Storm
310861 6.5 MEDIUM
Network
google chrome Google Chrome before 3.0 does not properly handle XML documents, which allows remote attackers to obtain sensitive information via a crafted web site. CWE-200
Information Exposure
CVE-2010-3917 2024-11-21 10:19 2020-02-6 Show GitHub Exploit DB Packet Storm
310862 8.8 HIGH
Network
obs-server
suse
obs-server
linux_enterprise_server
obs-server before 1.7.7 allows logins by 'unconfirmed' accounts due to a bug in the REST api implementation. CWE-863
 Incorrect Authorization
CVE-2010-3782 2024-11-21 10:19 2020-01-3 Show GitHub Exploit DB Packet Storm
310863 6.1 MEDIUM
Network
redhat jboss_business_rules_management_system JBoss BRMS before 5.1.0 has a XSS vulnerability via asset=UUID parameter. CWE-79
Cross-site Scripting
CVE-2010-3857 2024-11-21 10:19 2019-11-13 Show GitHub Exploit DB Packet Storm
310864 8.8 HIGH
Network
ettercap-project
debian
ettercap
debian_linux
An unchecked sscanf() call in ettercap before 0.7.5 allows an insecure temporary settings file to overflow a static-sized buffer on the stack. CWE-120
Classic Buffer Overflow
CVE-2010-3844 2024-11-21 10:19 2019-11-13 Show GitHub Exploit DB Packet Storm
310865 6.1 MEDIUM
Network
typo3
debian
typo3
debian_linux
TYPO3 before 4.4.1 allows XSS in the frontend search box. CWE-79
Cross-site Scripting
CVE-2010-3674 2024-11-21 10:19 2019-11-6 Show GitHub Exploit DB Packet Storm
310866 5.3 MEDIUM
Network
typo3 typo3 TYPO3 before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows information disclosure in the mail header of the HTML mailing API. CWE-200
Information Exposure
CVE-2010-3673 2024-11-21 10:19 2019-11-6 Show GitHub Exploit DB Packet Storm
310867 6.1 MEDIUM
Network
typo3 typo3 TYPO3 before 4.3.4 and 4.4.x before 4.4.1 allows XSS in the textarea view helper in an extbase extension. CWE-79
Cross-site Scripting
CVE-2010-3672 2024-11-21 10:19 2019-11-6 Show GitHub Exploit DB Packet Storm
310868 6.5 MEDIUM
Network
typo3 typo3 TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 is open to a session fixation attack which allows remote attackers to hijack a victim's session. CWE-384
 Session Fixation
CVE-2010-3671 2024-11-21 10:19 2019-11-6 Show GitHub Exploit DB Packet Storm
310869 4.8 MEDIUM
Network
typo3 typo3 TYPO3 before 4.3.4 and 4.4.x before 4.4.1 contains insecure randomness during generation of a hash with the "forgot password" function. CWE-326
Inadequate Encryption Strength
CVE-2010-3670 2024-11-21 10:19 2019-11-6 Show GitHub Exploit DB Packet Storm
310870 5.4 MEDIUM
Network
typo3 typo3 TYPO3 before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows XSS and Open Redirection in the frontend login box. CWE-79
CWE-601
Cross-site Scripting
Open Redirect
CVE-2010-3669 2024-11-21 10:19 2019-11-5 Show GitHub Exploit DB Packet Storm
310871 7.5 HIGH
Network
typo3 typo3 TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Header Injection in the secure download feature jumpurl. CWE-74
Injection
CVE-2010-3668 2024-11-21 10:19 2019-11-5 Show GitHub Exploit DB Packet Storm
310872 5.3 MEDIUM
Network
typo3 typo3 TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Spam Abuse in the native form content element. CWE-20
 Improper Input Validation 
CVE-2010-3667 2024-11-21 10:19 2019-11-5 Show GitHub Exploit DB Packet Storm
310873 5.3 MEDIUM
Network
typo3 typo3 TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 contains insecure randomness in the uniqid function. CWE-330
 Use of Insufficiently Random Values
CVE-2010-3666 2024-11-21 10:19 2019-11-5 Show GitHub Exploit DB Packet Storm
310874 5.4 MEDIUM
Network
typo3 typo3 TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows XSS on the Extension Manager. CWE-79
Cross-site Scripting
CVE-2010-3665 2024-11-21 10:19 2019-11-5 Show GitHub Exploit DB Packet Storm
310875 6.5 MEDIUM
Network
typo3 typo3 TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Information Disclosure on the backend. CWE-200
