Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 4, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
205931 6.1 警告
Network
Apache Software Foundation - Apache Ranger の Policy Admin Tool におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2015-0265 2016-04-13 11:45 2015-08-5 Show GitHub Exploit DB Packet Storm
205932 7.5 重要
Network
レッドハット - Red Hat Enterprise Linux の glibc パッケージの calloc 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2015-5229 2016-04-13 11:34 2015-07-24 Show GitHub Exploit DB Packet Storm
205933 9.8 緊急
Network
SAP - SAP NetWeaver Java AS の Configuration Wizard における XML 外部エンティティの脆弱性 CWE-Other
その他
CVE-2016-3974 2016-04-13 11:04 2016-03-8 Show GitHub Exploit DB Packet Storm
205934 6.3 警告
Network
SAP - SAP NetWeaver AS Java の XML Data Archiving Service における重要な情報を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2015-8840 2016-04-13 11:04 2015-07-15 Show GitHub Exploit DB Packet Storm
205935 6.1 警告
Network
Debian
WebSVN
- WebSVN におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-2511 2016-04-12 18:03 2016-02-22 Show GitHub Exploit DB Packet Storm
205936 3.1
Network
Django Software Foundation - Django の contrib/auth/hashers.py のパスワードハッシャーにおけるユーザを列挙される脆弱性 CWE-200
情報漏えい
CVE-2016-2513 2016-04-12 17:55 2016-03-1 Show GitHub Exploit DB Packet Storm
205937 7.4 重要
Network
Django Software Foundation - Django の utils.http.is_safe_url 関数におけるユーザを任意の Web サイトにリダイレクトされる脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-2512 2016-04-12 17:55 2016-03-1 Show GitHub Exploit DB Packet Storm
205938 7.5 重要
Network
Node.js Foundation
Fedora Project
- Node.js の HTTP ヘッダ構文解析コードにおける HTTP レスポンス分割保護メカニズムを回避される脆弱性 CWE-20
不適切な入力確認
CVE-2016-2216 2016-04-12 17:51 2016-02-9 Show GitHub Exploit DB Packet Storm
205939 7.5 重要
Network
Node.js Foundation
Fedora Project
- Node.js における HTTP リクエストスマグリング攻撃を実行される脆弱性 CWE-20
不適切な入力確認
CVE-2016-2086 2016-04-12 17:51 2016-02-9 Show GitHub Exploit DB Packet Storm
205940 6.1 警告
Network
シトリックス・システムズ - Citrix XenMobile Server の Web ユーザインターフェースにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-2789 2016-04-12 17:42 2016-03-8 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 4, 2026, 4:17 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
351251 - ecartis
listar
ecartis
listar
Buffer overflows in Ecartis (formerly Listar) 1.0.0 in snapshot 20020427 and earlier allow local users to gain privileges via (1) a long command line argument, which is not properly handled in core.c… NVD-CWE-Other
CVE-2002-0468 2016-10-18 11:20 2002-08-12 Show GitHub Exploit DB Packet Storm
351252 - macromedia flash_player Standalone Macromedia Flash Player 5.0 before 5,0,30,2 allows remote attackers to execute arbitrary programs via a .SWF file containing the "exec" FSCommand. NVD-CWE-Other
CVE-2002-0477 2016-10-18 11:20 2002-08-12 Show GitHub Exploit DB Packet Storm
351253 - foundrynet edgeiron The default configuration of Foundry Networks EdgeIron 4802F allows remote attackers to modify sensitive information via arbitrary SNMP community strings. NVD-CWE-Other
CVE-2002-0478 2016-10-18 11:20 2002-08-12 Show GitHub Exploit DB Packet Storm
351254 - iss realsecure_nokia ISS RealSecure for Nokia devices before IPSO build 6.0.2001.141d is configured to allow a user "skank" on a machine "starscream" to become a key manager when the "first time connection" feature is en… NVD-CWE-Other
CVE-2002-0480 2016-10-18 11:20 2002-08-12 Show GitHub Exploit DB Packet Storm
351255 - php php move_uploaded_file in PHP does not does not check for the base directory (open_basedir), which could allow remote attackers to upload files to unintended locations on the system. NVD-CWE-Other
CVE-2002-0484 2016-10-18 11:20 2002-08-12 Show GitHub Exploit DB Packet Storm
351256 - linux_directory_penguin nslookup Linux Directory Penguin NsLookup CGI script (nslookup.pl) 1.0 allows remote attackers to execute arbitrary code via shell metacharacters in the (1) query or (2) type parameters. NVD-CWE-Other
CVE-2002-0489 2016-10-18 11:20 2002-08-12 Show GitHub Exploit DB Packet Storm
351257 - phpbb_group phpbb phpBB 1.4.4 and earlier with BBcode allows remote attackers to cause a denial of service (CPU consumption) and corrupt the database via null \0 characters within [code] tags. NVD-CWE-Other
CVE-2002-0533 2016-10-18 11:20 2002-08-12 Show GitHub Exploit DB Packet Storm
351258 - openbsd openbsd mail in OpenBSD 2.9 and 3.0 processes a tilde (~) escape character in a message even when it is not in interactive mode, which could allow local users to gain root privileges via calls to mail in cro… NVD-CWE-Other
CVE-2002-0542 2016-10-18 11:20 2002-07-3 Show GitHub Exploit DB Packet Storm
351259 - oracle application_server
application_server_web_cache
oracle8i
oracle9i
PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to obtain sensitive information via the OWA_UTIL stored procedures (1) OWA_UTIL.signature, (2) OWA_UTIL.listpri… NVD-CWE-Other
CVE-2002-0560 2016-10-18 11:20 2002-07-3 Show GitHub Exploit DB Packet Storm
351260 - oracle application_server
application_server_web_cache
oracle8i
oracle9i
The default configuration of the PL/SQL Gateway web administration interface in Oracle 9i Application Server 1.0.2.x uses null authentication, which allows remote attackers to gain privileges and mod… NVD-CWE-Other
CVE-2002-0561 2016-10-18 11:20 2002-07-3 Show GitHub Exploit DB Packet Storm