Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 22, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
231231 6.8 警告 sweetphp - TotalCalendar の cms_detect.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2009-1406 2012-12-20 19:10 2009-04-24 Show GitHub Exploit DB Packet Storm
231232 10 危険 forkosh - mathTex の mathtex.cgi における任意のコマンドを実行される脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2009-1383 2012-12-20 19:10 2009-07-14 Show GitHub Exploit DB Packet Storm
231233 4.3 警告 レッドハット - Red Hat JBoss Enterprise Application Platform の JBossAs におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-1380 2012-12-20 19:10 2009-12-9 Show GitHub Exploit DB Packet Storm
231234 9.3 危険 xilisoft - Xilisoft Video Converter の ape_plugin.plg におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-1370 2012-12-20 19:10 2009-04-22 Show GitHub Exploit DB Packet Storm
231235 4.9 警告 サン・マイクロシステムズ - Sun OpenSolaris の SCTP におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2009-1359 2012-12-20 19:10 2009-04-19 Show GitHub Exploit DB Packet Storm
231236 6.8 警告 サン・マイクロシステムズ - Sun Java System Delegated Administrator の da/DA/Login における CRLF インジェクションの脆弱性 CWE-20
不適切な入力確認
CVE-2009-1357 2012-12-20 19:10 2009-04-21 Show GitHub Exploit DB Packet Storm
231237 4 警告 sergey lyubka - Mongoose におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2009-1354 2012-12-20 19:10 2009-04-21 Show GitHub Exploit DB Packet Storm
231238 5 警告 sebastian fernandez - Zervit Webserver の libz/misc.c におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-1353 2012-12-20 19:10 2009-04-21 Show GitHub Exploit DB Packet Storm
231239 4.3 警告 レッドハット - C2Net Stronghold におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-1349 2012-12-20 19:10 2009-04-21 Show GitHub Exploit DB Packet Storm
231240 6 警告 TWiki - TWiki におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2009-1339 2012-12-20 19:10 2009-04-5 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 22, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
196601 5.5 MEDIUM
Local
amd romepi_firmware A randomly generated Initialization Vector (IV) may lead to a collision of IVs with the same key potentially resulting in information disclosure. CWE-330
 Use of Insufficiently Random Values
CVE-2021-26407 2024-11-21 14:56 2023-01-11 Show GitHub Exploit DB Packet Storm
196602 6.5 MEDIUM
Local
amd epyc_7001_firmware
epyc_7251_firmware
epyc_7261_firmware
epyc_7281_firmware
epyc_7301_firmware
epyc_7351_firmware
epyc_7351p_firmware
epyc_7371_firmware
epyc_7401_firmware
Insufficient checks in SEV may lead to a malicious hypervisor disclosing the launch secret potentially resulting in compromise of VM confidentiality. NVD-CWE-noinfo
CVE-2021-26403 2024-11-21 14:56 2023-01-11 Show GitHub Exploit DB Packet Storm
196603 7.1 HIGH
Local
amd epyc_7h12_firmware
epyc_7f72_firmware
epyc_7f52_firmware
epyc_7f32_firmware
epyc_7742_firmware
epyc_7702p_firmware
epyc_7702_firmware
epyc_7662_firmware
epyc_7642_firmware
Insufficient bounds checking in ASP (AMD Secure Processor) firmware while handling BIOS mailbox commands, may allow an attacker to write partially-controlled data out-of-bounds to SMM or SEV-ES regio… CWE-787
 Out-of-bounds Write
CVE-2021-26402 2024-11-21 14:56 2023-01-11 Show GitHub Exploit DB Packet Storm
196604 7.8 HIGH
Local
amd epyc_7h12_firmware