Information Exposure
CVE-2010-3664 2024-11-21 10:19 2019-11-5 Show GitHub Exploit DB Packet Storm
310876 8.8 HIGH
Network
typo3 typo3 TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 contains an insecure default value of the variable fileDenyPattern which could allow remote attackers to execute ar… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2010-3663 2024-11-21 10:19 2019-11-5 Show GitHub Exploit DB Packet Storm
310877 8.8 HIGH
Network
typo3 typo3 TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows SQL Injection on the backend. CWE-89
SQL Injection
CVE-2010-3662 2024-11-21 10:19 2019-11-5 Show GitHub Exploit DB Packet Storm
310878 6.1 MEDIUM
Network
typo3 typo3 TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Open Redirection on the backend. CWE-601
Open Redirect
CVE-2010-3661 2024-11-21 10:19 2019-11-2 Show GitHub Exploit DB Packet Storm
310879 5.4 MEDIUM
Network
typo3 typo3 TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows XSS on the backend. CWE-79
Cross-site Scripting
CVE-2010-3660 2024-11-21 10:19 2019-11-2 Show GitHub Exploit DB Packet Storm
310880 5.4 MEDIUM
Network
typo3 typo3 Multiple cross-site scripting (XSS) vulnerabilities in TYPO3 CMS 4.1.x before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4, and 4.4.x before 4.4.1 allow remote authenticated backend users to injec… CWE-79
Cross-site Scripting
CVE-2010-3659 2024-11-21 10:19 2017-10-21 Show GitHub Exploit DB Packet Storm
310881 9.8 CRITICAL
Network
apache_authenhook_project apache_authenhook libapache-authenhook-perl 2.00-04 stores usernames and passwords in plaintext in the vhost error log. CWE-200
Information Exposure
CVE-2010-3845 2024-11-21 10:19 2017-08-9 Show GitHub Exploit DB Packet Storm
310882 6.8 MEDIUM
ffmpeg
mplayerhq
ffmpeg
mplayer
FFmpeg before 0.5.4, as used in MPlayer and other products, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a mal… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2010-3908 2024-11-21 10:19 2011-05-21 Show GitHub Exploit DB Packet Storm
310883 7.6 HIGH
microsoft windows_server_2008
windows_xp
windows_7
windows_vista
windows_server_2003
windows_2003_server
fxscover.exe in the Fax Cover Page Editor in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold an… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2010-3974 2024-11-21 10:19 2011-04-14 Show GitHub Exploit DB Packet Storm
310884 9.3 HIGH
microsoft .net_framework The x86 JIT compiler in Microsoft .NET Framework 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 does not properly compile function calls, which allows remote attackers to execute arbitrary code via (1) a crafted X… CWE-20
 Improper Input Validation 
CVE-2010-3958 2024-11-21 10:19 2011-04-14 Show GitHub Exploit DB Packet Storm
310885 4.3 MEDIUM
horde groupware
dynamic_imp
Cross-site scripting (XSS) vulnerability in Horde Dynamic IMP (DIMP) before 1.1.5, and Horde Groupware Webmail Edition before 1.2.7, allows remote attackers to inject arbitrary web script or HTML via… CWE-79
Cross-site Scripting
CVE-2010-3693 2024-11-21 10:19 2011-04-4 Show GitHub Exploit DB Packet Storm
310886 4.3 MEDIUM
horde imp
groupware
Cross-site scripting (XSS) vulnerability in fetchmailprefs.php in Horde IMP before 4.3.8, and Horde Groupware Webmail Edition before 1.2.7, allows remote attackers to inject arbitrary web script or H… CWE-79
Cross-site Scripting
CVE-2010-3695 2024-11-21 10:19 2011-04-1 Show GitHub Exploit DB Packet Storm
310887 5.0 MEDIUM
openslp
vmware
openslp
esxi
esx
The extension parser in slp_v2message.c in OpenSLP 1.2.1, and other versions before SVN revision 1647, as used in Service Location Protocol daemon (SLPD) in VMware ESX 4.0 and 4.1 and ESXi 4.0 and 4.… NVD-CWE-noinfo
CVE-2010-3609 2024-11-21 10:19 2011-03-12 Show GitHub Exploit DB Packet Storm
310888 1.2 LOW
apache tomcat Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applications to read or write … NVD-CWE-Other
