NVD Vulnerability Information Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
In descending order of publication date
In descending order of update date
Number of items displayed

You can search the list of vulnerabilities managed by the NVD (National Vulnerability Database).
Since vulnerability information is often updated before JVN (Japan Vulnerability Note), vulnerabilities that are not listed in JVN may be updated.

If there is a vulnerability related to JVN (Japan Vulnerability Note), the information will be displayed on the detail page.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW

Update Date:June 21, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
311151 5.0 MEDIUM
sun jre
jdk
sdk
Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, and 1.4.2_27 allows remote attackers to affect confidentiality via unknown ve… NVD-CWE-noinfo
CVE-2010-3551 2024-11-21 10:19 2010-10-20 Show GitHub Exploit DB Packet Storm
311152 9.3 HIGH
sun jre
jdk
Unspecified vulnerability in the Java Web Start component in Oracle Java SE and Java for Business 6 Update 21 and 5.0 Update 25 allows remote attackers to affect confidentiality, integrity, and avail… NVD-CWE-noinfo
CVE-2010-3550 2024-11-21 10:19 2010-10-20 Show GitHub Exploit DB Packet Storm
311153 6.8 MEDIUM
sun jre
jdk
sdk
Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, int… NVD-CWE-noinfo
CVE-2010-3549 2024-11-21 10:19 2010-10-20 Show GitHub Exploit DB Packet Storm
311154 5.0 MEDIUM
sun jre
jdk
sdk
Unspecified vulnerability in the Java Naming and Directory Interface (JNDI) component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, and 1.4.2_27 allows remote attackers to affec… NVD-CWE-noinfo
CVE-2010-3548 2024-11-21 10:19 2010-10-20 Show GitHub Exploit DB Packet Storm
311155 5.1 MEDIUM
sun jre
jdk
sdk
Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, int… NVD-CWE-noinfo
CVE-2010-3541 2024-11-21 10:19 2010-10-20 Show GitHub Exploit DB Packet Storm
311156 9.3 HIGH
adobe flash_player Untrusted search path vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows allows local users, and possibly remote attackers, to execute arbitrary code and cond… NVD-CWE-Other
CVE-2010-3976 2024-11-21 10:19 2010-10-20 Show GitHub Exploit DB Packet Storm
311157 9.3 HIGH
adobe flash_player Untrusted search path vulnerability in Adobe Flash Player 9 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse schannel.… NVD-CWE-Other
CVE-2010-3975 2024-11-21 10:19 2010-10-20 Show GitHub Exploit DB Packet Storm
311158 9.3 HIGH
realnetworks realplayer
realplayer_sp
Multiple heap-based buffer overflows in an ActiveX control in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1.4 allow remote attackers to execute arbitrary code via a long… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2010-3751 2024-11-21 10:19 2010-10-19 Show GitHub Exploit DB Packet Storm
311159 9.3 HIGH
realnetworks realplayer
realplayer_sp
rjrmrpln.dll in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.4, and RealPlayer Enterprise 2.1.2 does not properly validate file contents that are used during interaction w… CWE-20
 Improper Input Validation 
CVE-2010-3750 2024-11-21 10:19 2010-10-19 Show GitHub Exploit DB Packet Storm
311160 9.3 HIGH
realnetworks realplayer
realplayer_sp
The browser-plugin implementation in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1 allows remote attackers to arguments to the RecordClip method, which allows remote att… CWE-94
Code Injection
CVE-2010-3749 2024-11-21 10:19 2010-10-19 Show GitHub Exploit DB Packet Storm
311161 10.0 HIGH
realnetworks realplayer
realplayer_sp
Stack-based buffer overflow in the RichFX component in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.4, and RealPlayer Enterprise 2.1.2 allows remote attackers to have an u… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2010-3748 2024-11-21 10:19 2010-10-19 Show GitHub Exploit DB Packet Storm
311162 9.3 HIGH
realnetworks realplayer
realplayer_sp
An ActiveX control in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.4, and RealPlayer Enterprise 2.1.2 does not properly initialize an unspecified object component during p… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2010-3747 2024-11-21 10:19 2010-10-19 Show GitHub Exploit DB Packet Storm
