Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 9, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
258541 9.3 危険 マイクロソフト - Microsoft Internet Explorer に脆弱性 CWE-94
コード・インジェクション
CVE-2009-3672 2010-01-14 12:08 2009-11-25 Show GitHub Exploit DB Packet Storm
258542 9.3 危険 サン・マイクロシステムズ
VMware
- Sun Java SE の java.lang パッケージにおける脆弱性 CWE-362
競合状態
CVE-2009-2724 2010-01-14 12:08 2009-08-10 Show GitHub Exploit DB Packet Storm
258543 10 危険 サン・マイクロシステムズ
VMware
- Sun Java SE の Provider クラスにおける脆弱性 CWE-noinfo
情報不足
CVE-2009-2721 2010-01-14 12:08 2009-08-10 Show GitHub Exploit DB Packet Storm
258544 5 警告 有限会社シースリー - WebCalenderC3 におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2010-0348 2010-01-12 15:01 2010-01-12 Show GitHub Exploit DB Packet Storm
258545 4.3 警告 有限会社シースリー - WebCalenderC3 におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-0349 2010-01-12 15:00 2010-01-12 Show GitHub Exploit DB Packet Storm
258546 10 危険 サイバートラスト株式会社
XEmacs
- XEmacs の glyphs-eimage.c における整数オーバーフローの脆弱性 CWE-189
数値処理の問題
CVE-2009-2688 2010-01-12 14:48 2009-08-5 Show GitHub Exploit DB Packet Storm
258547 6.8 警告 IBM - IBM WebSphere Application Server (WAS) におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2009-2746 2010-01-12 14:48 2009-11-13 Show GitHub Exploit DB Packet Storm
258548 5 警告 アップル - Apple Safari におけるローカル HTML ファイルを読まれる脆弱性 CWE-Other
その他
CVE-2009-2842 2010-01-7 12:09 2009-11-11 Show GitHub Exploit DB Packet Storm
258549 5.5 警告 シックス・アパート株式会社 - Movable Type におけるアクセス制限回避の脆弱性 CWE-264
認可・権限・アクセス制御
- 2010-01-6 15:01 2010-01-6 Show GitHub Exploit DB Packet Storm
258550 9.3 危険 マイクロソフト - Microsoft Office Word および Open XML File Format Converter における、任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2009-3135 2010-01-6 14:44 2009-11-10 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 10, 2026, 5 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
199281 6.1 MEDIUM
Network
adobe experience_manager
experience_manager_cloud_service
AEM's Cloud Service offering, as well as versions 6.5.7.0 (and below), 6.4.8.3 (and below) and 6.3.3.8 (and below) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abus… - CVE-2021-21084 2024-11-21 14:47 2021-06-28 Show GitHub Exploit DB Packet Storm
199282 7.5 HIGH
Network
adobe experience_manager
experience_manager_cloud_service
AEM's Cloud Service offering, as well as versions 6.5.7.0 (and below), 6.4.8.3 (and below) and 6.3.3.8 (and below) are affected by an Improper Access Control vulnerability. An unauthenticated attacke… NVD-CWE-Other
CVE-2021-21083 2024-11-21 14:47 2021-06-28 Show GitHub Exploit DB Packet Storm
199283 6.1 MEDIUM
Network
ec-cube ec-cube Cross-site scripting vulnerability in EC-CUBE EC-CUBE 4.0.0 to 4.0.5-p1 (EC-CUBE 4 series) allows a remote attacker to inject an arbitrary script by leading an administrator or a user to a specially … CWE-79
Cross-site Scripting
CVE-2021-20751 2024-11-21 14:47 2021-06-28 Show GitHub Exploit DB Packet Storm
199284 6.1 MEDIUM
Network
ec-cube ec-cube Cross-site scripting vulnerability in EC-CUBE EC-CUBE 3.0.0 to 3.0.18-p2 (EC-CUBE 3 series) and EC-CUBE 4.0.0 to 4.0.5-p1 (EC-CUBE 4 series) allows a remote attacker to inject an arbitrary script by … CWE-79
Cross-site Scripting
CVE-2021-20750 2024-11-21 14:47 2021-06-28 Show GitHub Exploit DB Packet Storm
199285 5.4 MEDIUM
Network
nendeb fudousan_plugin
fudousan_plugin_pro_multi-user
fudousan_plugin_pro_single-user
Cross-site scripting vulnerability in Fudousan plugin ver5.7.0 and earlier, Fudousan Plugin Pro Single-User Type ver5.7.0 and earlier, and Fudousan Plugin Pro Multi-User Type ver5.7.0 and earlier all… CWE-79
Cross-site Scripting
CVE-2021-20749 2024-11-21 14:47 2021-06-28 Show GitHub Exploit DB Packet Storm
199286 5.4 MEDIUM
Network
wordpress_popular_posts_project wordpress_popular_posts Cross-site scripting vulnerability in WordPress Popular Posts 5.3.2 and earlier allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors. CWE-79
Cross-site Scripting
CVE-2021-20746 2024-11-21 14:47 2021-06-28 Show GitHub Exploit DB Packet Storm
199287 7.8 HIGH
Local
inkdrop inkdrop Inkdrop versions prior to v5.3.1 allows an attacker to execute arbitrary OS commands on the system where it runs by loading a file or code snippet containing an invalid iframe into Inkdrop. CWE-78
OS Command 
CVE-2021-20745 2024-11-21 14:47 2021-06-28 Show GitHub Exploit DB Packet Storm
199288 8.8 HIGH
Network
hitachi
nec
virtual_file_platform
nas_gateway_nh4a_firmware
nas_gateway_nh8a_firmware
nas_gateway_nh4b_firmware
nas_gateway_nh8b_firmware
nas_gateway_nh4c_firmware
nas_gateway_nh8c_firmware
Hitachi Virtual File Platform Versions prior to 5.5.3-09 and Versions prior to 6.4.3-09, and NEC Storage M Series NAS Gateway Nh4a/Nh8a versions prior to FOS 5.5.3-08(NEC2.5.4a) and Nh4b/Nh8b, Nh4c/N… CWE-78
OS Command 
CVE-2021-20740 2024-11-21 14:47 2021-06-28 Show GitHub Exploit DB Packet Storm
199289 7.5 HIGH
Network
phoenixcontact fl_comserver_uni_232\/422\/485_firmware
fl_comserver_uni_232\/422\/485-t_firmware
In Phoenix Contact FL COMSERVER UNI in versions < 2.40 a invalid Modbus exception response can lead to a temporary denial of service. - CVE-2021-21002 2024-11-21 14:47 2021-06-26 Show GitHub Exploit DB Packet Storm
199290 7.5 HIGH
Network
phoenixcontact fl_switch_smcs_16tx_firmware
fl_switch_smcs_14tx\/2fx_firmware
fl_switch_smcs_14tx\/2fx-sm_firmware
fl_switch_smcs_8gt_firmware
fl_switch_smcs_6gt\/2sfp_firmware
fl_switch_smcs_8tx-pn_…
In Phoenix Contact FL SWITCH SMCS series products in multiple versions if an attacker sends a hand-crafted TCP-Packet with the Urgent-Flag set and the Urgent-Pointer set to 0, the network stack will … - CVE-2021-21005 2024-11-21 14:47 2021-06-26 Show GitHub Exploit DB Packet Storm