Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 12, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
255181 6.9 警告 acpid - acpid の umask におけるサービス運用妨害 (DoS) の脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2009-4235 2010-01-21 11:44 2009-12-7 Show GitHub Exploit DB Packet Storm
255182 6.9 警告 サイバートラスト株式会社
レッドハット
acpid
- acpid のレッドハットパッチにおける権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2009-4033 2010-01-21 11:43 2009-12-7 Show GitHub Exploit DB Packet Storm
255183 10 危険 アドビシステムズ - Adobe Illustrator における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2009-3952 2010-01-21 11:43 2010-01-7 Show GitHub Exploit DB Packet Storm
255184 9.3 危険 アドビシステムズ - Adobe Illustrator における Encapsulated PostScript ファイルの処理に関する任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2009-4195 2010-01-21 11:43 2009-12-4 Show GitHub Exploit DB Packet Storm
255185 4.4 警告 サイバートラスト株式会社
Linux
レッドハット
- Linux Kernel の exit_notify 関数における任意のシグナルをプロセスに送信可能な脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2009-1337 2010-01-21 11:23 2009-04-22 Show GitHub Exploit DB Packet Storm
255186 4.9 警告 サイバートラスト株式会社
Linux
レッドハット
- Linux Kernel における sendmsg 関数の呼び出しに関するサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2008-5300 2010-01-21 11:22 2008-12-1 Show GitHub Exploit DB Packet Storm
255187 6.8 警告 シスコシステムズ - 複数の SSL VPN (Web VPN) 製品においてウェブブラウザのセキュリティが迂回される問題 CWE-264
認可・権限・アクセス制御
CVE-2009-2631 2010-01-20 14:15 2009-12-1 Show GitHub Exploit DB Packet Storm
255188 4.4 警告 DAG
レッドハット
- dstat における Python module の検索パスに関する権限昇格の脆弱性 CWE-Other
その他
CVE-2009-3894 2010-01-20 14:15 2009-11-29 Show GitHub Exploit DB Packet Storm
255189 6.4 警告 OSIsoft - PI Server の OSIsoft PI System におけるデータベースの情報を変更される脆弱性 CWE-310
暗号の問題
CVE-2009-0209 2010-01-20 14:14 2009-10-1 Show GitHub Exploit DB Packet Storm
255190 9.3 危険 サン・マイクロシステムズ
freedesktop.org
レッドハット
サイバートラスト株式会社
Glyph & Cog, LLC
- Xpdf および Poppler の PSOutputDev::doImageL1Sep 関数における整数オーバーフローの脆弱性 CWE-189
数値処理の問題
CVE-2009-3606 2010-01-20 11:57 2009-10-15 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 12, 2026, 5:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
210641 7.2 HIGH
Network
apache syncope In Apache Syncope 2.1.X releases prior to 2.1.7, when the Flowable extension is enabled, an administrator with workflow entitlements can use Shell Service Tasks to perform malicious operations, inclu… NVD-CWE-noinfo
CVE-2020-11977 2024-11-21 13:59 2020-09-16 Show GitHub Exploit DB Packet Storm
210642 7.5 HIGH
Network
apache cocoon When using the StreamGenerator, the code parse a user-provided XML. A specially crafted XML, including external system entities, could be used to access any file on the server system. CWE-611
XXE
CVE-2020-11991 2024-11-21 13:59 2020-09-11 Show GitHub Exploit DB Packet Storm
210643 9.8 CRITICAL
Network
apache
oracle
activemq
flexcube_private_banking
enterprise_repository
communications_diameter_signaling_router
communications_element_manager
communications_session_route_manager
communications_s…
A regression has been introduced in the commit preventing JMX re-bind. By passing an empty environment map to RMIConnectorServer, instead of the map that contains the authentication credentials, it l… NVD-CWE-noinfo
CVE-2020-11998 2024-11-21 13:59 2020-09-11 Show GitHub Exploit DB Packet Storm
210644 9.8 CRITICAL
Network
apache netbeans To be able to analyze gradle projects, the build scripts need to be executed. Apache NetBeans follows this pattern. This causes the code of the build script to be invoked at load time of the project.… NVD-CWE-noinfo
CVE-2020-11986 2024-11-21 13:59 2020-09-10 Show GitHub Exploit DB Packet Storm
210645 8.8 HIGH
Network
foxitsoftware phantompdf
reader
In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can execute arbitrary code via a heap-based buffer overflow because dirty image-resource data is mishandled. CWE-787
 Out-of-bounds Write
CVE-2020-12248 2024-11-21 13:59 2020-09-4 Show GitHub Exploit DB Packet Storm
210646 7.1 HIGH
Local
foxitsoftware phantompdf
reader
In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can obtain sensitive information from an out-of-bounds read because a text-string index continues to be used after… CWE-125
Out-of-bounds Read
CVE-2020-12247 2024-11-21 13:59 2020-09-4 Show GitHub Exploit DB Packet Storm
210647 6.1 MEDIUM
Network
oscommerce ce_phoenix Several XSS vulnerabilities in osCommerce CE Phoenix before 1.0.6.0 allow an attacker to inject and execute arbitrary JavaScript code. The malicious code can be injected as follows: the page paramete… CWE-79
Cross-site Scripting
CVE-2020-12058 2024-11-21 13:59 2020-09-3 Show GitHub Exploit DB Packet Storm
210648 6.1 MEDIUM
Physics
teamwire teamwire The Teamwire application 5.3.0 for Android allows physically proximate attackers to exploit a flaw related to the pass-code component. CWE-306
Missing Authentication for Critical Function
CVE-2020-12621 2024-11-21 13:59 2020-09-3 Show GitHub Exploit DB Packet Storm
210649 5.4 MEDIUM
Network
open-xchange open-xchange_appsuite OX App Suite 7.10.3 and earlier allows XSS via text/x-javascript, text/rdf, or a PDF document. CWE-79
Cross-site Scripting
CVE-2020-12646 2024-11-21 13:59 2020-09-1 Show GitHub Exploit DB Packet Storm
210650 9.8 CRITICAL
Network
open-xchange open-xchange_appsuite OX App Suite 7.10.1 to 7.10.3 has improper input validation for rate limits with a crafted User-Agent header, spoofed vacation notices, and /apps/load memory consumption. CWE-307
mproper Restriction of Excessive Authentication Attempts
CVE-2020-12645 2024-11-21 13:59 2020-09-1 Show GitHub Exploit DB Packet Storm