Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 21, 2026, 2 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
240491 4.3 警告 ZooEffect - WordPress 用 ZooEffect プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-5180 2012-09-21 15:29 2012-09-20 Show GitHub Exploit DB Packet Storm
240492 4.3 警告 Skysa - WordPress 用 Skysa App Bar Integration プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-5179 2012-09-21 15:28 2012-09-20 Show GitHub Exploit DB Packet Storm
240493 4.3 警告 Infoblox - Infoblox NetMRI の netmri/config/userAdmin/login.tdf におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-5178 2012-09-21 15:28 2011-10-18 Show GitHub Exploit DB Packet Storm
240494 4.3 警告 eSyndiCat - eSyndiCat Pro の admin/controller.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-5177 2012-09-21 15:27 2012-09-20 Show GitHub Exploit DB Packet Storm
240495 5 警告 WizOne Solutions - Drupal 用 Fill PDF モジュールにおける任意の PDF ファイルを書かれる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-5007 2012-09-21 15:01 2012-01-4 Show GitHub Exploit DB Packet Storm
240496 6.8 警告 Database Publishing Consultants - Drupal 用 Admin:hover モジュールにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2012-1631 2012-09-21 15:01 2012-01-11 Show GitHub Exploit DB Packet Storm
240497 2.1 注意 Nestor Mata Cuthbert - Drupal 用 Taxonomy Navigator モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-1630 2012-09-21 15:00 2012-01-11 Show GitHub Exploit DB Packet Storm
240498 2.1 注意 Dmitry Loac - Drupal 用 Taxotouch モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-1629 2012-09-21 15:00 2012-01-11 Show GitHub Exploit DB Packet Storm
240499 3.5 注意 63reasons - Drupal 用 SuperCron モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-1628 2012-09-21 14:59 2012-01-11 Show GitHub Exploit DB Packet Storm
240500 6 警告 Karen Stevenson - Drupal 用 Date モジュールのイベントの変更フォームにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2012-1626 2012-09-21 14:59 2012-01-11 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 21, 2026, 4:10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
268081 5.5 MEDIUM
Local
huawei p8_firmware The graphics driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-… CWE-399
 Resource Management Errors
CVE-2016-1496 2024-11-21 11:46 2016-04-13 Show GitHub Exploit DB Packet Storm
268082 7.8 HIGH
Local
huawei mate_s_firmware Integer overflow in the graphics drivers in Huawei Mate S smartphones with software CRR-TL00 before CRR-TL00C01B160SP01, CRR-UL00 before CRR-UL00C00B160, and CRR-CL00 before CRR-CL00C92B161 allows at… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2016-1495 2024-11-21 11:46 2016-04-13 Show GitHub Exploit DB Packet Storm
268083 6.1 MEDIUM
Network
cisco unity_connection Cross-site scripting (XSS) vulnerability in Cisco Unity Connection through 11.0 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCus21776. CWE-79
Cross-site Scripting
CVE-2016-1377 2024-11-21 11:46 2016-04-13 Show GitHub Exploit DB Packet Storm
268084 5.3 MEDIUM
Network
cisco ios_xr Cisco IOS XR 4.2.3, 4.3.0, 4.3.4, and 5.3.1 on ASR 9000 devices allows remote attackers to cause a denial of service (CRC and symbol errors, and interface flap) via crafted bit patterns in packets, a… CWE-20
 Improper Input Validation 
CVE-2016-1376 2024-11-21 11:46 2016-04-13 Show GitHub Exploit DB Packet Storm
268085 8.8 HIGH
Local
qemu
redhat
debian
qemu
openstack
virtualization
debian_linux
Use-after-free vulnerability in hw/ide/ahci.c in QEMU, when built with IDE AHCI Emulation support, allows guest OS users to cause a denial of service (instance crash) or possibly execute arbitrary co… CWE-416
 Use After Free
CVE-2016-1568 2024-11-21 11:46 2016-04-12 Show GitHub Exploit DB Packet Storm
268086 8.8 HIGH
Network
oar_project
debian
oar
debian_linux
The oarsh script in OAR before 2.5.7 allows remote authenticated users of a cluster to obtain sensitive information and possibly gain privileges via vectors related to OpenSSH options. CWE-264
Permissions, Privileges, and Access Controls
CVE-2016-1235 2024-11-21 11:46 2016-04-12 Show GitHub Exploit DB Packet Storm
268087 6.1 MEDIUM
Network
cisco ip_interoperability_and_collaboration_system Cross-site scripting (XSS) vulnerability in Cisco IP Interoperability and Collaboration System 4.10(1) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSC… CWE-79
Cross-site Scripting
CVE-2016-1375 2024-11-21 11:46 2016-04-9 Show GitHub Exploit DB Packet Storm
268088 7.0 HIGH
Local
exim exim Exim before 4.86.2, when installed setuid root, allows local users to gain privileges via the perl_startup argument. CWE-264
Permissions, Privileges, and Access Controls
CVE-2016-1531 2024-11-21 11:46 2016-04-8 Show GitHub Exploit DB Packet Storm
268089 8.1 HIGH
Local
redhat
oracle
qemu
openstack
linux
qemu
The (1) fw_cfg_write and (2) fw_cfg_read functions in hw/nvram/fw_cfg.c in QEMU before 2.4, when built with the Firmware Configuration device emulation support, allow guest OS users with the CAP_SYS_… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2016-1714 2024-11-21 11:46 2016-04-8 Show GitHub Exploit DB Packet Storm
268090 6.8 MEDIUM
Network
netapp clustered_data_ontap NetApp Clustered Data ONTAP 8.3.1 does not properly verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafte… CWE-200
CWE-20
Information Exposure
 Improper Input Validation 
CVE-2016-1563 2024-11-21 11:46 2016-04-7 Show GitHub Exploit DB Packet Storm