Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 8, 2026, 12:07 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
257621 6.8 警告 Haxx
アップル
サイバートラスト株式会社
レッドハット
- curl および libcurl の redirect 実装における任意のコマンドを実行される脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2009-0037 2010-04-13 14:45 2009-03-3 Show GitHub Exploit DB Packet Storm
257622 9.3 危険 ジャストシステム - 一太郎シリーズにおける任意のコードが実行される脆弱性 CWE-noinfo
情報不足
CVE-2010-1424 2010-04-12 15:32 2010-04-12 Show GitHub Exploit DB Packet Storm
257623 4.4 警告 ヒューレット・パッカード - HP HP-UX におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2010-1030 2010-04-12 12:19 2010-03-26 Show GitHub Exploit DB Packet Storm
257624 10 危険 IntelliCom Innovation AB - IntelliCom NetBiter Config HICP におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-4462 2010-04-12 12:19 2010-03-29 Show GitHub Exploit DB Packet Storm
257625 7.5 危険 The PHP Group - PHP の セッション拡張子における open_basedir または safe_mode 制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2010-1130 2010-04-12 12:19 2010-03-26 Show GitHub Exploit DB Packet Storm
257626 4.3 警告 Zope Foundation - Zope におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-1104 2010-04-9 16:21 2010-03-25 Show GitHub Exploit DB Packet Storm
257627 4 警告 ヒューレット・パッカード - HP HP-UX の NFS/ONCplus にあるインストールプロセスにおけるファイルシステムのアクセス権を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2010-0451 2010-04-9 16:21 2010-03-25 Show GitHub Exploit DB Packet Storm
257628 7.5 危険 GNU Project
サイバートラスト株式会社
レッドハット
- GnuTLS の gnutls_x509_crt_get_serial 関数におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2010-0731 2010-04-9 16:21 2010-03-25 Show GitHub Exploit DB Packet Storm
257629 4.3 警告 シスコシステムズ - Cisco Router and Security Device Manager におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-0594 2010-04-8 15:03 2010-04-8 Show GitHub Exploit DB Packet Storm
257630 4.3 警告 MODX - MODx におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-1427 2010-04-8 15:02 2010-04-8 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 8, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
194631 9.8 CRITICAL
Network
cdr_project cdr An issue was discovered in Deserializer::read_vec in the cdr crate before 0.2.4 for Rust. A user-provided Read implementation can gain access to the old contents of newly allocated heap memory, viola… CWE-908
 Use of Uninitialized Resource
CVE-2021-26305 2024-11-21 14:56 2021-01-29 Show GitHub Exploit DB Packet Storm
194632 5.4 MEDIUM
Network
phpgurukul daily_expense_tracker_system PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to stored XSS via the add-expense.php Item parameter. CWE-79
Cross-site Scripting
CVE-2021-26304 2024-11-21 14:56 2021-01-29 Show GitHub Exploit DB Packet Storm
194633 6.1 MEDIUM
Network
phpgurukul daily_expense_tracker_system PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to stored XSS via the user-profile.php Full Name field. CWE-79
Cross-site Scripting
CVE-2021-26303 2024-11-21 14:56 2021-01-29 Show GitHub Exploit DB Packet Storm
194634 5.3 MEDIUM
Network
godaddy node-config-shield scripts/cli.js in the GoDaddy node-config-shield (aka Config Shield) package before 0.2.2 for Node.js calls eval when processing a set command. NOTE: the vendor reportedly states that this is not a v… CWE-913
 Improper Control of Dynamically-Managed Code Resources
CVE-2021-26276 2024-11-21 14:56 2021-01-28 Show GitHub Exploit DB Packet Storm
194635 6.5 MEDIUM
Network
ckeditor
oracle
ckeditor
webcenter_sites
agile_plm
commerce_merchandising
jd_edwards_enterpriseone_tools
financial_services_model_management_and_governance
financial_services_analytical_application…
It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plug… CWE-829
 Inclusion of Functionality from Untrusted Control Sphere
CVE-2021-26272 2024-11-21 14:56 2021-01-27 Show GitHub Exploit DB Packet Storm
194636 6.5 MEDIUM
Network
ckeditor
oracle
ckeditor
webcenter_sites
agile_plm
jd_edwards_enterpriseone_tools
financial_services_analytical_applications_infrastructure
siebel_ui_framework
application_express
It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs pl… CWE-829
 Inclusion of Functionality from Untrusted Control Sphere
CVE-2021-26271 2024-11-21 14:56 2021-01-27 Show GitHub Exploit DB Packet Storm
194637 7.5 HIGH
Network
cpanel cpanel cPanel before 92.0.9 allows a MySQL user (who has an old-style password hash) to bypass suspension (SEC-579). NVD-CWE-noinfo
CVE-2021-26267 2024-11-21 14:56 2021-01-27 Show GitHub Exploit DB Packet Storm
194638 7.5 HIGH
Network
cpanel cpanel cPanel before 92.0.9 allows a Reseller to bypass the suspension lock (SEC-578). NVD-CWE-Other
CVE-2021-26266 2024-11-21 14:56 2021-01-27 Show GitHub Exploit DB Packet Storm
194639 6.5 MEDIUM
Network
intel openvino Improper input validation in the Intel(R) Distribution of OpenVINO(TM) Toolkit may allow an authenticated user to potentially enable denial of service via network access. CWE-20
 Improper Input Validation 
CVE-2021-26251 2024-11-21 14:55 2022-11-12 Show GitHub Exploit DB Packet Storm
194640 6.3 MEDIUM
Network
kubernetes kubernetes Kube-proxy on Windows can unintentionally forward traffic to local processes listening on the same port (“spec.ports[*].port”) as a LoadBalancer Service when the LoadBalancer controller does not … NVD-CWE-noinfo
CVE-2021-25736 2024-11-21 14:55 2023-10-30 Show GitHub Exploit DB Packet Storm