Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 18, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
255791 10 危険 マイクロソフト - Microsoft Windows の SMB クライアントにおける任意のコードを実行される脆弱性 CWE-399
リソース管理の問題
CVE-2010-0269 2010-05-10 19:09 2010-04-13 Show GitHub Exploit DB Packet Storm
255792 9.3 危険 マイクロソフト - Microsoft Windows の Cabinet File Viewer Shell Extension における任意のコードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2010-0487 2010-05-10 19:09 2010-04-13 Show GitHub Exploit DB Packet Storm
255793 9.3 危険 マイクロソフト - Microsoft Windows の Authenticode Signature Verification における任意のコードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2010-0486 2010-05-10 19:09 2010-04-13 Show GitHub Exploit DB Packet Storm
255794 4.7 警告 サイバートラスト株式会社
Linux
レッドハット
- x86_64 および amd64 プラットフォーム上 Linux Kernel におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2009-4271 2010-05-10 18:25 2010-03-16 Show GitHub Exploit DB Packet Storm
255795 5 警告 VMware - VMware Authorization Service の VMware Authentication Daemon におけるサービス運用妨害 (DoS) の脆弱性 CWE-134
書式文字列の問題
CVE-2009-3707 2010-05-7 17:26 2009-10-16 Show GitHub Exploit DB Packet Storm
255796 9.3 危険 VMware - VMnc メディアコーデックおよびムービーデコーダにおける任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2009-1565 2010-05-7 17:26 2010-04-9 Show GitHub Exploit DB Packet Storm
255797 9.3 危険 VMware - VMnc メディアコーデックおよびムービーデコーダにおけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-1564 2010-05-7 17:25 2010-04-9 Show GitHub Exploit DB Packet Storm
255798 10 危険 VMware - VMware Remote Console の vmware-vmrc.exe build 158248 における任意のコードを実行される脆弱性 CWE-134
書式文字列の問題
CVE-2009-3732 2010-05-7 17:25 2010-04-9 Show GitHub Exploit DB Packet Storm
255799 7.2 危険 VMware - 複数の VMware 製品の vmrun における権限昇格の脆弱性 CWE-134
書式文字列の問題
CVE-2010-1139 2010-05-7 17:25 2010-04-9 Show GitHub Exploit DB Packet Storm
255800 5 警告 VMware - 複数の VMware 製品の仮想ネットワークスタックにおける重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2010-1138 2010-05-7 17:25 2010-04-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 19, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
225211 5.4 MEDIUM
Network
sentrifugo sentrifugo Multiple stored XSS vulnerabilities in Sentrifugo 3.2 could allow authenticated users to inject arbitrary web script or HTML. CWE-79
Cross-site Scripting
CVE-2019-15814 2024-11-21 13:29 2019-09-4 Show GitHub Exploit DB Packet Storm
225212 8.8 HIGH
Network
sentrifugo sentrifugo Multiple file upload restriction bypass vulnerabilities in Sentrifugo 3.2 could allow authenticated users to execute arbitrary code via a webshell. CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2019-15813 2024-11-21 13:29 2019-09-4 Show GitHub Exploit DB Packet Storm
225213 4.4 MEDIUM
Local
systemd_project
fedoraproject
redhat
systemd
fedora
enterprise_linux
openshift_container_platform
enterprise_linux_eus
enterprise_linux_server_tus
enterprise_linux_server_aus
enterprise_linux_server_update_services_…
In systemd 240, bus_open_system_watch_bind_with_description in shared/bus-util.c (as used by systemd-resolved to connect to the system D-Bus instance), calls sd_bus_set_trusted, which disables access… NVD-CWE-noinfo
CVE-2019-15718 2024-11-21 13:29 2019-09-4 Show GitHub Exploit DB Packet Storm
225214 7.5 HIGH
Network
libexpat_project
python
libexpat
python
In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML_GetCurrentLineNumber (or XML_GetCurrentColumn… CWE-125
CWE-776
Out-of-bounds Read
XML Entity Expansion
CVE-2019-15903 2024-11-21 13:29 2019-09-4 Show GitHub Exploit DB Packet Storm
225215 5.6 MEDIUM
Local
linux
debian
opensuse
netapp
linux_kernel
debian_linux
leap
active_iq_performance_analytics_services
service_processor
baseboard_management_controller_firmware
A backporting error was discovered in the Linux stable/longterm kernel 4.4.x through 4.4.190, 4.9.x through 4.9.190, 4.14.x through 4.14.141, 4.19.x through 4.19.69, and 5.2.x through 5.2.11. Misuse … CWE-200
Information Exposure
CVE-2019-15902 2024-11-21 13:29 2019-09-4 Show GitHub Exploit DB Packet Storm
225216 6.1 MEDIUM
Network
nagios log_server Nagios Log Server before 2.0.8 allows Reflected XSS via the username on the Login page. CWE-79
Cross-site Scripting
CVE-2019-15898 2024-11-21 13:29 2019-09-4 Show GitHub Exploit DB Packet Storm
225217 7.5 HIGH
Network
varnish_cache_project
varnish-software
debian
varnish_cache
debian_linux
An issue was discovered in Varnish Cache before 6.0.4 LTS, and 6.1.x and 6.2.x before 6.2.1. An HTTP/1 parsing failure allows a remote attacker to trigger an assert by sending crafted HTTP/1 requests… CWE-617
 Reachable Assertion
CVE-2019-15892 2024-11-21 13:29 2019-09-4 Show GitHub Exploit DB Packet Storm
225218 6.1 MEDIUM
Network
wpdownloadmanager wordpress_download_manager The download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by the orderby or search[publish_date] parameter. CWE-79
Cross-site Scripting
CVE-2019-15889 2024-11-21 13:29 2019-09-4 Show GitHub Exploit DB Packet Storm
225219 8.8 HIGH
Network
metagauss profilegrid The profilegrid-user-profiles-groups-and-communities plugin before 2.8.6 for WordPress has remote code execution via an wp-admin/admin-ajax.php request with the action=pm_template_preview&html=<?php … CWE-94
Code Injection
CVE-2019-15873 2024-11-21 13:29 2019-09-3 Show GitHub Exploit DB Packet Storm
225220 9.8 CRITICAL
Network
wpbrigade loginpress The LoginPress plugin before 1.1.4 for WordPress has SQL injection via an import of settings. CWE-89
SQL Injection
CVE-2019-15872 2024-11-21 13:29 2019-09-3 Show GitHub Exploit DB Packet Storm