Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 12, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
252371 4 警告 シックス・アパート株式会社 - Movable Type におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-4634 2011-05-31 10:35 2008-10-17 Show GitHub Exploit DB Packet Storm
252372 5 警告 アドビシステムズ - Adobe Flash Media Server におけるサービス運用妨害 (XML データ破損) の脆弱性 CWE-399
リソース管理の問題
CVE-2011-0612 2011-05-27 11:19 2011-05-12 Show GitHub Exploit DB Packet Storm
252373 9.3 危険 アドビシステムズ - Windows 上で稼働する Adobe Audition におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2011-0615 2011-05-27 10:50 2011-05-12 Show GitHub Exploit DB Packet Storm
252374 9.3 危険 アドビシステムズ - Windows 上で稼働する Adobe Audition におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2011-0614 2011-05-27 10:49 2011-05-12 Show GitHub Exploit DB Packet Storm
252375 5 警告 レッドハット
Avahi
オラクル
- Avahi の avahi-core/socket.c におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2011-1002 2011-05-27 10:33 2011-02-22 Show GitHub Exploit DB Packet Storm
252376 5 警告 Squid-cache.org
レッドハット
- Squid の string-comparison 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2010-3072 2011-05-27 10:05 2010-09-3 Show GitHub Exploit DB Packet Storm
252377 6 警告 Walrus,Digit. - WalRack におけるアップロードファイルの取扱いに関する脆弱性 CWE-20
不適切な入力確認
CVE-2011-1329 2011-05-26 11:06 2011-05-26 Show GitHub Exploit DB Packet Storm
252378 6.9 警告 Linux
レッドハット
- Linux kernel の Radeon GPU ドライバにおける任意のメモリロケーションへ書き込みされる脆弱性 CWE-20
不適切な入力確認
CVE-2011-1016 2011-05-26 10:45 2011-02-28 Show GitHub Exploit DB Packet Storm
252379 6.9 警告 Linux
レッドハット
- Linux kernel の drm_modeset_ctl 関数における整数符号エラーの脆弱性 CWE-189
数値処理の問題
CVE-2011-1013 2011-05-26 10:43 2011-05-9 Show GitHub Exploit DB Packet Storm
252380 6.2 警告 Linux
レッドハット
- Linux kernel の caiaq Native Instruments USB オーディオ機能におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2011-0712 2011-05-26 10:21 2011-02-18 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 13, 2026, 5:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
222371 9.0 CRITICAL
Network
fudforum fudforum FUDForum 3.0.9 is vulnerable to Stored XSS via the User-Agent HTTP header. This may result in remote code execution. An attacker can use a user account to fully compromise the system via a GET reques… CWE-79
CWE-78
Cross-site Scripting
OS Command 
CVE-2019-18873 2024-11-21 13:33 2019-11-12 Show GitHub Exploit DB Packet Storm
222372 6.5 MEDIUM
Network
imagemagick imagemagick ImageMagick before 7.0.9-0 allows remote attackers to cause a denial of service because XML_PARSE_HUGE is not properly restricted in coders/svg.c, related to SVG and libxml2. CWE-674
 Uncontrolled Recursion
CVE-2019-18853 2024-11-21 13:33 2019-11-12 Show GitHub Exploit DB Packet Storm
222373 9.8 CRITICAL
Network
dlink dir-600_b1_firmware
dir-615_j1_firmware
dir-645_a1_firmware
dir-815_a1_firmware
dir-823_a1_firmware
dir-842_c1_firmware
dir-890l_a1_firmware
Certain D-Link devices have a hardcoded Alphanetworks user account with TELNET access because of /etc/config/image_sign or /etc/alpha_config/image_sign. This affects DIR-600 B1 V2.01 for WW, DIR-890L… CWE-319
Cleartext Transmission of Sensitive Information
CVE-2019-18852 2024-11-21 13:33 2019-11-11 Show GitHub Exploit DB Packet Storm
222374 5.5 MEDIUM
Local
tnef_project
fedoraproject
canonical
debian
tnef
fedora
ubuntu_linux
debian_linux
In tnef before 1.4.18, an attacker may be able to write to the victim's .ssh/authorized_keys file via an e-mail message with a crafted winmail.dat application/ms-tnef attachment, because of a heap-ba… CWE-125
Out-of-bounds Read
CVE-2019-18849 2024-11-21 13:33 2019-11-11 Show GitHub Exploit DB Packet Storm
222375 7.3 HIGH
Network
chartkick chartkick.js Chartkick.js 3.1.0 through 3.1.3, as used in the Chartkick gem before 3.3.0 for Ruby, allows prototype pollution. NVD-CWE-noinfo
CVE-2019-18841 2024-11-21 13:33 2019-11-11 Show GitHub Exploit DB Packet Storm
222376 7.5 HIGH
Network
envoyproxy
istio
envoy
istio
Envoy 1.12.0 allows a remote denial of service because of resource loops, as demonstrated by a single idle TCP connection being able to keep a worker thread in an infinite busy loop when continue_on_… CWE-835
 Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2019-18836 2024-11-21 13:33 2019-11-11 Show GitHub Exploit DB Packet Storm
222377 7.1 HIGH
Local
patriotmemory viper_rgb_firmware The MsIo64.sys and MsIo32.sys drivers in Patriot Viper RGB before 1.1 allow local users (including low integrity processes) to read and write to arbitrary memory locations, and consequently gain NT A… CWE-269
 Improper Privilege Management
CVE-2019-18845 2024-11-21 13:33 2019-11-10 Show GitHub Exploit DB Packet Storm
222378 7.5 HIGH
Network
wolfssl wolfssl In wolfSSL 4.1.0 through 4.2.0c, there are missing sanity checks of memory accesses in parsing ASN.1 certificate data while handshaking. Specifically, there is a one-byte heap-based buffer overflow i… CWE-787
 Out-of-bounds Write
CVE-2019-18840 2024-11-21 13:33 2019-11-9 Show GitHub Exploit DB Packet Storm
222379 9.8 CRITICAL
Network
energycap energycap Escalation of privileges in EnergyCAP 7 through 7.5.6 allows an attacker to access data. If an unauthenticated user clicks on a link on the public dashboard, the resource opens in EnergyCAP with acce… CWE-269
 Improper Privilege Management
CVE-2019-18623 2024-11-21 13:33 2019-11-9 Show GitHub Exploit DB Packet Storm
222380 9.8 CRITICAL
Network
matrix synapse Matrix Synapse before 1.5.0 mishandles signature checking on some federation APIs. Events sent over /send_join, /send_leave, and /invite may not be correctly signed, or may not come from the expected… CWE-345
 Insufficient Verification of Data Authenticity
CVE-2019-18835 2024-11-21 13:33 2019-11-8 Show GitHub Exploit DB Packet Storm