Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 26, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
253371 4.3 警告 マイクロソフト - 複数の Microsoft SharePoint 製品におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-1893 2011-10-20 16:20 2011-09-13 Show GitHub Exploit DB Packet Storm
253372 9.3 危険 マイクロソフト - Microsoft Office 2003 および 2007 における権限昇格の脆弱性 CWE-Other
その他
CVE-2011-1980 2011-10-20 16:19 2011-09-13 Show GitHub Exploit DB Packet Storm
253373 9.3 危険 マイクロソフト - Microsoft Office 2007 および 2010 における任意のコードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2011-1982 2011-10-20 16:19 2011-09-13 Show GitHub Exploit DB Packet Storm
253374 7.2 危険 マイクロソフト - Windows Server 2003 および 2008 の WINS における権限昇格の脆弱性性 CWE-264
認可・権限・アクセス制御
CVE-2011-1984 2011-10-20 16:19 2011-09-13 Show GitHub Exploit DB Packet Storm
253375 9.3 危険 マイクロソフト - Microsoft Excel 2003 における任意のコードを実行される脆弱性 CWE-399
リソース管理の問題
CVE-2011-1986 2011-10-20 16:18 2011-09-13 Show GitHub Exploit DB Packet Storm
253376 9.3 危険 マイクロソフト - 複数の Microsoft Excel 製品における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2011-1987 2011-10-20 16:18 2011-09-13 Show GitHub Exploit DB Packet Storm
253377 9.3 危険 マイクロソフト - 複数の Microsoft Excel 製品における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2011-1988 2011-10-20 16:18 2011-09-13 Show GitHub Exploit DB Packet Storm
253378 9.3 危険 マイクロソフト - 複数の Microsoft Excel 製品における任意のコードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2011-1989 2011-10-20 16:17 2011-09-13 Show GitHub Exploit DB Packet Storm
253379 9.3 危険 マイクロソフト - 複数の Microsoft Excel 製品における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2011-1990 2011-10-20 16:17 2011-09-13 Show GitHub Exploit DB Packet Storm
253380 9.3 危険 マイクロソフト - Microsoft Windows における権限昇格の脆弱性 CWE-Other
その他
CVE-2011-1991 2011-10-20 16:17 2011-09-13 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 26, 2026, 4:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
225121 9.8 CRITICAL
Network
nsa ghidra NSA Ghidra through 9.0.4, when experimental mode is enabled, allows arbitrary code execution if the Read XML Files feature of Bit Patterns Explorer is used with a modified XML document. This occurs i… CWE-91
Blind XPath Injection
CVE-2019-16941 2024-11-21 13:31 2019-09-29 Show GitHub Exploit DB Packet Storm
225122 5.5 MEDIUM
Local
glyphandcog xpdf Xpdf 4.01.01 has an out-of-bounds write in the vertProfile part of the TextPage::findGaps function in TextOutputDev.cc, a different vulnerability than CVE-2019-9877. CWE-787
 Out-of-bounds Write
CVE-2019-16927 2024-11-21 13:31 2019-09-28 Show GitHub Exploit DB Packet Storm
225123 8.8 HIGH
Adjacent
nuvending nulock The Nulock application 1.5.0 for mobile devices sends a cleartext password over Bluetooth, which allows remote attackers (after sniffing the network) to take control of the lock. CWE-319
Cleartext Transmission of Sensitive Information
CVE-2019-16924 2024-11-21 13:31 2019-09-28 Show GitHub Exploit DB Packet Storm
225124 6.1 MEDIUM
Network
kkcms_project kkcms kkcms 1.3 has jx.php?url= XSS. CWE-79
Cross-site Scripting
CVE-2019-16923 2024-11-21 13:31 2019-09-28 Show GitHub Exploit DB Packet Storm
225125 5.3 MEDIUM
Network
salesagility suitecrm SuiteCRM 7.10.x before 7.10.20 and 7.11.x before 7.11.8 allows unintended public exposure of files. NVD-CWE-noinfo
CVE-2019-16922 2024-11-21 13:31 2019-09-28 Show GitHub Exploit DB Packet Storm
225126 7.5 HIGH
Network
linux linux_kernel In the Linux kernel before 4.17, hns_roce_alloc_ucontext in drivers/infiniband/hw/hns/hns_roce_main.c does not initialize the resp data structure, which might allow attackers to obtain sensitive info… CWE-665
 Improper Initialization
CVE-2019-16921 2024-11-21 13:31 2019-09-27 Show GitHub Exploit DB Packet Storm
225127 7.5 HIGH
Network
reputeinfosystems arforms In the ARforms plugin 3.7.1 for WordPress, arf_delete_file in arformcontroller.php allows unauthenticated deletion of an arbitrary file by supplying the full pathname. CWE-22
Path Traversal
CVE-2019-16902 2024-11-21 13:31 2019-09-27 Show GitHub Exploit DB Packet Storm
225128 9.8 CRITICAL
Network
dlink dir-655_firmware
dir-866l_firmware
dir-652_firmware
dhp-1565_firmware
dir-855l_firmware
dap-1533_firmware
dir-862l_firmware
dir-615_firmware
dir-835_firmware
dir-825_firmwa…
Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a "PingTest" device c… CWE-78
OS Command 
CVE-2019-16920 2024-11-21 13:31 2019-09-27 Show GitHub Exploit DB Packet Storm
225129 9.8 CRITICAL
Network
netgate pfsense An issue was discovered in pfSense through 2.4.4-p3. widgets/widgets/picture.widget.php uses the widgetkey parameter directly without sanitization (e.g., a basename call) for a pathname to file_get_c… CWE-22
Path Traversal
CVE-2019-16915 2024-11-21 13:31 2019-09-27 Show GitHub Exploit DB Packet Storm
225130 6.1 MEDIUM
Network
netgate pfsense An XSS issue was discovered in pfSense through 2.4.4-p3. In services_captiveportal_mac.php, the username and delmac parameters are displayed without sanitization. CWE-79
Cross-site Scripting
CVE-2019-16914 2024-11-21 13:31 2019-09-27 Show GitHub Exploit DB Packet Storm