Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 9, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
258561 9.3 危険 マイクロソフト - Microsoft Windows の kernel における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2009-2514 2010-01-4 15:24 2009-11-10 Show GitHub Exploit DB Packet Storm
258562 6.8 警告 マイクロソフト - Microsoft Windows の kernel の Graphics Device Interface (GDI) における権限を取得される脆弱性 CWE-20
不適切な入力確認
CVE-2009-2513 2010-01-4 15:24 2009-11-10 Show GitHub Exploit DB Packet Storm
258563 6.8 警告 マイクロソフト - Microsoft Windows の kernel における権限を取得される脆弱性 CWE-20
不適切な入力確認
CVE-2009-1127 2010-01-4 15:24 2009-11-10 Show GitHub Exploit DB Packet Storm
258564 10 危険 マイクロソフト - Microsoft Windows の License Logging Server (llssrv.exe) における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2009-2523 2010-01-4 15:24 2009-11-10 Show GitHub Exploit DB Packet Storm
258565 9.3 危険 マイクロソフト - Microsoft Windows の Web Services on Devices API (WSDAPI) における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2009-2512 2010-01-4 15:23 2009-11-10 Show GitHub Exploit DB Packet Storm
258566 10 危険 アップル
VMware
サン・マイクロシステムズ
- Sun Java SE の Provider クラスにおける詳細不明な脆弱性 CWE-noinfo
情報不足
CVE-2009-2722 2010-01-4 14:56 2009-08-10 Show GitHub Exploit DB Packet Storm
258567 10 危険 アップル
VMware
サン・マイクロシステムズ
- Sun Java SE の Provider クラスにおける詳細不明な脆弱性 CWE-noinfo
情報不足
CVE-2009-2723 2010-01-4 14:55 2009-08-10 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 9, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
210751 5.5 MEDIUM
Local
appimage appimaged AppImage appimaged before 1.0.3 does not properly check whether a downloaded file is a valid appimage. For example, it will accept a crafted mp3 file that contains an appimage, and install it. CWE-494
 Download of Code Without Integrity Check
CVE-2020-25266 2024-11-21 14:17 2020-12-3 Show GitHub Exploit DB Packet Storm
210752 6.5 MEDIUM
Network
appimage libappimage AppImage libappimage before 1.0.3 allows attackers to trigger an overwrite of a system-installed .desktop file by providing a .desktop file that contains Name= with path components. NVD-CWE-noinfo
CVE-2020-25265 2024-11-21 14:17 2020-12-3 Show GitHub Exploit DB Packet Storm
210753 8.8 HIGH
Network
we-con plc_editor WECON PLC Editor Versions 1.3.8 and prior has a heap-based buffer overflow vulnerabilities have been identified that may allow arbitrary code execution. CWE-125
Out-of-bounds Read
CVE-2020-25181 2024-11-21 14:17 2020-12-2 Show GitHub Exploit DB Packet Storm
210754 8.8 HIGH
Network
we-con plc_editor WECON PLC Editor Versions 1.3.8 and prior has a stack-based buffer overflow vulnerability has been identified that may allow arbitrary code execution. CWE-787
 Out-of-bounds Write
CVE-2020-25177 2024-11-21 14:17 2020-12-2 Show GitHub Exploit DB Packet Storm
210755 9.8 CRITICAL
Network
rtautomation 499es_ethernet\/ip_adaptor_firmware 499ES EtherNet/IP (ENIP) Adaptor Source Code is vulnerable to a stack-based buffer overflow, which may allow an attacker to send a specially crafted packet that may result in a denial-of-service cond… CWE-787
 Out-of-bounds Write
CVE-2020-25159 2024-11-21 14:17 2020-11-25 Show GitHub Exploit DB Packet Storm
210756 9.8 CRITICAL
Network
paradox ip150_firmware The affected product is vulnerable to three stack-based buffer overflows, which may allow an unauthenticated attacker to remotely execute arbitrary code on the IP150 (firmware versions 5.02.09). - CVE-2020-25189 2024-11-21 14:17 2020-11-22 Show GitHub Exploit DB Packet Storm
210757 8.8 HIGH
Network
paradox ip150_firmware The affected product is vulnerable to five post-authentication buffer overflows, which may allow a logged in user to remotely execute arbitrary code on the IP150 (firmware versions 5.02.09). - CVE-2020-25185 2024-11-21 14:17 2020-11-21 Show GitHub Exploit DB Packet Storm
210758 5.4 MEDIUM
Network
grocy_project grocy Cross-site Scripting (XSS) vulnerability in grocy 2.7.1 via the add recipe module, which gets executed when deleting the recipe. CWE-79
Cross-site Scripting
CVE-2020-25454 2024-11-21 14:17 2020-11-19 Show GitHub Exploit DB Packet Storm
210759 7.3 HIGH
Network
lemocms lemocms app\admin\controller\sys\Uploads.php in lemocms 1.8.x allows users to upload files to upload executable files. CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2020-25406 2024-11-21 14:17 2020-11-19 Show GitHub Exploit DB Packet Storm
210760 7.5 HIGH
Network
taskcafe_project taskcafe Cross domain policies in Taskcafe Project Management tool before version 0.1.0 and 0.1.1 allows remote attackers to access sensitive data such as access token. NVD-CWE-noinfo
CVE-2020-25400 2024-11-21 14:17 2020-11-18 Show GitHub Exploit DB Packet Storm