Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 22, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228081 5 警告 サン・マイクロシステムズ - Sun Java SE の Java Web Start 実装におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2009-2719 2012-12-20 19:10 2009-08-10 Show GitHub Exploit DB Packet Storm
228082 6.8 警告 サン・マイクロシステムズ - Sun Java SE の AWT 実装におけるユーザに信頼されないアプレットと保護されない通信をさせる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2009-2718 2012-12-20 19:10 2009-08-10 Show GitHub Exploit DB Packet Storm
228083 6.8 警告 サン・マイクロシステムズ - Windows 上で稼動している Sun Java SE の AWT 実装におけるユーザに信頼されないアプレットと保護されない通信をさせる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2009-2717 2012-12-20 19:10 2009-08-10 Show GitHub Exploit DB Packet Storm
228084 7.5 危険 サン・マイクロシステムズ - Sun Java SE のプラグイン機能における "古い zip および証明書処理" の脆弱性を悪用される脆弱性 CWE-noinfo
情報不足
CVE-2009-2716 2012-12-20 19:10 2009-08-10 Show GitHub Exploit DB Packet Storm
228085 4.9 警告 サン・マイクロシステムズ - Sun VirtualBox におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2009-2715 2012-12-20 19:10 2009-08-7 Show GitHub Exploit DB Packet Storm
228086 4.9 警告 サン・マイクロシステムズ - Sun VirtualBox におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2009-2714 2012-12-20 19:10 2009-08-5 Show GitHub Exploit DB Packet Storm
228087 4.3 警告 サン・マイクロシステムズ - Sun Java System Access Manager の CDCServlet コンポーネントにおける重要な情報を取得される脆弱性 CWE-noinfo
情報不足
CVE-2009-2713 2012-12-20 19:10 2009-08-5 Show GitHub Exploit DB Packet Storm
228088 2.1 注意 サン・マイクロシステムズ - Sun Java System Access Manager および OpenSSO Enterprise などにおける平文パスワードを特定される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2009-2712 2012-12-20 19:10 2009-08-5 Show GitHub Exploit DB Packet Storm
228089 5 警告 strongSwan - strongSwan の asn1_length 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-310
暗号の問題
CVE-2009-2661 2012-12-20 19:10 2009-07-23 Show GitHub Exploit DB Packet Storm
228090 7.5 危険 ZNC - ZNC におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2009-2658 2012-12-20 19:10 2009-08-4 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 22, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
225381 8.8 HIGH
Network
opmantek open-audit The Create Discoveries feature of Open-AudIT before 3.2.0 allows an authenticated attacker to execute arbitrary OS commands via a crafted value for a URL field. CWE-78
OS Command 
CVE-2019-16293 2024-11-21 13:30 2019-09-14 Show GitHub Exploit DB Packet Storm
225382 5.4 MEDIUM
Network
webcraftic woody_ad_snippets The insert-php (aka Woody ad snippets) plugin before 2.2.8 for WordPress allows authenticated XSS via the winp_item parameter. CWE-79
Cross-site Scripting
CVE-2019-16289 2024-11-21 13:30 2019-09-14 Show GitHub Exploit DB Packet Storm
225383 7.5 HIGH
Network
tenda n301_firmware On Tenda N301 wireless routers, a long string in the wifiSSID parameter of a goform/setWifi POST request causes the device to crash. NVD-CWE-noinfo
CVE-2019-16288 2024-11-21 13:30 2019-09-14 Show GitHub Exploit DB Packet Storm
225384 7.8 HIGH
Local
picoc_project picoc PicoC 2.1 has a heap-based buffer overflow in StringStrcpy in cstdlib/string.c when called from ExpressionParseFunctionCall in expression.c. CWE-787
 Out-of-bounds Write
CVE-2019-16277 2024-11-21 13:30 2019-09-13 Show GitHub Exploit DB Packet Storm
225385 6.5 MEDIUM
Adjacent
w1.fi
debian
canonical
hostapd
wpa_supplicant
debian_linux
ubuntu_linux
hostapd before 2.10 and wpa_supplicant before 2.10 allow an incorrect indication of disconnection in certain situations because source address validation is mishandled. This is a denial of service th… CWE-346
 Origin Validation Error
CVE-2019-16275 2024-11-21 13:30 2019-09-13 Show GitHub Exploit DB Packet Storm
225386 6.1 MEDIUM
Network
afterlogic aurora Afterlogic Aurora through 8.3.9-build-a3 has XSS that can be leveraged for session hijacking by retrieving the session cookie from the administrator login. CWE-79
Cross-site Scripting
CVE-2019-16238 2024-11-21 13:30 2019-09-13 Show GitHub Exploit DB Packet Storm
225387 9.1 CRITICAL
Network
tripplite pdumh15at_firmware Tripp Lite PDUMH15AT 12.04.0053 devices allow unauthenticated POST requests to the /Forms/ directory, as demonstrated by changing the manager or admin password, or shutting off power to an outlet. NO… CWE-287
Improper Authentication
CVE-2019-16261 2024-11-21 13:30 2019-09-13 Show GitHub Exploit DB Packet Storm
225388 9.8 CRITICAL
Network
motorola motorola_firmware Some Motorola devices include the SIMalliance Toolbox Browser (aka S@T Browser) on the UICC, which might allow remote attackers to retrieve location and IMEI information, or retrieve other data or ex… NVD-CWE-noinfo
CVE-2019-16257 2024-11-21 13:30 2019-09-12 Show GitHub Exploit DB Packet Storm
225389 9.8 CRITICAL
Network
samsung samsung_firmware Some Samsung devices include the SIMalliance Toolbox Browser (aka S@T Browser) on the UICC, which might allow remote attackers to retrieve location and IMEI information, or retrieve other data or exe… NVD-CWE-noinfo
CVE-2019-16256 2024-11-21 13:30 2019-09-12 Show GitHub Exploit DB Packet Storm
225390 7.5 HIGH
Network
oceanwp ocean_extra includes/wizard/wizard.php in the Ocean Extra plugin through 1.5.8 for WordPress allows unauthenticated options changes and injection of a Cascading Style Sheets (CSS) token sequence. CWE-287
Improper Authentication
CVE-2019-16250 2024-11-21 13:30 2019-09-12 Show GitHub Exploit DB Packet Storm