Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 12, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
226601 10 危険 シマンテック - SSS などで使用される AMS の CBA における任意のコマンドを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2009-1429 2012-12-20 19:10 2009-04-28 Show GitHub Exploit DB Packet Storm
226602 4.3 警告 シマンテック - SAV などで使用される Symantec Log Viewer におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-1428 2012-12-20 19:10 2009-04-28 Show GitHub Exploit DB Packet Storm
226603 4.3 警告 webSPELL - webSPELL におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-1408 2012-12-20 19:10 2009-04-14 Show GitHub Exploit DB Packet Storm
226604 6.8 警告 wonko - NotFTP の config.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2009-1407 2012-12-20 19:10 2009-04-24 Show GitHub Exploit DB Packet Storm
226605 6.8 警告 sweetphp - TotalCalendar の cms_detect.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2009-1406 2012-12-20 19:10 2009-04-24 Show GitHub Exploit DB Packet Storm
226606 10 危険 forkosh - mathTex の mathtex.cgi における任意のコマンドを実行される脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2009-1383 2012-12-20 19:10 2009-07-14 Show GitHub Exploit DB Packet Storm
226607 4.3 警告 レッドハット - Red Hat JBoss Enterprise Application Platform の JBossAs におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-1380 2012-12-20 19:10 2009-12-9 Show GitHub Exploit DB Packet Storm
226608 9.3 危険 xilisoft - Xilisoft Video Converter の ape_plugin.plg におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-1370 2012-12-20 19:10 2009-04-22 Show GitHub Exploit DB Packet Storm
226609 4.9 警告 サン・マイクロシステムズ - Sun OpenSolaris の SCTP におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2009-1359 2012-12-20 19:10 2009-04-19 Show GitHub Exploit DB Packet Storm
226610 6.8 警告 サン・マイクロシステムズ - Sun Java System Delegated Administrator の da/DA/Login における CRLF インジェクションの脆弱性 CWE-20
不適切な入力確認
CVE-2009-1357 2012-12-20 19:10 2009-04-21 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 12, 2026, 5:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
213551 7.5 HIGH
Network
dasannetworks h660rm_firmware DASAN H660RM devices with firmware 1.03-0022 use a hard-coded key for logs encryption. Data stored using this key can be decrypted by anyone able to access this key. CWE-798
 Use of Hard-coded Credentials
CVE-2019-9975 2024-11-21 13:52 2019-04-12 Show GitHub Exploit DB Packet Storm
213552 9.1 CRITICAL
Network
dasannetworks h660rm_firmware diag_tool.cgi on DASAN H660RM GPON routers with firmware 1.03-0022 lacks any authorization check, which allows remote attackers to run a ping command via a GET request to enumerate LAN devices or cra… CWE-306
CWE-862
Missing Authentication for Critical Function
 Missing Authorization
CVE-2019-9974 2024-11-21 13:52 2019-04-12 Show GitHub Exploit DB Packet Storm
213553 9.8 CRITICAL
Network
jfrog artifactory An issue was discovered in JFrog Artifactory 6.7.3. By default, the access-admin account is used to reset the password of the admin account in case an administrator gets locked out from the Artifacto… NVD-CWE-noinfo
CVE-2019-9733 2024-11-21 13:52 2019-04-12 Show GitHub Exploit DB Packet Storm
213554 7.8 HIGH
Local
symantec endpoint_encryption Symantec Endpoint Encryption prior to SEE 11.2.1 MP1 may be susceptible to a Privilege Escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software ap… NVD-CWE-noinfo
CVE-2019-9694 2024-11-21 13:52 2019-04-11 Show GitHub Exploit DB Packet Storm
213555 6.1 MEDIUM
Network
symantec vip_enterprise_gateway Symantec VIP Enterprise Gateway (all versions) may be susceptible to a cross-site scripting (XSS) exploit, which is a type of issue that can enable attackers to inject client-side scripts into web pa… CWE-79
Cross-site Scripting
CVE-2019-9696 2024-11-21 13:52 2019-04-10 Show GitHub Exploit DB Packet Storm
213556 6.1 MEDIUM
Network
khanacademy
fedoraproject
simple-markdown
fedora
simple-markdown.js in Khan Academy simple-markdown before 0.4.4 allows XSS via a data: or vbscript: URI. CWE-79
Cross-site Scripting
CVE-2019-9844 2024-11-21 13:52 2019-04-9 Show GitHub Exploit DB Packet Storm
213557 7.5 HIGH
Network
kubernetes
cncf
netapp
kubernetes
portmap
cloud_insights
Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Kubernetes. The CNI 'portmap' plugin, used to setup HostPorts… CWE-670
 Always-Incorrect Control Flow Implementation
CVE-2019-9946 2024-11-21 13:52 2019-04-3 Show GitHub Exploit DB Packet Storm
213558 9.8 CRITICAL
Network
tongda2000 office_anywhere An issue was discovered in TONGDA Office Anywhere 10.18.190121. There is a SQL Injection vulnerability via the general/approve_center/list/input_form/work_handle.php run_id parameter. CWE-89
SQL Injection
CVE-2019-9759 2024-11-21 13:52 2019-04-2 Show GitHub Exploit DB Packet Storm
213559 7.5 HIGH
Network
harmistechnology je_messenger An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. Directory Traversal allows read access to arbitrary files. CWE-22
Path Traversal
CVE-2019-9922 2024-11-21 13:52 2019-03-30 Show GitHub Exploit DB Packet Storm
213560 6.5 MEDIUM
Network
harmistechnology je_messenger An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. It is possible to read information that should only be accessible by a different user. CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2019-9921 2024-11-21 13:52 2019-03-30 Show GitHub Exploit DB Packet Storm