Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 7, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
230281 7.5 危険 SAP - SAP IGS におけるヒープベースのバッファオーバーフローの脆弱性 - CVE-2006-4133 2012-12-20 18:02 2006-08-14 Show GitHub Exploit DB Packet Storm
230282 6.5 警告 symantec veritas - Symantec VERITAS Backup Exec におけるヒープベースのバッファオーバーフローの脆弱性 - CVE-2006-4128 2012-12-20 18:02 2006-08-11 Show GitHub Exploit DB Packet Storm
230283 7.5 危険 simple one-file guestbook - Simple one-file guestbook における認証を回避される脆弱性 - CVE-2006-4122 2012-12-20 18:02 2006-08-14 Show GitHub Exploit DB Packet Storm
230284 5.1 警告 see-commerce - See-Commerce の owimg.php3 における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-4121 2012-12-20 18:02 2006-08-14 Show GitHub Exploit DB Packet Storm
230285 5.4 警告 サン・マイクロシステムズ - Sun Solaris の squeue_drain 関数におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2006-4117 2012-12-20 18:02 2006-08-14 Show GitHub Exploit DB Packet Storm
230286 7.5 危険 phpmyring - Nicolas Grandjean PHPMyRing の view_com.php における SQL インジェクションの脆弱性 - CVE-2006-4114 2012-12-20 18:02 2006-08-14 Show GitHub Exploit DB Packet Storm
230287 7.5 危険 Ruby on Rails project - Ruby on Rails の "依存型分類メカニズム" における任意の Ruby コードを実行される脆弱性 CWE-noinfo
情報不足
CVE-2006-4112 2012-12-20 18:02 2006-08-10 Show GitHub Exploit DB Packet Storm
230288 7.5 危険 Ruby on Rails project - Ruby on Rails における "重大" または "深刻" な影響を引き起こす Ruby コードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2006-4111 2012-12-20 18:02 2006-08-9 Show GitHub Exploit DB Packet Storm
230289 3.6 注意 simpliciti - Simpliciti Locked Browser における許可されていない操作を実行される脆弱性 - CVE-2006-4092 2012-12-20 18:02 2006-08-11 Show GitHub Exploit DB Packet Storm
230290 4.3 警告 webligo - Webligo BlogHoster におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-4090 2012-12-20 18:02 2006-08-11 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 7, 2026, 4:22 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
212541 3.5 LOW
Network
vertiv avocent_umg-4000_firmware The web interface of the Vertiv Avocent UMG-4000 version 4.2.1.19 is vulnerable to stored XSS. A remote attacker authenticated with an administrator account could store a maliciously named file withi… CWE-79
Cross-site Scripting
CVE-2019-9508 2024-11-21 13:51 2020-03-31 Show GitHub Exploit DB Packet Storm
212542 7.2 HIGH
Network
vertiv avocent_umg-4000_firmware The web interface of the Vertiv Avocent UMG-4000 version 4.2.1.19 is vulnerable to command injection because the application incorrectly neutralizes code syntax before executing. Since all commands w… CWE-77
Command Injection
CVE-2019-9507 2024-11-21 13:51 2020-03-31 Show GitHub Exploit DB Packet Storm
212543 7.5 HIGH
Network
google android In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction i… CWE-125
Out-of-bounds Read
CVE-2019-9474 2024-11-21 13:51 2020-03-16 Show GitHub Exploit DB Packet Storm
212544 7.5 HIGH
Network
google android In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction i… CWE-125
Out-of-bounds Read
CVE-2019-9473 2024-11-21 13:51 2020-03-16 Show GitHub Exploit DB Packet Storm
212545 8.8 HIGH
Adjacent
synology
broadcom
router_manager
bcm4339_firmware
The Broadcom wl WiFi driver is vulnerable to a heap buffer overflow. If the vendor information element data length is larger than 164 bytes, a heap buffer overflow is triggered in wlc_wpa_plumb_gtk. … CWE-787
 Out-of-bounds Write
CVE-2019-9502 2024-11-21 13:51 2020-02-4 Show GitHub Exploit DB Packet Storm
212546 8.8 HIGH
Adjacent
synology
broadcom
router_manager
bcm4339_firmware
The Broadcom wl WiFi driver is vulnerable to a heap buffer overflow. By supplying a vendor information element with a data length larger than 32 bytes, a heap buffer overflow is triggered in wlc_wpa_… CWE-787
 Out-of-bounds Write
CVE-2019-9501 2024-11-21 13:51 2020-02-4 Show GitHub Exploit DB Packet Storm
212547 8.3 HIGH
Adjacent
broadcom
redhat
brcmfmac_driver
enterprise_linux
The Broadcom brcmfmac WiFi driver prior to commit a4176ec356c73a46c07c181c6d04039fafa34a9f is vulnerable to a frame validation bypass. If the brcmfmac driver receives a firmware event frame from a re… CWE-20
 Improper Input Validation 
CVE-2019-9503 2024-11-21 13:51 2020-01-17 Show GitHub Exploit DB Packet Storm
212548 8.3 HIGH
Adjacent
broadcom
linux
brcmfmac_driver
linux_kernel
The Broadcom brcmfmac WiFi driver prior to commit 1b5e2423164b3670e8bc9174e4762d297990deff is vulnerable to a heap buffer overflow. If the Wake-up on Wireless LAN functionality is configured, a malic… CWE-787
 Out-of-bounds Write
CVE-2019-9500 2024-11-21 13:51 2020-01-17 Show GitHub Exploit DB Packet Storm
212549 7.8 HIGH
Local
microsoft windows_10
windows_server_2019
A vulnerability in Microsoft Windows 10 1803 and Windows Server 2019 and later systems can allow authenticated RDP-connected clients to gain access to user sessions without needing to interact with t… CWE-755
 Improper Handling of Exceptional Conditions
CVE-2019-9510 2024-11-21 13:51 2020-01-16 Show GitHub Exploit DB Packet Storm
212550 9.8 CRITICAL
Network
mycarcontrols mycar_controls The MyCar Controls of AutoMobility Distribution Inc., mobile application contains hard-coded admin credentials. A remote unauthenticated attacker may be able to send commands to and retrieve data fro… CWE-798
 Use of Hard-coded Credentials
CVE-2019-9493 2024-11-21 13:51 2020-01-16 Show GitHub Exploit DB Packet Storm