Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 17, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
232511 4.3 警告 Simple Machines - Simple Machines Forum におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-5903 2012-11-20 13:54 2012-11-17 Show GitHub Exploit DB Packet Storm
232512 4.3 警告 DFLabs - DFLabs PTK の ptk/lib/modal_bookmark.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-5902 2012-11-20 13:53 2012-11-17 Show GitHub Exploit DB Packet Storm
232513 5 警告 DFLabs - DFLabs PTK におけるログなどを読まれる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-5901 2012-11-20 13:52 2012-11-17 Show GitHub Exploit DB Packet Storm
232514 7.5 危険 SAMEDIA O.E. - SAMEDIA LandShop における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2012-5900 2012-11-20 13:49 2012-11-17 Show GitHub Exploit DB Packet Storm
232515 4.3 警告 SAMEDIA O.E. - SAMEDIA LandShop の admin/action/objects.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-5899 2012-11-20 13:48 2012-11-17 Show GitHub Exploit DB Packet Storm
232516 6.8 警告 SAMEDIA O.E. - SAMEDIA LandShop におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2012-5898 2012-11-20 13:47 2012-11-17 Show GitHub Exploit DB Packet Storm
232517 10 危険 Quest Software Inc. - Quest InTrust の AnnotateX.dll における任意のコードを実行される脆弱性 CWE-DesignError
CVE-2012-5896 2012-11-20 13:43 2012-11-17 Show GitHub Exploit DB Packet Storm
232518 10 危険 iRODS - iRODS における脆弱性 CWE-noinfo
情報不足
CVE-2012-5895 2012-11-20 13:43 2012-03-16 Show GitHub Exploit DB Packet Storm
232519 7.5 危険 Havalite - Havalite CMS の hava_post.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2012-5894 2012-11-20 13:42 2012-11-17 Show GitHub Exploit DB Packet Storm
232520 6.8 警告 Havalite - Havalite CMS の hava_upload.php における任意のコードを実行される脆弱性 CWE-Other
その他
CVE-2012-5893 2012-11-20 13:41 2012-11-17 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 18, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
292891 - samsung
meizu
galaxy_note_2
mx
galaxy_s2
The kernel in Samsung Galaxy S2, Galaxy Note 2, MEIZU MX, and possibly other Android devices, when running an Exynos 4210 or 4412 processor, uses weak permissions (0666) for /dev/exynos-mem, which al… CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-6422 2024-11-21 10:46 2012-12-18 Show GitHub Exploit DB Packet Storm
292892 - xen xen Multiple HVM control operations in Xen 3.4 through 4.2 allow local HVM guest OS administrators to cause a denial of service (physical CPU consumption) via a large input. CWE-399
 Resource Management Errors
CVE-2012-6333 2024-11-21 10:46 2012-12-13 Show GitHub Exploit DB Packet Storm
292893 - simple_gmail_login 1.1.2
1.1.3
simple-gmail-login.php in the Simple Gmail Login plugin before 1.1.4 for WordPress allows remote attackers to obtain sensitive information via a request that lacks a timezone, leading to disclosure o… CWE-200
Information Exposure
CVE-2012-6313 2024-11-21 10:46 2012-12-11 Show GitHub Exploit DB Packet Storm
292894 - video-lead-form uk-cookie Cross-site scripting (XSS) vulnerability in the Video Lead Form plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the errMsg parameter in a video-lead-form actio… CWE-79
Cross-site Scripting
CVE-2012-6312 2024-11-21 10:46 2012-12-11 Show GitHub Exploit DB Packet Storm
292895 6.1 MEDIUM
Network
arc2_project arc2 ARC (aka ARC2) through 2011-12-01 allows reflected XSS via the end_point.php query parameter in an output=htmltab action. CWE-79
Cross-site Scripting
CVE-2012-5873 2024-11-21 10:45 2023-04-26 Show GitHub Exploit DB Packet Storm
292896 9.8 CRITICAL
Network
arc2_project arc2 ARC (aka ARC2) through 2011-12-01 allows blind SQL Injection in getTriplePatternSQL in ARC2_StoreSelectQueryHandler.php via comments in a SPARQL WHERE clause. CWE-89
SQL Injection
CVE-2012-5872 2024-11-21 10:45 2023-04-26 Show GitHub Exploit DB Packet Storm
292897 7.8 HIGH
Local
ibm
symantec
hp
notes
domino
data_loss_prevention_endpoint
data_loss_prevention_enforce\/detection_servers
messaging_gateway
mail_security
autonomy_keyview_idol
Multiple unspecified vulnerabilities in Autonomy KeyView IDOL before 10.16, as used in Symantec Mail Security for Microsoft Exchange before 6.5.8, Symantec Mail Security for Domino before 8.1.1, Syma… NVD-CWE-noinfo
CVE-2012-6277 2024-11-21 10:45 2020-02-22 Show GitHub Exploit DB Packet Storm
292898 7.5 HIGH
Network
magentocommerce magento Zend_XmlRpc Class in Magento before 1.7.0.2 contains an information disclosure vulnerability. CWE-200
Information Exposure
CVE-2012-6091 2024-11-21 10:45 2020-02-14 Show GitHub Exploit DB Packet Storm
292899 6.5 MEDIUM
Network
blackberry playbook_firmware BlackBerry PlayBook before 2.1 has an Information Disclosure Vulnerability via a Web browser component error CWE-200
Information Exposure
CVE-2012-5828 2024-11-21 10:45 2020-02-11 Show GitHub Exploit DB Packet Storm
292900 7.5 HIGH
Network
arctic_torrent_project arctic_torrent A vulnerability exists in Arctic Torrent 1.4 via unspecified vectors in .torrent file handling, which could let a malicious user cause a Denial of Service. NVD-CWE-noinfo
CVE-2012-6309 2024-11-21 10:45 2020-02-7 Show GitHub Exploit DB Packet Storm