Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 26, 2026, 4:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
204201 5.5 警告
Local
Xen プロジェクト - Xen の libxl デバイスハンドリングにおけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2016-4963 2016-06-8 15:56 2016-06-2 Show GitHub Exploit DB Packet Storm
204202 7.8 重要
Local
Ansible
Fedora Project
- Ansible の lxc_container モジュールの create_script 関数における任意のファイルに書き込まれる脆弱性 CWE-20
不適切な入力確認
CVE-2016-3096 2016-06-8 15:41 2016-04-15 Show GitHub Exploit DB Packet Storm
204203 7.5 重要
Network
Debian
Canonical
Igor Sysoev
- nginx の os/unix/ngx_files.c におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2016-4450 2016-06-8 14:53 2016-05-31 Show GitHub Exploit DB Packet Storm
204204 9.8 緊急
Network
Debian
Zend Technologies Ltd.
- Zend Framework の PDO アダプタにおける任意の SQL コマンドを実行される脆弱性 CWE-89
SQLインジェクション
CVE-2015-7695 2016-06-8 13:51 2015-09-15 Show GitHub Exploit DB Packet Storm
204205 7.8 重要
Local
Debian
Canonical
Spice Project
レッドハット
- SPICE におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2015-5260 2016-06-8 12:26 2015-10-6 Show GitHub Exploit DB Packet Storm
204206 9.8 緊急
Network
Debian
FreeType Project
- FreeType の複数の関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2014-9746 2016-06-8 12:08 2014-01-23 Show GitHub Exploit DB Packet Storm
204207 7.8 重要
Local
シスコシステムズ - Cisco IP Phone 8800 のソフトウェアにおける OS コマンド実行の権限を取得される脆弱性 CWE-20
不適切な入力確認
CVE-2016-1403 2016-06-7 18:18 2016-06-3 Show GitHub Exploit DB Packet Storm
204208 8.8 重要
Network
シスコシステムズ - Cisco Prime Network Analysis Module および Prime Virtual Network Analysis Module における任意の OS コマンドを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2016-1391 2016-06-7 18:18 2016-06-1 Show GitHub Exploit DB Packet Storm
204209 6.7 警告
Local
DELL EMC (旧 EMC Corporation) - EMC Isilon OneFS における root のシェルへのアクセス権を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-0908 2016-06-7 17:12 2016-06-2 Show GitHub Exploit DB Packet Storm
204210 - - Apache Software Foundation - ** 削除 ** Apache Cordova Android におけるアクセス制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2015-5256 2016-06-7 14:04 2015-11-20 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 26, 2026, 4:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
349371 - horde turba_h3 Multiple cross-site scripting (XSS) vulnerabilities in Horde Turba H3 2.0.4 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the address book and (2) contact data. NVD-CWE-Other
CVE-2005-4242 2011-03-8 11:27 2005-12-15 Show GitHub Exploit DB Packet Storm
349372 - quickpaypro quickpaypro Multiple SQL injection vulnerabilities in QuickPayPro 3.1 allow remote attackers to execute arbitrary SQL commands via the (1) popupid parameter in popups.edit.php; (2) so, (3) sb, and (4) nr paramet… NVD-CWE-Other
CVE-2005-4243 2011-03-8 11:27 2005-12-15 Show GitHub Exploit DB Packet Storm
349373 - snipegallery snipe_gallery SQL injection vulnerability in Snipe Gallery 3.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) gallery_id parameter to view.php and (2) image_id parameter to ima… CWE-89
SQL Injection
CVE-2005-4244 2011-03-8 11:27 2005-12-14 Show GitHub Exploit DB Packet Storm
349374 - snipegallery snipe_gallery Cross-site scripting (XSS) vulnerability in search.php in Snipe Gallery 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the keyword parameter. CWE-79
Cross-site Scripting
CVE-2005-4245 2011-03-8 11:27 2005-12-14 Show GitHub Exploit DB Packet Storm
349375 - quickpaypro quickpaypro Multiple cross-site scripting (XSS) vulnerabilities in QuickPayPro 3.1 allow remote attackers to inject arbitrary web script or HTML via various fields, such as those in (1) communication/subscribers… NVD-CWE-Other
CVE-2005-4248 2011-03-8 11:27 2005-12-15 Show GitHub Exploit DB Packet Storm
349376 - mcgallery mcgallery_pro Directory traversal vulnerability in mcGallery PRO 2.2 and earlier allows remote attackers to read arbitrary files via the language parameter. NVD-CWE-Other
CVE-2005-4250 2011-03-8 11:27 2005-12-14 Show GitHub Exploit DB Packet Storm
349377 - mcgallery mcgallery_pro Multiple SQL injection vulnerabilities in mcGallery PRO 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id, (2) start, and (3) rand parameters to show.php, and th… NVD-CWE-Other
CVE-2005-4251 2011-03-8 11:27 2005-12-14 Show GitHub Exploit DB Packet Storm
349378 - - - Cross-site scripting (XSS) vulnerability in mcGallery PRO 2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search module parameters. NVD-CWE-Other
CVE-2005-4252 2011-03-8 11:27 2005-12-14 Show GitHub Exploit DB Packet Storm
349379 - dreamlevels dream_poll SQL injection vulnerability in view_Results.php in DreamLevels DreamPoll 3.0 final allows remote attackers to execute arbitrary SQL commands via the id parameter. NVD-CWE-Other
CVE-2005-4254 2011-03-8 11:27 2005-12-15 Show GitHub Exploit DB Packet Storm
349380 - wikkawiki wikkawiki Cross-site scripting (XSS) vulnerability in TextSearch in WikkaWiki 1.1.6.0 allows remote attackers to inject arbitrary web script or HTML via a hex-encoded phrase parameter. NVD-CWE-Other
CVE-2005-4255 2011-03-8 11:27 2005-12-15 Show GitHub Exploit DB Packet Storm