Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 25, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
254131 10 危険 シスコシステムズ - Cisco Wireless LAN Controller における設定を変更される脆弱性 CWE-noinfo
情報不足
CVE-2009-1167 2011-06-10 09:53 2009-07-27 Show GitHub Exploit DB Packet Storm
254132 7.8 危険 シスコシステムズ - Cisco Wireless LAN Controller の管理用 Web インターフェースにおけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2009-1166 2011-06-10 09:53 2009-07-27 Show GitHub Exploit DB Packet Storm
254133 6.8 警告 Redback
Apache Software Foundation
- Apache Archiva および Apache Continuum におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2010-3449 2011-06-10 09:53 2010-11-24 Show GitHub Exploit DB Packet Storm
254134 5 警告 JSecurity
Apache Software Foundation
- Apache Shiro および JSecurity におけるアクセス制限を回避される脆弱性 CWE-22
パス・トラバーサル
CVE-2010-3863 2011-06-10 09:52 2010-11-5 Show GitHub Exploit DB Packet Storm
254135 4.3 警告 Apache Software Foundation - Apache CouchDB の Web 管理インターフェースにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-3854 2011-06-10 09:52 2011-01-28 Show GitHub Exploit DB Packet Storm
254136 4.3 警告 The Dojo Foundation
Apache Software Foundation
- Apache Struts などで利用される Dojo におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-6726 2011-06-10 09:51 2009-04-9 Show GitHub Exploit DB Packet Storm
254137 4.3 警告 Apache Software Foundation - Apache Struts の LookupDispatchAction、DispatchAction および ActionDispatcher におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-1548 2011-06-10 09:50 2006-03-30 Show GitHub Exploit DB Packet Storm
254138 7.8 危険 Apache Software Foundation - Apache Struts (with BeanUtils) の ActionForm におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2006-1547 2011-06-10 09:50 2006-03-30 Show GitHub Exploit DB Packet Storm
254139 4.3 警告 Apache Software Foundation
レッドハット
- Apache Struts におけるクロスサイトスクリプティングの脆弱性 - CVE-2005-3745 2011-06-10 09:49 2005-11-22 Show GitHub Exploit DB Packet Storm
254140 4.6 警告 Linux
レッドハット
- Linux kernel の bond_select_queue 関数におけるサービス運用妨害 (DoS)の脆弱性 CWE-20
不適切な入力確認
CVE-2011-1581 2011-06-9 10:31 2011-05-18 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 25, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
225351 9.8 CRITICAL
Network
codesys eni_server
codesys
CODESYS V2.3 ENI server up to V3.2.2.24 has a Buffer Overflow. CWE-787
 Out-of-bounds Write
CVE-2019-16265 2024-11-21 13:30 2019-10-26 Show GitHub Exploit DB Packet Storm
225352 8.8 HIGH
Network
open-emr openemr Authenticated SQL Injection in interface/forms/eye_mag/js/eye_base.php in OpenEMR through 5.0.2 allows a user to extract arbitrary data from the openemr database via a non-parameterized INSERT INTO s… CWE-89
SQL Injection
CVE-2019-16404 2024-11-21 13:30 2019-10-22 Show GitHub Exploit DB Packet Storm
225353 7.2 HIGH
Network
sonatype nexus_repository_manager
nexus_iq_server
Sonatype Nexus Repository Manager 2.x before 2.14.15 and 3.x before 3.19, and IQ Server before 72, has remote code execution. CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2019-16530 2024-11-21 13:30 2019-10-21 Show GitHub Exploit DB Packet Storm
225354 5.4 MEDIUM
Network
nchsoftware express_accounts_accounting In NCH Express Accounts Accounting v7.02, persistent cross site scripting (XSS) exists in Invoices/Sales Orders/Items/Customers/Quotes input field. An authenticated unprivileged user can add/modify t… CWE-79
Cross-site Scripting
CVE-2019-16330 2024-11-21 13:30 2019-10-18 Show GitHub Exploit DB Packet Storm
225355 7.3 HIGH
Network
url_redirect_project url_redirect The url_redirect (aka URL redirect) extension through 1.2.1 for TYPO3 fails to properly sanitize user input and is susceptible to SQL Injection. CWE-89
SQL Injection
CVE-2019-16682 2024-11-21 13:30 2019-10-17 Show GitHub Exploit DB Packet Storm
225356 5.4 MEDIUM
Network
pixelite events_manager The events-manager plugin through 5.9.5 for WordPress (aka Events Manager) is susceptible to Stored XSS due to improper encoding and insertion of data provided to the attribute map_style of shortcode… CWE-79
Cross-site Scripting
CVE-2019-16523 2024-11-21 13:30 2019-10-17 Show GitHub Exploit DB Packet Storm
225357 4.8 MEDIUM
Network
eu_cookie_law_project eu_cookie_law The eu-cookie-law plugin through 3.0.6 for WordPress (aka EU Cookie Law (GDPR)) is susceptible to Stored XSS due to improper encoding of several configuration options in the admin area and the displa… CWE-79
Cross-site Scripting
CVE-2019-16522 2024-11-21 13:30 2019-10-17 Show GitHub Exploit DB Packet Storm
225358 6.1 MEDIUM
Network
managewp broken_link_checker The broken-link-checker plugin through 1.11.8 for WordPress (aka Broken Link Checker) is susceptible to Reflected XSS due to improper encoding and insertion of an HTTP GET parameter into HTML. The fi… CWE-79
Cross-site Scripting
CVE-2019-16521 2024-11-21 13:30 2019-10-17 Show GitHub Exploit DB Packet Storm
225359 5.4 MEDIUM
Network
semperplugins all_in_one_seo_pack The all-in-one-seo-pack plugin before 3.2.7 for WordPress (aka All in One SEO Pack) is susceptible to Stored XSS due to improper encoding of the SEO-specific description for posts provided by the plu… CWE-79
Cross-site Scripting
CVE-2019-16520 2024-11-21 13:30 2019-10-16 Show GitHub Exploit DB Packet Storm
225360 5.4 MEDIUM
Network
nchsoftware express_invoice In NCH Express Invoice v7.12, persistent cross site scripting (XSS) exists via the Invoices/Items/Customers/Quotes input field. An authenticated unprivileged user can add/modify the Invoices/Items/Cu… CWE-79
Cross-site Scripting
CVE-2019-16282 2024-11-21 13:30 2019-10-15 Show GitHub Exploit DB Packet Storm