311163 4.3 MEDIUM
twiki twiki Multiple cross-site scripting (XSS) vulnerabilities in lib/TWiki.pm in TWiki before 5.0.1 allow remote attackers to inject arbitrary web script or HTML via (1) the rev parameter to the view script or… CWE-79
Cross-site Scripting
CVE-2010-3841 2024-11-21 10:19 2010-10-19 Show GitHub Exploit DB Packet Storm
311164 6.8 MEDIUM
rim blackberry_device_software The browser in Research In Motion (RIM) BlackBerry Device Software 5.0.0.593 Platform 5.1.0.147 on the BlackBerry 9700 does not properly restrict cross-domain execution of JavaScript, which allows re… CWE-264
Permissions, Privileges, and Access Controls
CVE-2010-3934 2024-11-21 10:19 2010-10-15 Show GitHub Exploit DB Packet Storm
311165 9.0 HIGH
oracle vm Unspecified vulnerability in the OracleVM component in Oracle VM 2.2.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to ovs-agen… NVD-CWE-noinfo
CVE-2010-3585 2024-11-21 10:19 2010-10-15 Show GitHub Exploit DB Packet Storm
311166 4.3 MEDIUM
oracle vm Unspecified vulnerability in the Oracle VM component in Oracle VM 2.2.1 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to ovs-agent. NOTE: the … NVD-CWE-noinfo
CVE-2010-3584 2024-11-21 10:19 2010-10-15 Show GitHub Exploit DB Packet Storm
311167 9.0 HIGH
oracle vm Unspecified vulnerability in the OracleVM component in Oracle VM 2.2.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to ovs-agen… NVD-CWE-noinfo
CVE-2010-3583 2024-11-21 10:19 2010-10-15 Show GitHub Exploit DB Packet Storm
311168 9.0 HIGH
oracle vm Unspecified vulnerability in the OracleVM component in Oracle VM 2.2.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to ovs-agen… NVD-CWE-noinfo
CVE-2010-3582 2024-11-21 10:19 2010-10-15 Show GitHub Exploit DB Packet Storm
311169 3.5 LOW
oracle fusion_middleware Unspecified vulnerability in the BPEL Console component in Oracle Fusion Middleware 11.1.1.1.0 and 11.1.1.2.0 allows remote authenticated users to affect integrity via unknown vectors. NVD-CWE-noinfo
CVE-2010-3581 2024-11-21 10:19 2010-10-15 Show GitHub Exploit DB Packet Storm
311170 4.6 MEDIUM
oracle opensolaris Unspecified vulnerability in Oracle OpenSolaris allows local users to affect availability via unknown vectors related to Kernel/File System. NVD-CWE-noinfo
CVE-2010-3580 2024-11-21 10:19 2010-10-15 Show GitHub Exploit DB Packet Storm
311171 6.4 MEDIUM
oracle sun_products_suite Unspecified vulnerability in the (1) Sun Convergence 1 and (2) Sun Java Communications Suite 7 components in Oracle Sun Products Suite 1.0 and 7.0 allows remote attackers to affect confidentiality an… NVD-CWE-noinfo
CVE-2010-3579 2024-11-21 10:19 2010-10-15 Show GitHub Exploit DB Packet Storm
311172 9.0 HIGH
oracle opensolaris Unspecified vulnerability in Oracle OpenSolaris allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Depot Server. NVD-CWE-noinfo
CVE-2010-3578 2024-11-21 10:19 2010-10-15 Show GitHub Exploit DB Packet Storm
311173 6.4 MEDIUM
oracle opensolaris Unspecified vulnerability in Oracle OpenSolaris allows remote attackers to affect confidentiality and integrity, related to Kernel/CIFS. NVD-CWE-noinfo
CVE-2010-3577 2024-11-21 10:19 2010-10-15 Show GitHub Exploit DB Packet Storm
311174 3.6 LOW
oracle solaris
opensolaris
Unspecified vulnerability in Oracle Solaris 8, 9, and 10, and OpenSolaris, allows local users to affect integrity and availability, related to the SCSI enclosure services device driver. NVD-CWE-noinfo
CVE-2010-3576 2024-11-21 10:19 2010-10-15 Show GitHub Exploit DB Packet Storm
311175 6.4 MEDIUM
oracle sun_product_suite Unspecified vulnerability in the Oracle Communications Messaging Server (Sun Java System Messaging Server) component in Oracle Sun Products Suite 6.0, 6.2, 6.3, and 7.0 allows remote attackers to aff… NVD-CWE-noinfo
CVE-2010-3575 2024-11-21 10:19 2010-10-15 Show GitHub Exploit DB Packet Storm
311176 6.4 MEDIUM
oracle sun_products_suite Unspecified vulnerability in the Oracle Communications Messaging Server (Sun Java System Messaging Server) component in Oracle Sun Products Suite 7.0 allows remote attackers to affect confidentiality… NVD-CWE-noinfo
