Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 16, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
204351 5.6 警告
Network
Pivotal Software, Inc. - Pivotal Spring Data JPA における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2016-6652 2016-10-13 11:41 2016-09-30 Show GitHub Exploit DB Packet Storm
204352 9.1 緊急
Network
SAP - SAP Netweaver の SCTC サブパッケージの複数の関数における任意のコマンドを実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-7435 2016-10-13 11:34 2016-03-8 Show GitHub Exploit DB Packet Storm
204353 7.5 重要
Network
SAP - SAP Netweaver の SAP_BASIS および SAP_ABA コンポーネントにおける Security Audit ログに書かれる IP アドレスを偽装される脆弱性 CWE-Other
その他
CVE-2016-4551 2016-10-13 11:34 2016-09-22 Show GitHub Exploit DB Packet Storm
204354 4.4 警告
Local
Fabrice Bellard - QEMU の hw/net/pcnet.c の pcnet_rdra_addr 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2016-7909 2016-10-13 11:30 2016-09-27 Show GitHub Exploit DB Packet Storm
204355 4.4 警告
Local
Fabrice Bellard - QEMU の hw/net/mcf_fec.c の mcf_fec_do_tx 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2016-7908 2016-10-13 11:30 2016-09-22 Show GitHub Exploit DB Packet Storm
204356 4.4 警告
Local
Fabrice Bellard - QEMU の hw/net/imx_fec.c の imx_fec_do_tx 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
CWE-399
CVE-2016-7907 2016-10-13 11:30 2016-09-22 Show GitHub Exploit DB Packet Storm
204357 9.8 緊急
Network
Fabrice Bellard - QEMU の xlnx.xps-ethernetlite の .receive コールバックにおけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2016-7161 2016-10-13 11:30 2016-08-9 Show GitHub Exploit DB Packet Storm
204358 7.5 重要
Network
Debian
The Perl Foundation
- Perl 用 DBD::mysql モジュールにおけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2016-1246 2016-10-13 11:30 2016-10-3 Show GitHub Exploit DB Packet Storm
204359 7.5 重要
Network
シスコシステムズ - Cisco Unified Contact Center Express で使用される Unified Intelligence Center におけるユーザアカウントを作成される脆弱性 CWE-20
不適切な入力確認
CVE-2016-6426 2016-10-13 11:13 2016-10-5 Show GitHub Exploit DB Packet Storm
204360 6.5 警告
Network
シスコシステムズ - Cisco IOS および IOS XE の IKEv2 クライアントおよびイニシエータの実装におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2016-6423 2016-10-13 11:13 2016-10-5 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 16, 2026, 4:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
347481 - datalifecms datalife_engine Multiple PHP remote file inclusion vulnerabilities in DataLife Engine (DLE) 8.3 allow remote attackers to execute arbitrary PHP code via a URL in (1) the selected_language parameter to engine/inc/inc… CWE-94
Code Injection
CVE-2010-2005 2017-08-17 10:32 2010-05-21 Show GitHub Exploit DB Packet Storm
347482 - chaos_tool_suite_project ctools Multiple cross-site scripting (XSS) vulnerabilities in the Chaos Tool Suite (aka CTools) module 6.x before 6.x-1.4 for Drupal allow remote attackers to inject arbitrary web script or HTML via a node … CWE-79
Cross-site Scripting
CVE-2010-2010 2017-08-17 10:32 2010-05-22 Show GitHub Exploit DB Packet Storm
347483 - imagetraders iceberg_cms SQL injection vulnerability in details.php in Iceberg CMS allows remote attackers to execute arbitrary SQL commands via the p_id parameter. CWE-89
SQL Injection
CVE-2010-2016 2017-08-17 10:32 2010-05-25 Show GitHub Exploit DB Packet Storm
347484 - bukulokomedia lokomedia_cms Directory traversal vulnerability in downlot.php in Lokomedia CMS 1.4.1 and 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. CWE-22
Path Traversal
CVE-2010-2018 2017-08-17 10:32 2010-05-25 Show GitHub Exploit DB Packet Storm
347485 - mgenti tftputil_gui Buffer overflow in k23productions TFTPUtil GUI (aka TFTPGUI) 1.4.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long transport mode. CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2010-2028 2017-08-17 10:32 2010-05-25 Show GitHub Exploit DB Packet Storm
347486 - cybozu cybozu_office
cybozu_dotsales
Cybozu Office 7 Ktai and Dotsales do not properly restrict access to the login page, which allows remote attackers to bypass authentication and obtain or modify sensitive information by using the uni… CWE-264
Permissions, Privileges, and Access Controls
CVE-2010-2029 2017-08-17 10:32 2010-05-25 Show GitHub Exploit DB Packet Storm
347487 - alan_palazzolo external_link_page Cross-site scripting (XSS) vulnerability in the External Link Page module 5.x before 5.x-1.0 and 6.x before 6.x-1.2 for Drupal allows remote attackers to inject arbitrary web script or HTML via vecto… CWE-79
Cross-site Scripting
CVE-2010-2030 2017-08-17 10:32 2010-05-25 Show GitHub Exploit DB Packet Storm
347488 - kingsoft webshield KAVSafe.sys 2010.4.14.609 and earlier, as used in Kingsoft Webshield 3.5.1.2 and earlier, allows local users to overwrite arbitrary kernel memory via a crafted request to IOCTL 0x830020d4 on the KAVS… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2010-2031 2017-08-17 10:32 2010-05-25 Show GitHub Exploit DB Packet Storm
347489 - gpeasy gpeasy_cms Cross-site request forgery (CSRF) vulnerability in gpEasy CMS 1.6.2, 1.6.1, and earlier allows remote attackers to hijack the authentication of administrators for requests that create new administrat… CWE-352
 Origin Validation Error
CVE-2010-2039 2017-08-17 10:32 2010-05-25 Show GitHub Exploit DB Packet Storm
347490 - v-eva shopzilla_affiliate_script_php Cross-site scripting (XSS) vulnerability in search.php in V-EVA Shopzilla Affiliate Script PHP allows remote attackers to inject arbitrary web script or HTML via the s parameter. CWE-79
Cross-site Scripting
CVE-2010-2040 2017-08-17 10:32 2010-05-25 Show GitHub Exploit DB Packet Storm