Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 19, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
231041 7.5 危険 Virtue Netz - Virtuenetz Virtue Online Test Generator の text.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-2392 2012-12-20 19:10 2009-07-9 Show GitHub Exploit DB Packet Storm
231042 4.3 警告 Virtue Netz - Virtuenetz Virtue Online Test Generator の text.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-2391 2012-12-20 19:10 2009-07-9 Show GitHub Exploit DB Packet Storm
231043 6.8 警告 usolved - USOLVED NEWSolved の newsscript.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-2389 2012-12-20 19:10 2009-07-9 Show GitHub Exploit DB Packet Storm
231044 6.8 警告 shalwan - Opial の admin/index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-2388 2012-12-20 19:10 2009-07-9 Show GitHub Exploit DB Packet Storm
231045 4.9 警告 サン・マイクロシステムズ - Sun OpenSolaris の proc filesystem におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2009-2387 2012-12-20 19:10 2009-07-5 Show GitHub Exploit DB Packet Storm
231046 4.3 警告 tangocms - TangoCMS の application/libraries/Html.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-2376 2012-12-20 19:10 2009-07-8 Show GitHub Exploit DB Packet Storm
231047 6.8 警告 wxwidgets - wxWidgets の src/common/image.cpp における整数オーバーフローの脆弱性 CWE-189
数値処理の問題
CVE-2009-2369 2012-12-20 19:10 2009-07-8 Show GitHub Exploit DB Packet Storm
231048 9.3 危険 yukudr - KUDRSOFT AudioPLUS におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-2363 2012-12-20 19:10 2009-07-8 Show GitHub Exploit DB Packet Storm
231049 9.3 危険 yukudr - KUDRSOFT AudioPLUS におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-2362 2012-12-20 19:10 2009-07-8 Show GitHub Exploit DB Packet Storm
231050 7.5 危険 yasinkaplan - TekRADIUS における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-2359 2012-12-20 19:10 2009-07-7 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 20, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
196231 6.5 MEDIUM
Network
apache druid In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSource allows authenticated users to read data from other sources than inten… CWE-610
Externally Controlled Reference to a Resource in Another Sphere
CVE-2021-26920 2024-11-21 14:57 2021-07-2 Show GitHub Exploit DB Packet Storm
196232 7.8 HIGH
Local
autodesk advance_steel
autocad
autocad_architecture
civil_3d
autocad_electrical
autocad_lt
autocad_map_3d
autocad_mechanical
autocad_mep
autocad_plant_3d
dwg_trueview
An Arbitrary Address Write issue in the Autodesk DWG application can allow a malicious user to leverage the application to write in unexpected paths. In order to exploit this the attacker would need … CWE-787
 Out-of-bounds Write
CVE-2021-27043 2024-11-21 14:57 2021-06-25 Show GitHub Exploit DB Packet Storm
196233 7.8 HIGH
Local
autodesk advance_steel
autocad
autocad_architecture
civil_3d
autocad_electrical
autocad_lt
autocad_map_3d
autocad_mechanical
autocad_mep
autocad_plant_3d
A maliciously crafted DWG file can be used to write beyond the allocated buffer while parsing DWG files. The vulnerability exists because the application fails to handle a crafted DWG file, which cau… CWE-755
 Improper Handling of Exceptional Conditions
CVE-2021-27042 2024-11-21 14:57 2021-06-25 Show GitHub Exploit DB Packet Storm
196234 7.8 HIGH
Local
autodesk
iconics
mitsubishielectric
design_review
advance_steel
autocad
autocad_architecture
civil_3d
autocad_electrical
autocad_lt
autocad_map_3d
autocad_mechanical
autocad_mep
autocad_plant_3d
genesis…
A maliciously crafted DWG file can be used to write beyond the allocated buffer while parsing DWG files. This vulnerability can be exploited to execute arbitrary code CWE-787
 Out-of-bounds Write
CVE-2021-27041 2024-11-21 14:57 2021-06-25 Show GitHub Exploit DB Packet Storm
196235 3.3 LOW
Local
autodesk
iconics
mitsubishielectric
advance_steel
autocad
autocad_architecture
civil_3d
autocad_electrical
autocad_lt
autocad_map_3d
autocad_mechanical
autocad_mep
autocad_plant_3d
dwg_trueview
genesis6…
A maliciously crafted DWG file can be forced to read beyond allocated boundaries when parsing the DWG file. This vulnerability can be exploited to execute arbitrary code. CWE-125
Out-of-bounds Read
CVE-2021-27040 2024-11-21 14:57 2021-06-25 Show GitHub Exploit DB Packet Storm
196236 9.8 CRITICAL
Network
siemens sinamics_sl150_firmware
sinamics_sm150_firmware
sinamics_sm150i_firmware
SINAMICS medium voltage routable products are affected by a vulnerability in the Sm@rtServer component for remote access that could allow an unauthenticated attacker to cause a denial-of-service cond… - CVE-2021-27388 2024-11-21 14:57 2021-06-16 Show GitHub Exploit DB Packet Storm
196237 7.5 HIGH
Network
hitachienergy relion_670_firmware
relion_650_firmware
relion_sam600-io_firmware
rtu500_firmware
reb500_firmware
fox615_tego1_firmware
modular_switchgear_monitoring_firmware
gms600_firmware
Improper Input Validation vulnerability in Hitachi ABB Power Grids Relion 670 Series, Relion 670/650 Series, Relion 670/650/SAM600-IO, Relion 650, REB500, RTU500 Series, FOX615 (TEGO1), MSM, GMS600, … CWE-20
 Improper Input Validation 
CVE-2021-27196 2024-11-21 14:57 2021-06-15 Show GitHub Exploit DB Packet Storm
196238 9.8 CRITICAL
Network
wowonder wowonder In WoWonder 3.0.4, remote attackers can take over any account due to the weak cryptographic algorithm in recover.php. The code parameter is easily predicted from the time of day. CWE-330
 Use of Insufficiently Random Values
CVE-2021-27200 2024-11-21 14:57 2021-06-12 Show GitHub Exploit DB Packet Storm
196239 9.8 CRITICAL
Network
hillrom spot_vital_signs_4400
connex_central_station
connex_device_integration_suite_network_connectivity_engine
connex_integrated_wall_system
connex_spot_monitor
connex_vital_signs_monitor
The affected product is vulnerable to an out-of-bounds write, which may result in corruption of data or code execution on the Welch Allyn medical device management tools (Welch Allyn Service Tool: ve… - CVE-2021-27410 2024-11-21 14:57 2021-06-12 Show GitHub Exploit DB Packet Storm
196240 7.5 HIGH
Network
hillrom spot_vital_signs_4400
connex_central_station
connex_device_integration_suite_network_connectivity_engine
connex_integrated_wall_system
connex_spot_monitor
connex_vital_signs_monitor
The affected product is vulnerable to an out-of-bounds read, which can cause information leakage leading to arbitrary code execution if chained to the out-of-bounds write vulnerability on the Welch A… - CVE-2021-27408 2024-11-21 14:57 2021-06-12 Show GitHub Exploit DB Packet Storm