epyc_7f72_firmware
epyc_7f52_firmware
epyc_7f32_firmware
epyc_7742_firmware
epyc_7702p_firmware
epyc_7702_firmware
epyc_7662_firmware
epyc_7642_firmware
Insufficient input validation in SYS_KEY_DERIVE system call in a compromised user application or ABL may allow an attacker to corrupt ASP (AMD Secure Processor) OS memory which may lead to potential … CWE-787
 Out-of-bounds Write
CVE-2021-26398 2024-11-21 14:56 2023-01-11 Show GitHub Exploit DB Packet Storm
196605 4.4 MEDIUM
Local
amd epyc_7003_firmware
epyc_72f3_firmware
epyc_7313_firmware
epyc_7313p_firmware
epyc_7343_firmware
epyc_7373x_firmware
epyc_73f3_firmware
epyc_7413_firmware
epyc_7443_firmware
Insufficient validation of address mapping to IO in ASP (AMD Secure Processor) may result in a loss of memory integrity in the SNP guest. CWE-345
 Insufficient Verification of Data Authenticity
CVE-2021-26396 2024-11-21 14:56 2023-01-11 Show GitHub Exploit DB Packet Storm
196606 5.5 MEDIUM
Local
amd epyc_7003_firmware
epyc_72f3_firmware
epyc_7313_firmware
epyc_7313p_firmware
epyc_7343_firmware
epyc_7373x_firmware
epyc_73f3_firmware
epyc_7413_firmware
epyc_7443_firmware
Insufficient fencing and checks in System Management Unit (SMU) may result in access to invalid message port registers that could result in a potential denial-of-service. NVD-CWE-noinfo
CVE-2021-26355 2024-11-21 14:56 2023-01-11 Show GitHub Exploit DB Packet Storm
196607 5.5 MEDIUM
Local
amd ryzen_3_3100_firmware
ryzen_3_3200g_firmware
ryzen_3_3200u_firmware
ryzen_3_3250c_firmware
ryzen_3_3250u_firmware
ryzen_3_3300g_firmware
ryzen_3_3300u_firmware
ryzen_3_3300x_firm…
Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an integer overflow in the L2 directory table in SPI flash resulting in a potential… CWE-190
 Integer Overflow or Wraparound
CVE-2021-26346 2024-11-21 14:56 2023-01-11 Show GitHub Exploit DB Packet Storm
196608 5.5 MEDIUM
Local
amd epyc_7003_firmware
epyc_72f3_firmware
epyc_7313_firmware
epyc_7313p_firmware
epyc_7343_firmware
epyc_7373x_firmware
epyc_73f3_firmware
epyc_7413_firmware
epyc_7443_firmware
Insufficient validation in ASP BIOS and DRTM commands may allow malicious supervisor x86 software to disclose the contents of sensitive memory which may result in information disclosure. CWE-668
 Exposure of Resource to Wrong Sphere
CVE-2021-26343 2024-11-21 14:56 2023-01-11 Show GitHub Exploit DB Packet Storm
196609 4.4 MEDIUM
Local
amd epyc_7003_firmware
epyc_72f3_firmware
epyc_7313_firmware
epyc_7313p_firmware
epyc_7343_firmware
epyc_7373x_firmware
epyc_73f3_firmware
epyc_7413_firmware
epyc_7443_firmware
Failure to verify the mode of CPU execution at the time of SNP_INIT may lead to a potential loss of memory integrity for SNP guests. NVD-CWE-noinfo
CVE-2021-26328 2024-11-21 14:56 2023-01-11 Show GitHub Exploit DB Packet Storm
196610 7.8 HIGH
Local
amd epyc_7h12_firmware
epyc_7f72_firmware
epyc_7f52_firmware
epyc_7f32_firmware
epyc_7742_firmware
epyc_7702p_firmware
epyc_7702_firmware
epyc_7662_firmware
epyc_7642_firmware
Failure to validate the communication buffer and communication service in the BIOS may allow an attacker to tamper with the buffer resulting in potential SMM (System Management Mode) arbitrary code e… CWE-20
 Improper Input Validation 
CVE-2021-26316 2024-11-21 14:56 2023-01-11 Show GitHub Exploit DB Packet Storm