Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 8, 2026, 4:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1191 4.3 警告
Network
Devolutions Devolutions Server DevolutionsのDevolutions Serverにおけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2026-9223 2026-05-28 14:35 2026-05-22 Show GitHub Exploit DB Packet Storm
1192 4.3 警告
Network
Devolutions Devolutions Server DevolutionsのDevolutions Serverにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2026-9224 2026-05-28 14:35 2026-05-22 Show GitHub Exploit DB Packet Storm
1193 5 警告
Network
Devolutions Devolutions Server DevolutionsのDevolutions Serverにおけるオープンリダイレクトの脆弱性 CWE-601
オープンリダイレクト
CVE-2026-9245 2026-05-28 14:35 2026-05-22 Show GitHub Exploit DB Packet Storm
1194 4.3 警告
Network
Devolutions Devolutions Server DevolutionsのDevolutions Serverにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2026-9246 2026-05-28 14:35 2026-05-22 Show GitHub Exploit DB Packet Storm
1195 2.4
Network
Devolutions Devolutions Server DevolutionsのDevolutions Serverにおける不十分なロギングに関する脆弱性 CWE-778
不十分なロギング
CVE-2026-9247 2026-05-28 14:35 2026-05-22 Show GitHub Exploit DB Packet Storm
1196 2.6
Network
Devolutions Devolutions Server DevolutionsのDevolutions Serverにおけるユーザ制御の鍵による認証回避に関する脆弱性 CWE-639
ユーザ制御の鍵による認証回避
CVE-2026-9248 2026-05-28 14:35 2026-05-22 Show GitHub Exploit DB Packet Storm
1197 3.1
Network
Devolutions Devolutions Server DevolutionsのDevolutions Serverにおける未検証のパスワード変更に関する脆弱性 CWE-620
未検証のパスワード変更
CVE-2026-9249 2026-05-28 14:35 2026-05-22 Show GitHub Exploit DB Packet Storm
1198 5.4 警告
Network
Devolutions Devolutions Server DevolutionsのDevolutions Serverにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2026-9251 2026-05-28 14:35 2026-05-22 Show GitHub Exploit DB Packet Storm
1199 9.8 緊急
Network
LiteSpeed Technologies LiteSpeed cPanel Plugin
LiteSpeed WHM Plugin (previously cPanel/WHM Plugin)
LiteSpeed TechnologiesのLiteSpeed cPanel Plugin等の複数製品における不適切な権限設定に関する脆弱性 CWE-266
不適切な権限設定
CVE-2026-48172 2026-05-28 14:34 2026-05-21 Show GitHub Exploit DB Packet Storm
1200 9.8 緊急
Network
Apache Software Foundation Apache Fory Apache Software FoundationのApache Foryにおける信頼できないデータのデシリアライゼーションに関する脆弱性 CWE-502
信頼性のないデータのデシリアライゼーション
CVE-2026-48207 2026-05-28 14:34 2026-05-21 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 8, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
310851 - oracle siebel_option_pack_ie_activex_control The Oracle Siebel Option Pack for IE ActiveX control does not properly initialize memory that is used by the NewBusObj method, which allows remote attackers to execute arbitrary code via a crafted HT… CWE-94
Code Injection
CVE-2009-3737 2024-11-21 10:08 2010-08-18 Show GitHub Exploit DB Packet Storm
310852 - oracle opensso_enterprise Unspecified vulnerability in Oracle OpenSSO Enterprise 8.0 allows remote attackers to affect integrity via unknown vectors. NVD-CWE-noinfo
CVE-2009-3762 2024-11-21 10:08 2010-07-14 Show GitHub Exploit DB Packet Storm
310853 - oracle opensso_enterprise Unspecified vulnerability in the OpenSSO component in Oracle OpenSSO Enterprise 8.0 allows remote attackers to affect integrity via unknown vectors. NVD-CWE-noinfo
CVE-2009-3764 2024-11-21 10:08 2010-07-14 Show GitHub Exploit DB Packet Storm
310854 - oracle opensso_enterprise Unspecified vulnerability in the Access Manager / OpenSSO component in Oracle OpenSSO Enterprise 7.1, 7, 2005Q4, and 8.0 allows remote attackers to affect integrity via unknown vectors. NVD-CWE-noinfo
CVE-2009-3763 2024-11-21 10:08 2010-07-14 Show GitHub Exploit DB Packet Storm
310855 - adobe
macromedia
flash_player
air
Unspecified vulnerability in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of service (memory consumption) or po… CWE-399
NVD-CWE-noinfo
 Resource Management Errors
CVE-2009-3793 2024-11-21 10:08 2010-06-16 Show GitHub Exploit DB Packet Storm
310856 3.3 LOW
Local
noping
debian
liboping
debian_linux
liboping 1.3.2 allows users reading arbitrary files upon the local system. CWE-20
 Improper Input Validation 
CVE-2009-3614 2024-11-21 10:07 2019-11-9 Show GitHub Exploit DB Packet Storm
310857 3.1 LOW
Adjacent
redhat enterprise_virtualization_manager In RHEV-M VDC 2.2.0, it was found that the SSL certificate was not verified when using the client-side Red Hat Enterprise Virtualization Manager interface (a Windows Presentation Foundation (WPF) XAM… CWE-295
Improper Certificate Validation 
CVE-2009-3552 2024-11-21 10:07 2019-11-9 Show GitHub Exploit DB Packet Storm
310858 - vmware hyperic_hq The monitor perl script in the Sybase database plug-in in SpringSource Hyperic HQ before 4.3 allows local users to obtain the database password by listing the process and its arguments. CWE-200
Information Exposure
CVE-2009-2899 2024-11-21 10:06 2012-12-6 Show GitHub Exploit DB Packet Storm
310859 - symantec altiris_deployment_solution
altiris_notification_server
management_platform
The Altiris eXpress NS SC Download ActiveX control in AeXNSPkgDLLib.dll, as used in Symantec Altiris Deployment Solution 6.9.x, Notification Server 6.0.x, and Symantec Management Platform 7.0.x expos… NVD-CWE-Other
CVE-2009-3028 2024-11-21 10:06 2011-03-8 Show GitHub Exploit DB Packet Storm
310860 6.1 MEDIUM
Network
mantisbt mantisbt MantisBT 1.2.x before 1.2.2 insecurely handles attachments and MIME types. Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks. CWE-79
Cross-site Scripting
CVE-2009-2802 2024-11-21 10:05 2019-11-9 Show GitHub Exploit DB Packet Storm