Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 24, 2026, 2 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
240391 6.8 警告 mybulletinboard - MyBB の inc/functions_post.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-4706 2012-09-25 15:35 2006-09-12 Show GitHub Exploit DB Packet Storm
240392 6.8 警告 マイクロソフト - Microsoft Visual Studio 2005 におけるクロスゾーンスクリプティングの脆弱性 CWE-Other
その他
CVE-2006-4704 2012-09-25 15:35 2006-11-1 Show GitHub Exploit DB Packet Storm
240393 5 警告 IBM - IBM Director における HTTP ヘッダから重要な情報を取得される脆弱性 - CVE-2006-4683 2012-09-25 15:35 2006-09-11 Show GitHub Exploit DB Packet Storm
240394 5 警告 IBM - IBM Director におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2006-4682 2012-09-25 15:35 2006-09-11 Show GitHub Exploit DB Packet Storm
240395 5 警告 IBM - IBM Director の Redirect.bat におけるディレクトリトラバーサルの脆弱性 - CVE-2006-4681 2012-09-25 15:35 2006-09-11 Show GitHub Exploit DB Packet Storm
240396 2.6 注意 PHP-Fusion - PHP-Fusion の maincore.php における SQL インジェクション攻撃を実行される脆弱性 - CVE-2006-4673 2012-09-25 15:35 2006-09-11 Show GitHub Exploit DB Packet Storm
240397 4.3 警告 mkportal - MKPortal の index.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-4665 2012-09-25 15:35 2006-09-8 Show GitHub Exploit DB Packet Storm
240398 4.3 警告 luke hutteman - Luke Hutteman SharpReader におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-4761 2012-09-25 15:35 2006-09-13 Show GitHub Exploit DB Packet Storm
240399 5 警告 laurentiu matei - Laurentiu Matei XHP CMS におけるインストールパスを取得される脆弱性 - CVE-2006-4752 2012-09-25 15:35 2006-09-13 Show GitHub Exploit DB Packet Storm
240400 6.8 警告 laurentiu matei - Laurentiu Matei XHP CMS の index.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-4751 2012-09-25 15:35 2006-09-13 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 24, 2026, 4:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
267381 7.8 HIGH
Local
mozilla firefox The maintenance service in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 on Windows does not prevent MAR extracted-file modification during updater execution, which might allow local u… CWE-264
Permissions, Privileges, and Access Controls
CVE-2016-2826 2024-11-21 11:48 2016-06-13 Show GitHub Exploit DB Packet Storm
267382 6.5 MEDIUM
Network
canonical
opensuse
mozilla
ubuntu_linux
leap
opensuse
firefox
Mozilla Firefox before 47.0 allows remote attackers to bypass the Same Origin Policy and modify the location.host property via an invalid data: URL. CWE-284
Improper Access Control
CVE-2016-2825 2024-11-21 11:48 2016-06-13 Show GitHub Exploit DB Packet Storm
267383 8.8 HIGH
Network
mozilla
opensuse
firefox
leap
opensuse
The TSymbolTableLevel class in ANGLE, as used in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 on Windows, allows remote attackers to cause a denial of service (out-of-bounds write and… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2016-2824 2024-11-21 11:48 2016-06-13 Show GitHub Exploit DB Packet Storm
267384 6.5 MEDIUM
Network
debian
mozilla
canonical
opensuse
debian_linux
firefox
ubuntu_linux
leap
opensuse
Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to spoof the address bar via a SELECT element with a persistent menu. CWE-284
Improper Access Control
CVE-2016-2822 2024-11-21 11:48 2016-06-13 Show GitHub Exploit DB Packet Storm
267385 7.5 HIGH
Network
mozilla
debian
opensuse
canonical
firefox
debian_linux
leap
opensuse
ubuntu_linux
Use-after-free vulnerability in the mozilla::dom::Element class in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2, when contenteditable mode is enabled, allows remote attackers to execu… NVD-CWE-Other
CVE-2016-2821 2024-11-21 11:48 2016-06-13 Show GitHub Exploit DB Packet Storm
267386 8.8 HIGH
Network
opensuse
mozilla
debian
canonical
leap
opensuse
firefox
debian_linux
ubuntu_linux
Heap-based buffer overflow in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to execute arbitrary code via foreign-context HTML5 fragments, as demonstrated by fr… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2016-2819 2024-11-21 11:48 2016-06-13 Show GitHub Exploit DB Packet Storm
267387 8.8 HIGH
Network
mozilla
debian
redhat
novell
opensuse
canonical
firefox
debian_linux
enterprise_linux_desktop
enterprise_linux_server
enterprise_linux_server_aus
enterprise_linux_for_scientific_computing
enterprise_linux_workstation
enterpris…
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to cause a denial of service (memory corruption and a… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2016-2818 2024-11-21 11:48 2016-06-13 Show GitHub Exploit DB Packet Storm
267388 8.8 HIGH
Network
mozilla
canonical
novell
opensuse
firefox_esr
ubuntu_linux
suse_linux_enterprise_server
suse_linux_enterprise_desktop
suse_linux_enterprise_software_development_kit
leap
opensuse
firefox
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly exe… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2016-2815 2024-11-21 11:48 2016-06-13 Show GitHub Exploit DB Packet Storm
267389 5.5 MEDIUM
Local
google android Activity Manager in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 does not properly terminate process groups, which allows attackers to obtain sensitive information via a … CWE-200
Information Exposure
CVE-2016-2500 2024-11-21 11:48 2016-06-13 Show GitHub Exploit DB Packet Storm
267390 5.5 MEDIUM
Local
google android AudioSource.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 does not initialize certain data, which allows attacker… CWE-200
Information Exposure
CVE-2016-2499 2024-11-21 11:48 2016-06-13 Show GitHub Exploit DB Packet Storm