Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 6, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
222371 4.3 警告 AlgoSec - AlgoSec Firewall Analyzer の afa/php/Login.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-5092 2014-01-31 12:28 2013-08-7 Show GitHub Exploit DB Packet Storm
222372 6.5 警告 WebHive - SocialEngine 用 Timeline プラグインのユーザプロファイルページ機能における任意のコードを実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-4898 2014-01-31 11:54 2013-07-25 Show GitHub Exploit DB Packet Storm
222373 4.3 警告 Zabbix - Zabbix の libs/zbxmedia/eztexting.c における SSL サーバになりすまされる脆弱性 CWE-310
暗号の問題
CVE-2012-6086 2014-01-31 11:27 2012-12-2 Show GitHub Exploit DB Packet Storm
222374 5 警告 株式会社ロックオン - EC-CUBE における情報漏えいの脆弱性 CWE-200
情報漏えい
CVE-2014-0808 2014-01-30 18:39 2014-01-22 Show GitHub Exploit DB Packet Storm
222375 5 警告 株式会社ロックオン - EC-CUBE における情報改ざんの脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-0807 2014-01-30 18:37 2014-01-22 Show GitHub Exploit DB Packet Storm
222376 2.6 注意 株式会社ロックオン - EC-CUBE におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2013-5993 2014-01-30 18:36 2013-11-20 Show GitHub Exploit DB Packet Storm
222377 4.3 警告 株式会社ロックオン - EC-CUBE におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-5996 2014-01-30 18:35 2013-11-20 Show GitHub Exploit DB Packet Storm
222378 5.5 警告 株式会社ロックオン - EC-CUBE における情報漏えいの脆弱性 CWE-200
情報漏えい
CVE-2013-5995 2014-01-30 18:34 2013-11-20 Show GitHub Exploit DB Packet Storm
222379 5 警告 株式会社ロックオン - EC-CUBE における情報漏えいの脆弱性 CWE-200
情報漏えい
CVE-2013-5994 2014-01-30 18:32 2013-11-20 Show GitHub Exploit DB Packet Storm
222380 6.4 警告 株式会社ロックオン - EC-CUBE におけるアクセス制限不備の脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-2314 2014-01-30 18:31 2013-05-23 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 6, 2026, 4:18 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
268501 5.3 MEDIUM
Network
acer acer_portal Acer Portal app before 3.9.4.2000 for Android does not properly validate SSL certificates, which allows remote attackers to perform a Man-in-the-middle attack via a crafted SSL certificate. CWE-295
Improper Certificate Validation 
CVE-2016-5648 2024-11-21 11:54 2017-06-9 Show GitHub Exploit DB Packet Storm
268502 7.5 HIGH
Network
redhat enterprise_linux_desktop
enterprise_linux_workstation
enterprise_linux_server
enterprise_linux_hpc_node
389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6 through 7, and Red Hat Enterprise Linux Workstat… CWE-200
Information Exposure
CVE-2016-5416 2024-11-21 11:54 2017-06-9 Show GitHub Exploit DB Packet Storm
268503 9.8 CRITICAL
Network
redhat enterprise_linux_desktop
enterprise_linux_workstation
enterprise_linux_server
enterprise_linux_hpc_node
389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6 through 7, and Red Hat Enterprise Linux Workstat… CWE-199
 Information Management Errors
CVE-2016-5405 2024-11-21 11:54 2017-06-9 Show GitHub Exploit DB Packet Storm
268504 7.8 HIGH
Local
pngquant pngquant Integer overflow in the rwpng_read_image24_libpng function in rwpng.c in pngquant 2.7.0 allows remote attackers to have unspecified impact via a crafted PNG file, which triggers a buffer overflow. CWE-190
 Integer Overflow or Wraparound
CVE-2016-5735 2024-11-21 11:54 2017-05-23 Show GitHub Exploit DB Packet Storm
268505 7.8 HIGH
Local
php php The bzread function in ext/bz2/bz2.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (out-of-bounds write) or execute arbitrary co… CWE-787
 Out-of-bounds Write
CVE-2016-5399 2024-11-21 11:54 2017-04-22 Show GitHub Exploit DB Packet Storm
268506 2.8 LOW
Local
oracle solaris_cluster Vulnerability in the Solaris Cluster component of Oracle Sun Systems Products Suite (subcomponent: NAS device addition). The supported version that is affected is 4.3. Easily "exploitable" vulnerabil… CWE-284
Improper Access Control
CVE-2016-5551 2024-11-21 11:54 2017-04-25 Show GitHub Exploit DB Packet Storm
268507 8.8 HIGH
Network
redhat jboss_bpm_suite
jboss_enterprise_brms_platform
Cross-site request forgery (CSRF) vulnerability in Red Hat JBoss BRMS and BPMS 6 allows remote attackers to hijack the authentication of users for requests that modify instances via a crafted web pag… CWE-352
 Origin Validation Error
CVE-2016-5401 2024-11-21 11:54 2017-04-21 Show GitHub Exploit DB Packet Storm
268508 9.8 CRITICAL
Network
novell groupwise Integer overflow in the Post Office Agent in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 might allow remote attackers to execute arbitrary code via a long (1) username or (2) password,… CWE-190
 Integer Overflow or Wraparound
CVE-2016-5762 2024-11-21 11:54 2017-04-21 Show GitHub Exploit DB Packet Storm
268509 6.1 MEDIUM
Network
novell groupwise Cross-site scripting (XSS) vulnerability in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 allows remote attackers to inject arbitrary web script or HTML via a crafted email. CWE-79
Cross-site Scripting
CVE-2016-5761 2024-11-21 11:54 2017-04-21 Show GitHub Exploit DB Packet Storm
268510 6.1 MEDIUM
Network
novell groupwise Multiple cross-site scripting (XSS) vulnerabilities in the administrator console in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 allow remote attackers to inject arbitrary web script or… CWE-79
Cross-site Scripting
CVE-2016-5760 2024-11-21 11:54 2017-04-21 Show GitHub Exploit DB Packet Storm