CVE-2010-3564 2024-11-21 10:19 2010-10-15 Show GitHub Exploit DB Packet Storm
311177 5.5 MEDIUM
oracle peoplesoft_and_jdedwards_product_suite Unspecified vulnerability in the PeopleSoft FMS ESA - EX component in Oracle PeopleSoft and JDEdwards Suite 8.9 Bundle #38, 9.0 Bundle #31, and 9.1 Bundle #6 allows remote authenticated users to affe… NVD-CWE-noinfo
CVE-2010-3547 2024-11-21 10:19 2010-10-15 Show GitHub Exploit DB Packet Storm
311178 5.8 MEDIUM
oracle sun_products_suite Unspecified vulnerability in the Sun Java System Identity Manager component in Oracle Sun Products Suite 8.1 allows remote attackers to affect confidentiality and integrity via unknown vectors. NVD-CWE-noinfo
CVE-2010-3546 2024-11-21 10:19 2010-10-15 Show GitHub Exploit DB Packet Storm
311179 5.8 MEDIUM
oracle sun_products_suite Unspecified vulnerability in the Oracle iPlanet Web Server (Sun Java System Web Server) component in Oracle Sun Products Suite 7.0 allows remote attackers to affect confidentiality and integrity via … NVD-CWE-noinfo
CVE-2010-3545 2024-11-21 10:19 2010-10-15 Show GitHub Exploit DB Packet Storm
311180 5.8 MEDIUM
oracle sun_products_suite Unspecified vulnerability in the Oracle iPlanet Web Server (Sun Java System Web Server) component in Oracle Sun Products Suite 7.0 allows remote attackers to affect integrity and availability via unk… NVD-CWE-noinfo
CVE-2010-3544 2024-11-21 10:19 2010-10-15 Show GitHub Exploit DB Packet Storm
311181 1.9 LOW
oracle solaris
opensolaris
Unspecified vulnerability in Oracle Solaris 8, 9, and 10, and OpenSolaris, allows local users to affect confidentiality, related to USB. NVD-CWE-noinfo
CVE-2010-3542 2024-11-21 10:19 2010-10-15 Show GitHub Exploit DB Packet Storm
311182 4.0 MEDIUM
oracle opensolaris
solaris
Unspecified vulnerability in Oracle Solaris 10 and OpenSolaris allows local users to affect availability, related to ZFS. NVD-CWE-noinfo
CVE-2010-3540 2024-11-21 10:19 2010-10-15 Show GitHub Exploit DB Packet Storm
311183 5.5 MEDIUM
oracle peoplesoft_and_jdedwards_product_suite Unspecified vulnerability in the PeopleSoft Enterprise FMS - GL component in Oracle PeopleSoft and JDEdwards Suite 8.9 Bundle #38, 9.0 Bundle #31, and 9.1 Bundle #6 allows remote authenticated users … NVD-CWE-noinfo
CVE-2010-3539 2024-11-21 10:19 2010-10-15 Show GitHub Exploit DB Packet Storm
311184 5.5 MEDIUM
oracle peoplesoft_and_jdedwards_product_suite Unspecified vulnerability in the PeopleSoft Enterprise FMS - GL component in Oracle PeopleSoft and JDEdwards Suite 8.9 Bundle #38, 9.0 Bundle #31, and 9.1 Bundle #6 allows remote authenticated users … NVD-CWE-noinfo
CVE-2010-3538 2024-11-21 10:19 2010-10-15 Show GitHub Exploit DB Packet Storm
311185 5.0 MEDIUM
infradead openconnect Unspecified vulnerability in OpenConnect before 2.23 allows remote AnyConnect SSL VPN servers to cause a denial of service (application crash) via a 404 HTTP status code. NVD-CWE-noinfo
CVE-2010-3903 2024-11-21 10:19 2010-10-14 Show GitHub Exploit DB Packet Storm
311186 5.0 MEDIUM
infradead openconnect OpenConnect before 2.26 places the webvpn cookie value in the debugging output, which might allow remote attackers to obtain sensitive information by reading this output, as demonstrated by output po… CWE-200
Information Exposure
CVE-2010-3902 2024-11-21 10:19 2010-10-14 Show GitHub Exploit DB Packet Storm
311187 6.4 MEDIUM
infradead openconnect OpenConnect before 2.25 does not properly validate X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary AnyConnect SSL VPN servers via a crafted server certificate that (1)… CWE-20
 Improper Input Validation 
CVE-2010-3901 2024-11-21 10:19 2010-10-14 Show GitHub Exploit DB Packet Storm
311188 5.8 MEDIUM
christian_dywan midori Midori before 0.2.5, when WebKitGTK+ before 1.1.14 or LibSoup before 2.29.91 is used, does not verify X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary https web sites v… NVD-CWE-Other
CVE-2010-3900 2024-11-21 10:19 2010-10-14 Show GitHub Exploit DB Packet Storm
311189 4.0 MEDIUM