CVE-2010-3718 2024-11-21 10:19 2011-02-11 Show GitHub Exploit DB Packet Storm
310889 5.0 MEDIUM
modxcms evolution Directory traversal vulnerability in MODx Evolution 1.0.4 and earlier allows remote attackers to read arbitrary files via unspecified vectors related to AjaxSearch, a different vulnerability than CVE… CWE-22
Path Traversal
CVE-2010-3930 2024-11-21 10:19 2011-02-2 Show GitHub Exploit DB Packet Storm
310890 7.5 HIGH
modxcms evolution SQL injection vulnerability in MODx Evolution 1.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via unknown vectors related to AjaxSearch. CWE-89
SQL Injection
CVE-2010-3929 2024-11-21 10:19 2011-02-2 Show GitHub Exploit DB Packet Storm
310891 4.3 MEDIUM
apache couchdb Multiple cross-site scripting (XSS) vulnerabilities in the web administration interface (aka Futon) in Apache CouchDB 0.8.0 through 1.0.1 allow remote attackers to inject arbitrary web script or HTML… CWE-79
Cross-site Scripting
CVE-2010-3854 2024-11-21 10:19 2011-02-2 Show GitHub Exploit DB Packet Storm
310892 8.5 HIGH
symantec im_manager Eval injection vulnerability in IMAdminSchedTask.asp in the administrative interface for Symantec IM Manager 8.4.16 and earlier allows remote attackers to execute arbitrary code via unspecified param… CWE-94
Code Injection
CVE-2010-3719 2024-11-21 10:19 2011-02-2 Show GitHub Exploit DB Packet Storm
310893 6.9 MEDIUM
apache
debian
canonical
openoffice
debian_linux
ubuntu_linux
soffice in OpenOffice.org (OOo) 3.x before 3.3 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current… CWE-22
Path Traversal
CVE-2010-3689 2024-11-21 10:19 2011-01-29 Show GitHub Exploit DB Packet Storm
310894 6.9 MEDIUM
lunascape lunascape Untrusted search path vulnerability in Lunascape before 6.4.0 allows local users to gain privileges via a Trojan horse DLL in the current working directory. NVD-CWE-Other
CVE-2010-3927 2024-11-21 10:19 2011-01-25 Show GitHub Exploit DB Packet Storm
310895 6.9 MEDIUM
linux-pam linux-pam pam_namespace.c in the pam_namespace module in Linux-PAM (aka pam) before 1.1.3 uses the environment of the invoking application or service during execution of the namespace.init script, which might … NVD-CWE-Other
CVE-2010-3853 2024-11-21 10:19 2011-01-25 Show GitHub Exploit DB Packet Storm
310896 5.8 MEDIUM
libfuse_project libfuse FUSE, possibly 2.8.5 and earlier, allows local users to create mtab entries with arbitrary pathnames, and consequently unmount any filesystem, via a symlink attack on the parent directory of the moun… CWE-59
Link Following
CVE-2010-3879 2024-11-21 10:19 2011-01-23 Show GitHub Exploit DB Packet Storm
310897 4.3 MEDIUM
rocomotion pm_bbs
pplog_2
p_forum
p_diary_r
pm_forum
p_link_compact
pplog
p_board
p_link
p_up_board
Cross-site scripting (XSS) vulnerability in multiple Rocomotion products, including P board 1.18 and other versions, P forum 1.30 and earlier, P up board 1.38 and other versions, P diary R 1.13 and e… CWE-79
Cross-site Scripting
CVE-2010-3931 2024-11-21 10:19 2011-01-21 Show GitHub Exploit DB Packet Storm
310898 6.8 MEDIUM
wayneeseguin ruby_version_manager Ruby Version Manager (RVM) before 1.2.1 writes file contents to a terminal without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via a crafted … NVD-CWE-Other
CVE-2010-3928 2024-11-21 10:19 2011-01-21 Show GitHub Exploit DB Packet Storm
310899 9.4 HIGH
oracle fusion_middleware Unspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10.1.3.4 and 10.1.3.5 allows remote attackers to affect integrity and availability via unknown vectors r… NVD-CWE-noinfo
CVE-2010-3599 2024-11-21 10:19 2011-01-20 Show GitHub Exploit DB Packet Storm
310900 7.1 HIGH
oracle fusion_middleware Unspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10.1.3.4 and 10.1.3.5 allows remote attackers to affect integrity via unknown vectors related to Import … NVD-CWE-noinfo
CVE-2010-3598 2024-11-21 10:19 2011-01-20 Show GitHub Exploit DB Packet Storm