Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 9, 2026, 2:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228491 7.5 危険 phpkick - PHPKick の statistics.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-3029 2012-12-20 19:29 2010-08-16 Show GitHub Exploit DB Packet Storm
228492 3.6 注意 Simon Phillips - Joomla! 用の Aardvertiser コンポーネントにおける特定のファイルを変更される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2010-3028 2012-12-20 19:29 2010-08-16 Show GitHub Exploit DB Packet Storm
228493 7.5 危険 tycoon - Tycoon Baseball Script の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-3027 2012-12-20 19:29 2010-08-16 Show GitHub Exploit DB Packet Storm
228494 5 警告 Wireshark - Wireshark の GSM A RR 解析子におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2010-2992 2012-12-20 19:29 2010-06-21 Show GitHub Exploit DB Packet Storm
228495 9.3 危険 raphael assenat - libmikmod の loaders/load_it.c におけるバッファオーバーリードを誘発される脆弱性 CWE-119
バッファエラー
CVE-2010-2971 2012-12-20 19:29 2010-08-5 Show GitHub Exploit DB Packet Storm
228496 7.8 危険 ウインドリバー株式会社 - Wind River VxWorks の FTP デーモンにおけるアクセス権を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2010-2968 2012-12-20 19:29 2010-08-5 Show GitHub Exploit DB Packet Storm
228497 7.8 危険 ウインドリバー株式会社 - Wind River VxWorks の loginLib におけるアクセス権を取得される脆弱性 CWE-310
暗号の問題
CVE-2010-2967 2012-12-20 19:29 2010-08-5 Show GitHub Exploit DB Packet Storm
228498 7.8 危険 ウインドリバー株式会社 - Wind River VxWorks の INCLUDE_SECURITY 機能におけるアクセス権を取得される脆弱性 CWE-255
証明書・パスワード管理
CVE-2010-2966 2012-12-20 19:29 2010-08-5 Show GitHub Exploit DB Packet Storm
228499 10 危険 Rockwell Automation
ウインドリバー株式会社
- Rockwell Automation 1756-ENBT series A で使用されている Wind River VxWorks における任意のメモリ領域を読まれる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2010-2965 2012-12-20 19:29 2010-08-5 Show GitHub Exploit DB Packet Storm
228500 6.9 警告 simone rota - SLiM における権限を取得される脆弱性 CWE-16
環境設定
CVE-2010-2945 2012-12-20 19:29 2010-08-30 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 9, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
194331 5.9 MEDIUM
Network
cira canadian_shield The CIRA Canadian Shield app before 4.0.13 for iOS lacks SSL Certificate Validation. CWE-295
Improper Certificate Validation 
CVE-2021-27189 2024-11-21 14:57 2021-02-23 Show GitHub Exploit DB Packet Storm
194332 5.4 MEDIUM
Network
mybb mybb MyBB before 1.8.25 allows stored XSS via nested [email] tags with MyCode (aka BBCode). CWE-79
Cross-site Scripting
CVE-2021-27279 2024-11-21 14:57 2021-02-23 Show GitHub Exploit DB Packet Storm
194333 9.8 CRITICAL
Network
shinobi shinobi_pro An issue was discovered in Shinobi through ocean version 1. lib/auth.js has Incorrect Access Control. Valid API Keys are held in an internal JS Object. Therefore an attacker can use JS Proto Method n… CWE-798
 Use of Hard-coded Credentials
CVE-2021-27228 2024-11-21 14:57 2021-02-23 Show GitHub Exploit DB Packet Storm
194334 5.4 MEDIUM
Network
monicahq monica The Contact page in Monica 2.19.1 allows stored XSS via the Description field. CWE-79
Cross-site Scripting
CVE-2021-27371 2024-11-21 14:57 2021-02-23 Show GitHub Exploit DB Packet Storm
194335 5.4 MEDIUM
Network
monicahq monica The Contact page in Monica 2.19.1 allows stored XSS via the Last Name field. CWE-79
Cross-site Scripting
CVE-2021-27370 2024-11-21 14:57 2021-02-23 Show GitHub Exploit DB Packet Storm
194336 5.4 MEDIUM
Network
monicahq monica The Contact page in Monica 2.19.1 allows stored XSS via the Middle Name field. CWE-79
Cross-site Scripting
CVE-2021-27369 2024-11-21 14:57 2021-02-23 Show GitHub Exploit DB Packet Storm
194337 5.4 MEDIUM
Network
monicahq monica The Contact page in Monica 2.19.1 allows stored XSS via the First Name field. CWE-79
Cross-site Scripting
CVE-2021-27368 2024-11-21 14:57 2021-02-23 Show GitHub Exploit DB Packet Storm
194338 5.3 MEDIUM
Network
telegram telegram The Terminate Session feature in the Telegram application through 7.2.1 for Android, and through 2.4.7 for Windows and UNIX, fails to invalidate a recently active session. CWE-613
 Insufficient Session Expiration
CVE-2021-27351 2024-11-21 14:57 2021-02-20 Show GitHub Exploit DB Packet Storm
194339 6.5 MEDIUM
Network
yeastar neogate_tg400_firmware Yeastar NeoGate TG400 91.3.0.3 devices are affected by Directory Traversal. An authenticated user can decrypt firmware and can read sensitive information, such as a password or decryption key. CWE-22
Path Traversal
CVE-2021-27328 2024-11-21 14:57 2021-02-20 Show GitHub Exploit DB Packet Storm
194340 6.1 MEDIUM
Network
zohocorp manageengine_adselfservice_plus A Server-side request forgery (SSRF) vulnerability in the ProductConfig servlet in Zoho ManageEngine ADSelfService Plus through 6013 allows a remote unauthenticated attacker to perform blind HTTP req… CWE-79
CWE-918
Cross-site Scripting
Server-Side Request Forgery (SSRF) 
CVE-2021-27214 2024-11-21 14:57 2021-02-20 Show GitHub Exploit DB Packet Storm