Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 22, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
251911 4.3 警告 Alexander Palmo - Simple PHP Blog におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-5029 2012-01-5 11:07 2011-12-29 Show GitHub Exploit DB Packet Storm
251912 4 警告 Novell - Novell Sentinel Log Manager におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2011-5028 2012-01-5 10:49 2011-12-29 Show GitHub Exploit DB Packet Storm
251913 4.3 警告 Zabbix - Zabbix におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-5027 2012-01-5 10:49 2011-08-4 Show GitHub Exploit DB Packet Storm
251914 4.3 警告 Zabbix - Zabbix における複数のクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-4615 2012-01-5 10:48 2011-08-4 Show GitHub Exploit DB Packet Storm
251915 10 危険 ヒューレット・パッカード - HP Database Archiving Software における任意のコードを実行される脆弱性 CWE-noinfo
情報不足
CVE-2011-4165 2012-01-5 10:47 2011-12-22 Show GitHub Exploit DB Packet Storm
251916 10 危険 ヒューレット・パッカード - HP Database Archiving Software における任意のコードを実行される脆弱性 CWE-noinfo
情報不足
CVE-2011-4164 2012-01-5 10:46 2011-12-22 Show GitHub Exploit DB Packet Storm
251917 10 危険 ヒューレット・パッカード - HP Database Archiving Software における任意のコードを実行される脆弱性 CWE-noinfo
情報不足
CVE-2011-4163 2012-01-5 10:44 2011-12-22 Show GitHub Exploit DB Packet Storm
251918 4.3 警告 Yaws - Yaws の wiki アプリケーションにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-5025 2012-01-5 10:21 2011-12-29 Show GitHub Exploit DB Packet Storm
251919 4.3 警告 GNU Project - Mailman 用の Mailman/htdig integration patch の mmsearch/design におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-5024 2012-01-5 10:21 2011-12-29 Show GitHub Exploit DB Packet Storm
251920 4.3 警告 Pligg - Pligg CMS の search.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-5023 2012-01-5 10:17 2011-12-29 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 22, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
224341 9.0 CRITICAL
Network
eclipse memory_analyzer Eclipse Memory Analyzer version 1.9.1 and earlier is subject to a cross site scripting (XSS) vulnerability when generating an HTML report from a malicious heap dump. The user must chose todownload, o… CWE-79
Cross-site Scripting
CVE-2019-17634 2024-11-21 13:32 2020-01-18 Show GitHub Exploit DB Packet Storm
224342 9.8 CRITICAL
Network
saltstack
debian
opensuse
canonical
salt
debian_linux
leap
ubuntu_linux
In SaltStack Salt through 2019.2.0, the salt-api NET API with the ssh client enabled is vulnerable to command injection. This allows an unauthenticated attacker with network access to the API endpoin… CWE-77
Command Injection
CVE-2019-17361 2024-11-21 13:32 2020-01-17 Show GitHub Exploit DB Packet Storm
224343 6.1 MEDIUM
Network
apache
oracle
cxf
flexcube_private_banking
retail_order_broker
communications_element_manager
communications_session_report_manager
communications_session_route_manager
commerce_guided_search
By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack, which … CWE-79
Cross-site Scripting
CVE-2019-17573 2024-11-21 13:32 2020-01-17 Show GitHub Exploit DB Packet Storm
224344 5.3 MEDIUM
Network
linux
debian
netapp
linux_kernel
debian_linux
a700s_firmware
8300_firmware
8700_firmware
a400_firmware
h610s_firmware
cloud_backup
steelstore_cloud_integrated_storage
data_availability_service…
The flow_dissector feature in the Linux kernel 4.3 through 5.x before 5.3.10 has a device tracking vulnerability, aka CID-55667441c84f. This occurs because the auto flowlabel of a UDP IPv6 packet rel… CWE-330
 Use of Insufficiently Random Values
CVE-2019-18282 2024-11-21 13:32 2020-01-17 Show GitHub Exploit DB Packet Storm
224345 6.5 MEDIUM
Network
osisoft pi_vision OSIsoft PI Vision, All versions of PI Vision prior to 2019. The affected product is vulnerable to an improper access control, which may return unauthorized tag data when viewing analysis data referen… NVD-CWE-Other
CVE-2019-18275 2024-11-21 13:32 2020-01-16 Show GitHub Exploit DB Packet Storm
224346 4.8 MEDIUM
Network
osisoft pi_vision OSIsoft PI Vision, PI Vision 2017 R2 and PI Vision 2017 R2 SP1. The affected product is vulnerable to cross-site scripting, which may allow invalid input to be introduced. CWE-79
Cross-site Scripting
CVE-2019-18273 2024-11-21 13:32 2020-01-16 Show GitHub Exploit DB Packet Storm
224347 8.8 HIGH
Network
osisoft pi_vision OSIsoft PI Vision, All versions of PI Vision prior to 2019. The affected product is vulnerable to a cross-site request forgery that may be introduced on the PI Vision administration site. CWE-352
 Origin Validation Error
CVE-2019-18271 2024-11-21 13:32 2020-01-16 Show GitHub Exploit DB Packet Storm
224348 4.7 MEDIUM
Local
osisoft pi_vision In OSIsoft PI System multiple products and versions, a local attacker could view sensitive information in log files when service accounts are customized during installation or upgrade of PI Vision. T… CWE-532
 Inclusion of Sensitive Information in Log Files
CVE-2019-18244 2024-11-21 13:32 2020-01-16 Show GitHub Exploit DB Packet Storm
224349 7.8 HIGH
Local
totalav totalav_2020 TotalAV 2020 4.14.31 has a quarantine flaw that allows privilege escalation. Exploitation uses an NTFS directory junction to restore a malicious DLL from quarantine into the system32 folder. NVD-CWE-noinfo
CVE-2019-18194 2024-11-21 13:32 2020-01-11 Show GitHub Exploit DB Packet Storm
224350 4.3 MEDIUM
Network
otrs
debian
opensuse
otrs
debian_linux
leap
backports_sle
An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.12, and Community Edition 5.0.x through 5.0.38 and 6.0.x through 6.0.23. An attacker who is logged into OTRS as an agent… NVD-CWE-noinfo
CVE-2019-18179 2024-11-21 13:32 2020-01-7 Show GitHub Exploit DB Packet Storm