Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 8, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228731 5 警告 Ubercart - Drupal 用の Ubercart モジュールにおける不特定の "複製操作" を誘発される脆弱性 CWE-20
不適切な入力確認
CVE-2009-4771 2012-12-20 19:28 2009-11-18 Show GitHub Exploit DB Packet Storm
228732 9 危険 Codeorigin - Sysax Multi Server におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2009-4790 2012-12-20 19:28 2010-04-22 Show GitHub Exploit DB Packet Storm
228733 7.2 危険 tukeva - TUKEVA Password Reminder における資格情報を発見される脆弱性 CWE-255
証明書・パスワード管理
CVE-2009-4781 2012-12-20 19:28 2010-04-21 Show GitHub Exploit DB Packet Storm
228734 7.5 危険 robert garrigos - NukeHall における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2009-4779 2012-12-20 19:28 2010-04-21 Show GitHub Exploit DB Packet Storm
228735 4.3 警告 Plohni - Plohni Shoutbox の index.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4767 2012-12-20 19:28 2010-04-20 Show GitHub Exploit DB Packet Storm
228736 5 警告 yasirpro - YP Portal MS-Pro Surumu におけるデータベースをダウンロードされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2009-4766 2012-12-20 19:28 2010-04-13 Show GitHub Exploit DB Packet Storm
228737 6.8 警告 phpmyvisites - phpMyVisites に使用されている ClickHeat プラグインにおける脆弱性 CWE-noinfo
情報不足
CVE-2009-4763 2012-12-20 19:28 2010-03-30 Show GitHub Exploit DB Packet Storm
228738 5 警告 Winn GuestBook - Winn ASP Guestbook におけるデータベースをダウンロードされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2009-4760 2012-12-20 19:28 2010-03-29 Show GitHub Exploit DB Packet Storm
228739 7.5 危険 phppower - Swinger Club Portal の anzeiger/start.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2009-4752 2012-12-20 19:28 2010-03-26 Show GitHub Exploit DB Packet Storm
228740 7.5 危険 phppower - Swinger Club Portal の anzeiger/start.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-4751 2012-12-20 19:28 2010-03-26 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 8, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
194381 5.5 MEDIUM
Local
amd epyc_7003_firmware
epyc_72f3_firmware
epyc_7313_firmware
epyc_7313p_firmware
epyc_7343_firmware
epyc_73f3_firmware
epyc_7413_firmware
epyc_7443_firmware
epyc_7443p_firmware
Insufficient validation of guest context in the SNP Firmware could lead to a potential loss of guest confidentiality. CWE-668
 Exposure of Resource to Wrong Sphere
CVE-2021-26327 2024-11-21 14:56 2021-11-17 Show GitHub Exploit DB Packet Storm
194382 5.5 MEDIUM
Local
amd epyc_7232p_firmware
epyc_7763_firmware
epyc_7713p_firmware
epyc_7713_firmware
epyc_7663_firmware
epyc_7643_firmware
epyc_75f3_firmware
epyc_7543p_firmware
epyc_7543_firmware
Insufficient input validation in the SNP_GUEST_REQUEST command may lead to a potential data abort error and a denial of service. CWE-20
 Improper Input Validation 
CVE-2021-26325 2024-11-21 14:56 2021-11-17 Show GitHub Exploit DB Packet Storm
194383 7.8 HIGH
Local
amd epyc_7232p_firmware
epyc_7763_firmware
epyc_7713p_firmware
epyc_7713_firmware
epyc_7663_firmware
epyc_7643_firmware
epyc_75f3_firmware
epyc_7543p_firmware
epyc_7543_firmware
Failure to validate SEV Commands while SNP is active may result in a potential impact to memory integrity. CWE-20
 Improper Input Validation 
CVE-2021-26323 2024-11-21 14:56 2021-11-17 Show GitHub Exploit DB Packet Storm
