Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 1, 2026, 12:10 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
254011 6.8 警告 アップル
サイバートラスト株式会社
サン・マイクロシステムズ
ターボリナックス
ヒューレット・パッカード
OpenSSL Project
レッドハット
- OpenSSL の SSL_get_shared_ciphers() 関数における一つずれエラーの脆弱性 CWE-189
数値処理の問題
CVE-2007-5135 2010-01-5 13:31 2007-10-12 Show GitHub Exploit DB Packet Storm
254012 7.8 危険 マイクロソフト - Microsoft Windows で稼働している Active Directory の LDAP サービスにおけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2009-1928 2010-01-4 15:24 2009-11-10 Show GitHub Exploit DB Packet Storm
254013 9.3 危険 マイクロソフト - Microsoft Windows の kernel における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2009-2514 2010-01-4 15:24 2009-11-10 Show GitHub Exploit DB Packet Storm
254014 6.8 警告 マイクロソフト - Microsoft Windows の kernel の Graphics Device Interface (GDI) における権限を取得される脆弱性 CWE-20
不適切な入力確認
CVE-2009-2513 2010-01-4 15:24 2009-11-10 Show GitHub Exploit DB Packet Storm
254015 6.8 警告 マイクロソフト - Microsoft Windows の kernel における権限を取得される脆弱性 CWE-20
不適切な入力確認
CVE-2009-1127 2010-01-4 15:24 2009-11-10 Show GitHub Exploit DB Packet Storm
254016 10 危険 マイクロソフト - Microsoft Windows の License Logging Server (llssrv.exe) における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2009-2523 2010-01-4 15:24 2009-11-10 Show GitHub Exploit DB Packet Storm
254017 9.3 危険 マイクロソフト - Microsoft Windows の Web Services on Devices API (WSDAPI) における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2009-2512 2010-01-4 15:23 2009-11-10 Show GitHub Exploit DB Packet Storm
254018 10 危険 アップル
VMware
サン・マイクロシステムズ
- Sun Java SE の Provider クラスにおける詳細不明な脆弱性 CWE-noinfo
情報不足
CVE-2009-2722 2010-01-4 14:56 2009-08-10 Show GitHub Exploit DB Packet Storm
254019 10 危険 アップル
VMware
サン・マイクロシステムズ
- Sun Java SE の Provider クラスにおける詳細不明な脆弱性 CWE-noinfo
情報不足
CVE-2009-2723 2010-01-4 14:55 2009-08-10 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 1, 2026, 4:54 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
223311 8.1 HIGH
Network
ttlock ttlock TTLock devices do not properly restrict password-reset attempts, leading to incorrect access control and disclosure of sensitive information about valid account names. CWE-640
 Weak Password Recovery Mechanism for Forgotten Password
CVE-2019-12943 2024-11-21 13:23 2019-09-11 Show GitHub Exploit DB Packet Storm
223312 6.5 MEDIUM
Adjacent
ttlock ttlock TTLock devices do not properly block guest access in certain situations where the network connection to the cloud is unavailable. CWE-862
 Missing Authorization
CVE-2019-12942 2024-11-21 13:23 2019-09-11 Show GitHub Exploit DB Packet Storm
223313 5.3 MEDIUM
Network
mendix mendix In Mendix 7.23.5 and earlier, issue in XML import mappings allow DOCTYPE declarations in the XML input that is potentially unsafe. CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2019-12996 2024-11-21 13:23 2019-09-11 Show GitHub Exploit DB Packet Storm
223314 7.8 HIGH
Local
cisco jabber A vulnerability in Cisco Jabber Client Framework (JCF) for Mac Software, installed as part of the Cisco Jabber for Mac client, could allow an authenticated, local attacker to execute arbitrary code o… CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2019-12645 2024-11-21 13:23 2019-09-5 Show GitHub Exploit DB Packet Storm
223315 6.1 MEDIUM
Network
cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack a… CWE-79
Cross-site Scripting
CVE-2019-12644 2024-11-21 13:23 2019-09-5 Show GitHub Exploit DB Packet Storm
223316 4.3 MEDIUM
Network
cisco content_security_management_appliance A vulnerability in the authorization module of Cisco Content Security Management Appliance (SMA) Software could allow an authenticated, remote attacker to gain out-of-scope access to email. The vulne… CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2019-12635 2024-11-21 13:23 2019-09-5 Show GitHub Exploit DB Packet Storm
223317 7.5 HIGH
Network
cisco unified_contact_center_express A vulnerability in Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to bypass access controls and conduct a server-side request forgery (SSRF) attack… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2019-12633 2024-11-21 13:23 2019-09-5 Show GitHub Exploit DB Packet Storm
223318 7.5 HIGH
Network
cisco finesse A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to bypass access controls and conduct a server-side request forgery (SSRF) attack on an affected system. The vulnerabi… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2019-12632 2024-11-21 13:23 2019-09-5 Show GitHub Exploit DB Packet Storm
223319 6.5 MEDIUM
Adjacent
espressif esp-idf
arduino-esp32
esp8266_nonos_sdk
The EAP peer implementation in Espressif ESP-IDF 2.0.0 through 4.0.0 and ESP8266_NONOS_SDK 2.2.0 through 3.1.0 processes EAP Success messages before any EAP method completion or failure, which allows… NVD-CWE-noinfo
CVE-2019-12586 2024-11-21 13:23 2019-09-5 Show GitHub Exploit DB Packet Storm
223320 6.5 MEDIUM
Adjacent
espressif esp8266_nonos_sdk
arduino_esp8266
The client 802.11 mac implementation in Espressif ESP8266_NONOS_SDK 2.2.0 through 3.1.0 does not validate correctly the RSN AuthKey suite list count in beacon frames, probe responses, and association… CWE-20
 Improper Input Validation 
CVE-2019-12588 2024-11-21 13:23 2019-09-4 Show GitHub Exploit DB Packet Storm