Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 5, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
222551 6.8 警告 XYZScripts - WordPress 用 Newsletter Manager プラグインにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2012-6629 2014-01-21 17:03 2012-05-15 Show GitHub Exploit DB Packet Storm
222552 4.3 警告 XYZScripts - WordPress 用 Newsletter Manager プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-6628 2014-01-21 17:03 2012-04-20 Show GitHub Exploit DB Packet Storm
222553 4.3 警告 XYZScripts - WordPress 用 Newsletter Manager プラグインの admin/test_mail.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-6627 2014-01-21 17:02 2012-05-15 Show GitHub Exploit DB Packet Storm
222554 4.3 警告 VastHTML - WordPress 用 ForumPress WP Forum Server プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-6623 2014-01-21 17:01 2012-07-14 Show GitHub Exploit DB Packet Storm
222555 4.3 警告 VastHTML - WordPress 用 ForumPress WP Forum Server プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-6622 2014-01-21 17:01 2012-04-18 Show GitHub Exploit DB Packet Storm
222556 7.5 危険 VastHTML - WordPress 用 ForumPress WP Forum Server プラグインにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2012-6625 2014-01-21 16:09 2012-04-18 Show GitHub Exploit DB Packet Storm
222557 4.3 警告 Mightymess - WordPress 用 SoundCloud Is Gold プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-6624 2014-01-21 16:08 2012-05-15 Show GitHub Exploit DB Packet Storm
222558 7.5 危険 Brian Cabunac - b2ePMS の verify-user.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2012-6626 2014-01-21 14:52 2012-05-11 Show GitHub Exploit DB Packet Storm
222559 4.3 警告 Vessio - Vessio NetBill におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-6632 2014-01-21 14:26 2012-05-11 Show GitHub Exploit DB Packet Storm
222560 6.8 警告 Vessio - Vessio NetBill の accounts/admin/index.php におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2012-6631 2014-01-21 14:24 2012-05-11 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 5, 2026, 4:11 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
267821 5.5 MEDIUM
Local
oracle
linux
linux
linux_kernel
vm_server
fs/overlayfs/dir.c in the OverlayFS filesystem implementation in the Linux kernel before 4.6 does not properly verify the upper dentry before proceeding with unlink and rename system-call processing,… CWE-20
 Improper Input Validation 
CVE-2016-6197 2024-11-21 11:55 2016-08-7 Show GitHub Exploit DB Packet Storm
267822 7.8 HIGH
Local
linux linux_kernel The apparmor_setprocattr function in security/apparmor/lsm.c in the Linux kernel before 4.6.5 does not validate the buffer size, which allows local users to gain privileges by triggering an AppArmor … CWE-264
CWE-119
Permissions, Privileges, and Access Controls
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2016-6187 2024-11-21 11:55 2016-08-7 Show GitHub Exploit DB Packet Storm
267823 7.8 HIGH
Local
linux linux_kernel net/core/skbuff.c in the Linux kernel 4.7-rc6 allows local users to cause a denial of service (panic) or possibly have unspecified other impact via certain IPv6 socket operations. CWE-20
 Improper Input Validation 
CVE-2016-6162 2024-11-21 11:55 2016-08-7 Show GitHub Exploit DB Packet Storm
267824 5.1 MEDIUM
Local
linux linux_kernel Race condition in the ec_device_ioctl_xcmd function in drivers/platform/chrome/cros_ec_dev.c in the Linux kernel before 4.7 allows local users to cause a denial of service (out-of-bounds array access… CWE-362
Race Condition
CVE-2016-6156 2024-11-21 11:55 2016-08-7 Show GitHub Exploit DB Packet Storm
267825 4.7 MEDIUM
Local
linux linux_kernel Race condition in the audit_log_single_execve_arg function in kernel/auditsc.c in the Linux kernel through 4.7 allows local users to bypass intended character-set restrictions or disrupt system-call … CWE-362
Race Condition
CVE-2016-6136 2024-11-21 11:55 2016-08-7 Show GitHub Exploit DB Packet Storm
267826 6.1 MEDIUM
Network
debian
djangoproject
debian_linux
django
Cross-site scripting (XSS) vulnerability in the dismissChangeRelatedObjectPopup function in contrib/admin/static/admin/js/admin/RelatedObjectLookups.js in Django before 1.8.14, 1.9.x before 1.9.8, an… CWE-79
Cross-site Scripting
CVE-2016-6186 2024-11-21 11:55 2016-08-6 Show GitHub Exploit DB Packet Storm
267827 9.8 CRITICAL
Network
sap hana The multi-tenant database container feature in SAP HANA does not properly encrypt communications, which allows remote attackers to bypass intended access restrictions and possibly have unspecified ot… CWE-284
Improper Access Control
CVE-2016-6150 2024-11-21 11:55 2016-08-5 Show GitHub Exploit DB Packet Storm
267828 5.5 MEDIUM
Local
sap hana_sps09 SAP HANA SPS09 1.00.091.00.14186593 allows local users to obtain sensitive information by leveraging the EXPORT statement to export files, aka SAP Security Note 2252941. CWE-200
Information Exposure
CVE-2016-6149 2024-11-21 11:55 2016-08-5 Show GitHub Exploit DB Packet Storm
267829 7.5 HIGH
Network
sap hana SAP HANA DB 1.00.73.00.389160 allows remote attackers to cause a denial of service (process termination) or execute arbitrary code via vectors related to an IMPORT statement, aka SAP Security Note 22… CWE-20
 Improper Input Validation 
CVE-2016-6148 2024-11-21 11:55 2016-08-5 Show GitHub Exploit DB Packet Storm
267830 9.8 CRITICAL
Network
sap trex An unspecified interface in SAP TREX 7.10 Revision 63 allows remote attackers to execute arbitrary OS commands with SIDadm privileges via unspecified vectors, aka SAP Security Note 2234226. CWE-78
OS Command 
CVE-2016-6147 2024-11-21 11:55 2016-08-5 Show GitHub Exploit DB Packet Storm