Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 6, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228871 4.3 警告 qtmsoft - Qualiteam X-Cart の customer/home.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-3592 2012-12-20 19:28 2009-10-8 Show GitHub Exploit DB Packet Storm
228872 7.5 危険 vspanel - VS PANEL の showcat.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-3590 2012-12-20 19:28 2009-10-8 Show GitHub Exploit DB Packet Storm
228873 5 警告 sql-ledger - SQL-Ledger におけるクッキーをキャプチャされる脆弱性 CWE-16
環境設定
CVE-2009-3584 2012-12-20 19:28 2009-12-23 Show GitHub Exploit DB Packet Storm
228874 5.1 警告 sql-ledger - SQL-Ledger の Preferences メニュー項目におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2009-3583 2012-12-20 19:28 2009-12-23 Show GitHub Exploit DB Packet Storm
228875 6.5 警告 sql-ledger - SQL-Ledger の delete サブルーチンにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-3582 2012-12-20 19:28 2009-12-23 Show GitHub Exploit DB Packet Storm
228876 3.5 注意 sql-ledger - SQL-Ledger におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-3581 2012-12-20 19:28 2009-12-23 Show GitHub Exploit DB Packet Storm
228877 6.8 警告 sql-ledger - SQL-Ledger の am.pl におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2009-3580 2012-12-20 19:28 2009-12-23 Show GitHub Exploit DB Packet Storm
228878 10 危険 tatsuhiro tsujikawa - aria の DHTRoutingTableDeserializer.cc におけるバッファオーバーフローの脆弱性 CWE-noinfo
情報不足
CVE-2009-3575 2012-12-20 19:28 2009-10-7 Show GitHub Exploit DB Packet Storm
228879 9.3 危険 tony million - Tuniac におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2009-3574 2012-12-20 19:28 2009-10-6 Show GitHub Exploit DB Packet Storm
228880 2.6 注意 xerver - Xerver HTTP Server におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-3562 2012-12-20 19:28 2009-10-5 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 6, 2026, 4:18 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
194751 7.8 HIGH
Local
avaya aura_device_services An arbitrary code execution vulnerability was discovered in Avaya Aura Device Services that may potentially allow a local user to execute specially crafted scripts. Affects 7.0 through 8.1.4.0 versio… NVD-CWE-noinfo
CVE-2021-25654 2024-11-21 14:55 2021-06-26 Show GitHub Exploit DB Packet Storm
194752 8.1 HIGH
Network
open-emr openemr In OpenEMR, versions 5.0.0 to 6.0.0.1 are vulnerable to weak password requirements as it does not enforce a maximum password length limit. If a malicious user is aware of the first 72 characters of t… CWE-521
Weak Password Requirements 
CVE-2021-25923 2024-11-21 14:55 2021-06-24 Show GitHub Exploit DB Packet Storm
194753 5.4 MEDIUM
Network
avaya aura_experience_portal Stored XSS injection vulnerabilities were discovered in the Avaya Aura Experience Portal Web management which could allow an authenticated user to potentially disclose sensitive information. Affected… CWE-79
Cross-site Scripting
CVE-2021-25656 2024-11-21 14:55 2021-06-24 Show GitHub Exploit DB Packet Storm
194754 6.1 MEDIUM
Network
avaya aura_experience_portal A vulnerability in the system Service Menu component of Avaya Aura Experience Portal may allow URL Redirection to any untrusted site through a crafted attack. Affected versions include 7.0 through 7.… CWE-601
Open Redirect
CVE-2021-25655 2024-11-21 14:55 2021-06-24 Show GitHub Exploit DB Packet Storm
194755 7.8 HIGH
Local
avaya aura_appliance_virtualization_platform A privilege escalation vulnerability was discovered in Avaya Aura Appliance Virtualization Platform Utilities (AVPU) that may potentially allow a local user to escalate privileges. Affects 8.0.0.0 th… NVD-CWE-noinfo
CVE-2021-25653 2024-11-21 14:55 2021-06-24 Show GitHub Exploit DB Packet Storm
194756 5.5 MEDIUM
Local
avaya aura_appliance_virtualization_platform An information disclosure vulnerability was discovered in the directory and file management of Avaya Aura Appliance Virtualization Platform Utilities (AVPU). This vulnerability may potentially allow … CWE-668
 Exposure of Resource to Wrong Sphere
CVE-2021-25652 2024-11-21 14:55 2021-06-24 Show GitHub Exploit DB Packet Storm
194757 7.8 HIGH
Local
avaya aura_utility_services A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local user to escalate privileges. Affects all 7.x versions of Avaya Aura Utility Servi… CWE-269
 Improper Privilege Management
CVE-2021-25651 2024-11-21 14:55 2021-06-24 Show GitHub Exploit DB Packet Storm
194758 8.8 HIGH
Local
avaya aura_utility_services A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local user to execute specially crafted scripts as a privileged user. Affects all 7.x v… CWE-269
 Improper Privilege Management
CVE-2021-25650 2024-11-21 14:55 2021-06-24 Show GitHub Exploit DB Packet Storm
194759 5.5 MEDIUM
Local
avaya aura_utility_services An information disclosure vulnerability was discovered in the directory and file management of Avaya Aura Utility Services. This vulnerability may potentially allow any local user to access system fu… NVD-CWE-Other
CVE-2021-25649 2024-11-21 14:55 2021-06-24 Show GitHub Exploit DB Packet Storm
194760 7.8 HIGH
Local
canonical apport It was discovered that apport in data/apport did not properly open a report file to prevent hanging reads on a FIFO. CWE-20
 Improper Input Validation 
CVE-2021-25684 2024-11-21 14:55 2021-06-11 Show GitHub Exploit DB Packet Storm