redhat enterprise_mrg lib/MessageStoreImpl.cpp in Red Hat Enterprise MRG before 1.2.2 allows remote authenticated users to cause a denial of service (stack memory exhaustion and broker crash) via a large persistent messag… CWE-399
 Resource Management Errors
CVE-2010-3701 2024-11-21 10:19 2010-10-13 Show GitHub Exploit DB Packet Storm
311190 7.2 HIGH
microsoft windows Unspecified vulnerability in Microsoft Windows on 32-bit platforms allows local users to gain privileges via unknown vectors, as exploited in the wild in July 2010 by the Stuxnet worm, and identified… NVD-CWE-noinfo
CVE-2010-3889 2024-11-21 10:19 2010-10-9 Show GitHub Exploit DB Packet Storm
311191 7.2 HIGH
microsoft windows Unspecified vulnerability in Microsoft Windows on 32-bit platforms allows local users to gain privileges via unknown vectors, as exploited in the wild in July 2010 by the Stuxnet worm, and identified… NVD-CWE-noinfo
CVE-2010-3888 2024-11-21 10:19 2010-10-9 Show GitHub Exploit DB Packet Storm
311192 4.3 MEDIUM
apple mail The Limit Mail feature in the Parental Controls functionality in Mail on Apple Mac OS X does not properly enforce the correspondence whitelist, which allows remote attackers to bypass intended access… CWE-264
Permissions, Privileges, and Access Controls
CVE-2010-3887 2024-11-21 10:19 2010-10-9 Show GitHub Exploit DB Packet Storm
311193 4.3 MEDIUM
microsoft internet_explorer The CTimeoutEventList::InsertIntoTimeoutList function in Microsoft mshtml.dll uses a certain pointer value as part of producing Timer ID values for the setTimeout and setInterval methods in VBScript … CWE-200
Information Exposure
CVE-2010-3886 2024-11-21 10:19 2010-10-9 Show GitHub Exploit DB Packet Storm
311194 6.8 MEDIUM
cmsmadesimple cms_made_simple Cross-site request forgery (CSRF) vulnerability in CMS Made Simple 1.8.1 and earlier allows remote attackers to hijack the authentication of administrators for requests that reset the administrative … CWE-352
 Origin Validation Error
CVE-2010-3884 2024-11-21 10:19 2010-10-9 Show GitHub Exploit DB Packet Storm
311195 6.8 MEDIUM
cmsmadesimple cms_made_simple Cross-site request forgery (CSRF) vulnerability in the Change Group Permissions module in CMS Made Simple 1.7.1 and earlier allows remote attackers to hijack the authentication of arbitrary users for… CWE-352
 Origin Validation Error
CVE-2010-3883 2024-11-21 10:19 2010-10-9 Show GitHub Exploit DB Packet Storm
311196 4.3 MEDIUM
cmsmadesimple cms_made_simple Multiple cross-site scripting (XSS) vulnerabilities in CMS Made Simple 1.7.1 and earlier allow remote attackers to inject arbitrary web script or HTML via input to the (1) Add Pages, (2) Add Global C… CWE-79
Cross-site Scripting
CVE-2010-3882 2024-11-21 10:19 2010-10-9 Show GitHub Exploit DB Packet Storm
311197 5.0 MEDIUM
rene_tegel visual_synapse Directory traversal vulnerability in Visual Synapse HTTP Server 1.0 RC1 through RC3, and 0.60 and earlier, allows remote attackers to read arbitrary files via a .. (dot dot) in the URI. CWE-22
Path Traversal
CVE-2010-3743 2024-11-21 10:19 2010-10-9 Show GitHub Exploit DB Packet Storm
311198 4.3 MEDIUM
freeradius freeradius The wait_for_child_to_die function in main/event.c in FreeRADIUS 2.1.x before 2.1.10, in certain circumstances involving long-term database outages, does not properly handle long queue times for requ… CWE-399
 Resource Management Errors
CVE-2010-3697 2024-11-21 10:19 2010-10-8 Show GitHub Exploit DB Packet Storm
311199 4.3 MEDIUM
freeradius freeradius The fr_dhcp_decode function in lib/dhcp.c in FreeRADIUS 2.1.9, in certain non-default builds, does not properly handle the DHCP Relay Agent Information option, which allows remote attackers to cause … CWE-399
 Resource Management Errors
CVE-2010-3696 2024-11-21 10:19 2010-10-8 Show GitHub Exploit DB Packet Storm
311200 6.4 MEDIUM
apereo phpcas Directory traversal vulnerability in the callback function in client.php in phpCAS before 1.1.3, when proxy mode is enabled, allows remote attackers to create or overwrite arbitrary files via directo… CWE-22
Path Traversal
CVE-2010-3692 2024-11-21 10:19 2010-10-8 Show GitHub Exploit DB Packet Storm