Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 20, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
240401 4.3 警告 Mike Carr - Flogr の index.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-4336 2012-09-19 16:17 2012-09-15 Show GitHub Exploit DB Packet Storm
240402 4.3 警告 Python Software Foundation - Beaker における重要なセッションデータの一部を取得される脆弱性 CWE-310
暗号の問題
CVE-2012-3458 2012-09-19 16:16 2012-09-15 Show GitHub Exploit DB Packet Storm
240403 4.3 警告 Kayako - Kayako Fusion におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-3233 2012-09-19 16:14 2012-09-15 Show GitHub Exploit DB Packet Storm
240404 6.8 警告 TestLink Development Team - TestLink におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2012-2275 2012-09-19 16:12 2012-09-15 Show GitHub Exploit DB Packet Storm
240405 4.3 警告 Banana Dance - Banana Dance の search.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-5176 2012-09-19 16:11 2011-10-2 Show GitHub Exploit DB Packet Storm
240406 7.5 危険 Banana Dance - Banana Dance の search.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2011-5175 2012-09-19 16:09 2011-10-2 Show GitHub Exploit DB Packet Storm
240407 7.2 危険 インテル - 複数の Intel 製品におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2011-5174 2012-09-19 16:07 2011-12-5 Show GitHub Exploit DB Packet Storm
240408 6.8 警告 Bugbear Entertainment - Bugbear Entertainment FlatOut におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2011-5173 2012-09-19 16:05 2012-09-15 Show GitHub Exploit DB Packet Storm
240409 9.3 危険 PowerProduction Software - StoryBoard Quick におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2011-5172 2012-09-19 16:04 2012-09-15 Show GitHub Exploit DB Packet Storm
240410 9.3 危険 Castillo Bueno Systems - Castillo Bueno Systems CCMPlayer におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2011-5170 2012-09-19 16:03 2011-10-2 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 21, 2026, 4:10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
267351 9.8 CRITICAL
Network
advantech vesp211-eu_firmware
vesp211-232_firmware
The web interface on Advantech/B+B SmartWorx VESP211-EU devices with firmware 1.7.2 and VESP211-232 devices with firmware 1.5.1 and 1.7.2 relies on the client to implement access control, which allow… CWE-284
Improper Access Control
CVE-2016-2275 2024-11-21 11:48 2016-02-21 Show GitHub Exploit DB Packet Storm
267352 5.5 MEDIUM
Local
xen xen VMX in Xen 4.6.x and earlier, when using an Intel or Cyrix CPU, allows local HVM guest users to cause a denial of service (guest crash) via vectors related to a non-canonical RIP. NVD-CWE-Other
CVE-2016-2271 2024-11-21 11:48 2016-02-20 Show GitHub Exploit DB Packet Storm
267353 6.8 MEDIUM
Network
debian
fedoraproject
xen
oracle
debian_linux
fedora
xen
vm_server
Xen 4.6.x and earlier allows local guest administrators to cause a denial of service (host reboot) via vectors related to multiple mappings of MMIO pages with different cachability settings. CWE-20
 Improper Input Validation 
CVE-2016-2270 2024-11-21 11:48 2016-02-20 Show GitHub Exploit DB Packet Storm
267354 5.3 MEDIUM
Adjacent
belden hirschmann_firmware
hirschmann_l2b
The password-sync feature on Belden Hirschmann Classic Platform switches L2B before 05.3.07 and L2E, L2P, L3E, and L3P before 09.0.06 sets an SNMP community to the same string as the administrator pa… CWE-200
Information Exposure
CVE-2016-2509 2024-11-21 11:48 2016-02-19 Show GitHub Exploit DB Packet Storm
267355 6.5 MEDIUM
Adjacent
comcast xfinity_home_security_system Comcast XFINITY Home Security System does not properly maintain base-station communication, which allows physically proximate attackers to defeat sensor functionality by interfering with ZigBee 2.4 G… CWE-254
 7PK - Security Features
CVE-2016-2398 2024-11-21 11:48 2016-02-18 Show GitHub Exploit DB Packet Storm
267356 9.8 CRITICAL
Network
sonicwall uma_em5000_firmware
analyzer
global_management_system
The cliserver implementation in Dell SonicWALL GMS, Analyzer, and UMA EM5000 7.2, 8.0, and 8.1 before Hotfix 168056 allows remote attackers to deserialize and execute arbitrary Java code via crafted … CWE-77
Command Injection
CVE-2016-2397 2024-11-21 11:48 2016-02-18 Show GitHub Exploit DB Packet Storm
267357 9.9 CRITICAL
Network
sonicwall analyzer
global_management_system
uma_em5000_firmware
The GMS ViewPoint (GMSVP) web application in Dell SonicWALL GMS, Analyzer, and UMA EM5000 7.2, 8.0, and 8.1 before Hotfix 168056 allows remote authenticated users to execute arbitrary commands via ve… CWE-77
Command Injection
CVE-2016-2396 2024-11-21 11:48 2016-02-18 Show GitHub Exploit DB Packet Storm
267358 7.5 HIGH
Network
sap netweaver Directory traversal vulnerability in the GetFileList function in the SAP Manufacturing Integration and Intelligence (xMII) component 15.0 for SAP NetWeaver 7.4 allows remote attackers to read arbitra… CWE-22
Path Traversal
CVE-2016-2389 2024-11-21 11:48 2016-02-17 Show GitHub Exploit DB Packet Storm
267359 6.1 MEDIUM
Network
sap netweaver Multiple cross-site scripting (XSS) vulnerabilities in the Java Proxy Runtime ProxyServer servlet in SAP NetWeaver 7.4 allow remote attackers to inject arbitrary web script or HTML via the (1) ns or … CWE-79
Cross-site Scripting
CVE-2016-2387 2024-11-21 11:48 2016-02-17 Show GitHub Exploit DB Packet Storm
267360 4.9 MEDIUM
Network
huawei mt882_firmware GlobespanVirata ftpd 1.0, as used on Huawei SmartAX MT882 devices V200R002B022 Arg, allows remote authenticated users to cause a denial of service (device outage) by using the FTP MKD command to crea… CWE-17
Code
CVE-2016-2314 2024-11-21 11:48 2016-02-15 Show GitHub Exploit DB Packet Storm