194384 5.5 MEDIUM
Local
amd epyc_7601_firmware
epyc_7551p_firmware
epyc_7551_firmware
epyc_7501_firmware
epyc_7451_firmware
epyc_7401_firmware
epyc_7371_firmware
epyc_7351p_firmware
epyc_7351_firmware
Insufficient ID command validation in the SEV Firmware may allow a local authenticated attacker to perform a denial of service of the PSP. CWE-77
Command Injection
CVE-2021-26321 2024-11-21 14:56 2021-11-17 Show GitHub Exploit DB Packet Storm
194385 5.5 MEDIUM
Local
amd epyc_7601_firmware
epyc_7551p_firmware
epyc_7551_firmware
epyc_7501_firmware
epyc_7451_firmware
epyc_7401_firmware
epyc_7371_firmware
epyc_7351p_firmware
epyc_7351_firmware
Insufficient validation of the AMD SEV Signing Key (ASK) in the SEND_START command in the SEV Firmware may allow a local authenticated attacker to perform a denial of service of the PSP CWE-295
Improper Certificate Validation 
CVE-2021-26320 2024-11-21 14:56 2021-11-17 Show GitHub Exploit DB Packet Storm
194386 7.8 HIGH
Local
amd epyc_7003_firmware
epyc_72f3_firmware
epyc_7313_firmware
epyc_7313p_firmware
epyc_7343_firmware
epyc_73f3_firmware
epyc_7413_firmware
epyc_7443_firmware
epyc_7443p_firmware
When the AMD Platform Security Processor (PSP) boot rom loads, authenticates, and subsequently decrypts an encrypted FW, due to insufficient verification of the integrity of decrypted image, arbitrar… CWE-345
 Insufficient Verification of Data Authenticity
CVE-2021-26315 2024-11-21 14:56 2021-11-17 Show GitHub Exploit DB Packet Storm
194387 7.5 HIGH
Network
amd epyc_7f72_firmware
epyc_7f52_firmware
epyc_7f32_firmware
epyc_7h12_firmware
epyc_7742_firmware
epyc_7702_firmware
epyc_7702p_firmware
epyc_7662_firmware
epyc_7642_firmware
Improper access controls in System Management Unit (SMU) may allow for an attacker to override performance control tables located in DRAM resulting in a potential lack of system resources. NVD-CWE-Other
CVE-2021-26338 2024-11-21 14:56 2021-11-17 Show GitHub Exploit DB Packet Storm
194388 5.5 MEDIUM
Local
amd epyc_7601_firmware
epyc_7551p_firmware
epyc_7551_firmware
epyc_7501_firmware
epyc_7451_firmware
epyc_7401_firmware
epyc_7371_firmware
epyc_7351p_firmware
epyc_7351_firmware
AMD System Management Unit (SMU) may experience an integer overflow when an invalid length is provided which may result in a potential loss of resources. CWE-190
 Integer Overflow or Wraparound
CVE-2021-26329 2024-11-21 14:56 2021-11-17 Show GitHub Exploit DB Packet Storm
194389 7.8 HIGH
Local
amd epyc_7232p_firmware
epyc_7763_firmware
epyc_7713p_firmware
epyc_7713_firmware
epyc_7663_firmware
epyc_7643_firmware
epyc_75f3_firmware
epyc_7543p_firmware
epyc_7543_firmware
Failure to validate VM_HSAVE_PA during SNP_INIT may result in a loss of memory integrity. CWE-665
 Improper Initialization
CVE-2021-26326 2024-11-21 14:56 2021-11-17 Show GitHub Exploit DB Packet Storm
194390 7.5 HIGH
Network
amd epyc_7601_firmware
epyc_7551p_firmware
epyc_7551_firmware
epyc_7501_firmware
epyc_7451_firmware
epyc_7401_firmware
epyc_7371_firmware
epyc_7351p_firmware
epyc_7351_firmware
Persistent platform private key may not be protected with a random IV leading to a potential “two time pad attack”. CWE-330
 Use of Insufficiently Random Values
CVE-2021-26322 2024-11-21 14:56 2021-11-17 Show GitHub Exploit DB Packet Storm