Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 18, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
251571 4.3 警告 The Tor Project - Tor におけるブリッジを列挙される脆弱性 CWE-200
情報漏えい
CVE-2011-2769 2011-12-27 11:01 2011-10-27 Show GitHub Exploit DB Packet Storm
251572 5.8 警告 The Tor Project - Tor における匿名化のためのプロパティを無効にされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2011-2768 2011-12-27 10:54 2011-10-27 Show GitHub Exploit DB Packet Storm
251573 7.5 危険 PmWiki - PmWiki の PageListSort 関数における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2011-4453 2011-12-27 10:46 2011-11-11 Show GitHub Exploit DB Packet Storm
251574 - - The Support Incident Tracker Project - Support Incident Tracker に複数の脆弱性 - CVE-2011-3831
CVE-2011-3833
CVE-2011-5067
CVE-2011-5068
CVE-2011-5069
CVE-2011-5070
2011-12-27 09:42 2011-12-5 Show GitHub Exploit DB Packet Storm
251575 9.3 危険 Sielco Sistemi - Sielco Sistemi Winlog PRO および Winlog Lite におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2011-4037 2011-12-26 16:32 2011-12-22 Show GitHub Exploit DB Packet Storm
251576 5 警告 Moodle - Moodle の calendar/set.php における CRLF インジェクションの脆弱性 CWE-94
コード・インジェクション
CVE-2011-4203 2011-12-26 16:32 2011-12-22 Show GitHub Exploit DB Packet Storm
251577 4.3 警告 The phpMyAdmin Project - phpMyAdmin におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-4634 2011-12-26 16:31 2011-12-1 Show GitHub Exploit DB Packet Storm
251578 4.3 警告 The phpMyAdmin Project - phpMyAdmin の libraries/display_export.lib.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-4780 2011-12-26 16:30 2011-12-21 Show GitHub Exploit DB Packet Storm
251579 4.3 警告 The phpMyAdmin Project - phpMyAdmin の libraries/config/ConfigFile.class.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-4782 2011-12-26 16:29 2011-12-21 Show GitHub Exploit DB Packet Storm
251580 6.5 警告 WordPress.org - WordPress において任意の PHP コードが実行可能な脆弱性 CWE-94
コード・インジェクション
- 2011-12-26 14:27 2011-12-26 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 18, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
223231 5.4 MEDIUM
Adjacent
qualcomm atheros_ar9132_firmware
atheros_ar9283_firmware
atheros_ar9285_firmware
A partial authentication bypass vulnerability exists on Atheros AR9132 3.60(AMX.8), AR9283 1.85, and AR9285 1.0.0.12NA devices. The vulnerability allows sending an unencrypted data frame to a WPA2-pr… CWE-290
 Authentication Bypass by Spoofing
CVE-2019-18991 2024-11-21 13:33 2020-10-1 Show GitHub Exploit DB Packet Storm
223232 5.4 MEDIUM
Adjacent
realtek rtl8812ar_firmware
rtl8196d_firmware
rtl8192er_firmware
rtl8881an_firmware
A partial authentication bypass vulnerability exists on Realtek RTL8812AR 1.21WW, RTL8196D 1.0.0, RTL8192ER 2.10, and RTL8881AN 1.09 devices. The vulnerability allows sending an unencrypted data fram… CWE-290
 Authentication Bypass by Spoofing
CVE-2019-18990 2024-11-21 13:33 2020-10-1 Show GitHub Exploit DB Packet Storm
223233 5.4 MEDIUM
Adjacent
mediatek mt7620n_firmware A partial authentication bypass vulnerability exists on Mediatek MT7620N 1.06 devices. The vulnerability allows sending an unencrypted data frame to a WPA2-protected WLAN router where the packet is r… CWE-290
 Authentication Bypass by Spoofing
CVE-2019-18989 2024-11-21 13:33 2020-10-1 Show GitHub Exploit DB Packet Storm
223234 9.8 CRITICAL
Network
akamai enterprise_application_access Enterprise Access Client Auto-Updater allows for Remote Code Execution prior to version 2.0.1. CWE-295
Improper Certificate Validation 
CVE-2019-18847 2024-11-21 13:33 2020-08-26 Show GitHub Exploit DB Packet Storm
223235 6.1 MEDIUM
Network
woocommerce subscriptions Persistent XSS in the WooCommerce Subscriptions plugin before 2.6.3 for WordPress allows remote attackers to execute arbitrary JavaScript because Billing Details are mishandled in WCS_Admin_Post_Type… CWE-79
Cross-site Scripting
CVE-2019-18834 2024-11-21 13:33 2020-07-24 Show GitHub Exploit DB Packet Storm
223236 7.8 HIGH
Local
synaptics
lenovo
hp
vfs75xx_firmware
thinkpad_25_firmware
thankpad_a475_firmware
thankpad_a485_firmware
thinkpad_e480_firmware
thinkpad_e580_firmware
thinkpad_e485_firmware
thinkpad_e585_firmware
Incorrect parameter validation in the synaTee component of Synaptics WBF drivers using an SGX enclave (all versions prior to 2019-11-15) allows a local user to execute arbitrary code in the enclave (… CWE-763
 Release of Invalid Pointer or Reference
CVE-2019-18619 2024-11-21 13:33 2020-07-22 Show GitHub Exploit DB Packet Storm
223237 6.0 MEDIUM
Local
synaptics
lenovo
hp
vfs75xx_firmware
thinkpad_25_firmware
thankpad_a475_firmware
thankpad_a485_firmware
thinkpad_e480_firmware
thinkpad_e580_firmware
thinkpad_e485_firmware
thinkpad_e585_firmware
Incorrect access control in the firmware of Synaptics VFS75xx family fingerprint sensors that include external flash (all versions prior to 2019-11-15) allows a local administrator or physical attack… NVD-CWE-noinfo
CVE-2019-18618 2024-11-21 13:33 2020-07-22 Show GitHub Exploit DB Packet Storm
223238 7.8 HIGH
Local
cypress cyw20735_firmware On the Cypress CYW20735 evaluation board, any data that exceeds 384 bytes is copied and causes an overflow. This is because the maximum BLOC buffer size for sending and receiving data is set to 384 b… CWE-787
 Out-of-bounds Write
CVE-2019-18614 2024-11-21 13:33 2020-06-16 Show GitHub Exploit DB Packet Storm
223239 9.8 CRITICAL
Network
dlink dap-1360_revision_f_firmware An issue was discovered on D-Link DAP-1360 revision F devices. Remote attackers can start a telnet service without authorization via an undocumented HTTP request. Although this is the primary vulnera… CWE-306
Missing Authentication for Critical Function
CVE-2019-18666 2024-11-21 13:33 2020-05-16 Show GitHub Exploit DB Packet Storm
223240 7.5 HIGH
Network
blaauwproducts remote_kiln_control Weak password requirements in Blaauw Remote Kiln Control through v3.00r4 allow a user to set short or guessable passwords (e.g., 1 or 1234). CWE-521
Weak Password Requirements 
CVE-2019-18872 2024-11-21 13:33 2020-05-7 Show GitHub Exploit DB Packet Storm