Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 24, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
240511 2.6 注意 jake olefsky - Fotopholder の index.php におけるディレクトリトラバーサルの脆弱性 - CVE-2006-4259 2012-09-25 15:35 2006-08-21 Show GitHub Exploit DB Packet Storm
240512 4 警告 john hanna - ASSP の get 機能における絶対パストラバーサルの脆弱性 - CVE-2006-4258 2012-09-25 15:35 2006-08-21 Show GitHub Exploit DB Packet Storm
240513 4 警告 IBM - IBM DB2 UDB におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2006-4257 2012-09-25 15:35 2006-08-21 Show GitHub Exploit DB Packet Storm
240514 4.3 警告 Horde - Horde Application Framework における他のサイトから Web ページをインクルードされる脆弱性 - CVE-2006-4256 2012-09-25 15:35 2006-08-21 Show GitHub Exploit DB Packet Storm
240515 4.3 警告 Horde - Horde IMP H3 の horde/imp/search.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-4255 2012-09-25 15:35 2006-08-21 Show GitHub Exploit DB Packet Storm
240516 5.1 警告 Joomla! - Joomla または Mambo 用の JIM コンポーネントにおける PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-4242 2012-09-25 15:35 2006-08-21 Show GitHub Exploit DB Packet Storm
240517 7.5 危険 mamboxchange - Reporter Mambo コンポーネントにおける PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-4241 2012-09-25 15:35 2006-08-21 Show GitHub Exploit DB Packet Storm
240518 7.5 危険 outreach project tool - OPT Max の include/urights.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-4239 2012-09-25 15:35 2006-08-21 Show GitHub Exploit DB Packet Storm
240519 7.5 危険 invisionix systems - IRSR の pageheaderdefault.inc.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-4237 2012-09-25 15:35 2006-08-21 Show GitHub Exploit DB Packet Storm
240520 2.6 注意 Irfan Skiljan - プラグインを持つ IrfanView におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2006-4231 2012-09-25 15:35 2006-08-18 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 25, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
266871 4.3 MEDIUM
Network
ibm rational_rhapsody_design_manager
rational_software_architect_design_manager
rational_quality_manager
rational_team_concert
rational_doors_next_generation
rational_engineering_lifecycle…
An undisclosed vulnerability in CLM applications may result in some administrative deployment parameters being shown to an attacker. CWE-200
Information Exposure
CVE-2016-2987 2024-11-21 11:49 2017-02-2 Show GitHub Exploit DB Packet Storm
266872 6.1 MEDIUM
Network
ibm inotes
domino
IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cred… CWE-79
Cross-site Scripting
CVE-2016-2939 2024-11-21 11:49 2017-02-2 Show GitHub Exploit DB Packet Storm
266873 6.1 MEDIUM
Network
ibm inotes
domino
IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cred… CWE-79
Cross-site Scripting
CVE-2016-2938 2024-11-21 11:49 2017-02-2 Show GitHub Exploit DB Packet Storm
266874 9.1 CRITICAL
Network
ibm security_access_manager_9.0_firmware
security_access_manager_for_mobile_8.0_firmware
security_access_manager_for_web_8.0_firmware
IBM Single Sign On for Bluemix could allow a remote attacker to obtain sensitive information, caused by a XML external entity (XXE) error when processing XML data by the XML parser. A remote attacker… CWE-611
XXE
CVE-2016-2908 2024-11-21 11:49 2017-02-2 Show GitHub Exploit DB Packet Storm
266875 5.6 MEDIUM
Network
saltstack salt Salt before 2015.5.10 and 2015.8.x before 2015.8.8, when PAM external authentication is enabled, allows attackers to bypass the configured authentication service by passing an alternate service with … CWE-287
Improper Authentication
CVE-2016-3176 2024-11-21 11:49 2017-02-1 Show GitHub Exploit DB Packet Storm
266876 9.8 CRITICAL
Network
giflib_project giflib Multiple use-after-free and double-free vulnerabilities in gifcolor.c in GIFLIB 5.1.2 have unspecified impact and attack vectors. CWE-415
CWE-416
 Double Free
 Use After Free
CVE-2016-3177 2024-11-21 11:49 2017-01-24 Show GitHub Exploit DB Packet Storm
266877 9.8 CRITICAL
Network
ivanti landesk_management_suite Buffer overflow in the collector.exe listener of the Landesk Management Suite 10.0.0.271 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a lar… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2016-3147 2024-11-21 11:49 2017-01-24 Show GitHub Exploit DB Packet Storm
266878 9.1 CRITICAL
Network
synacor zimbra_collaboration_suite Zimbra Collaboration before 8.7.0 allows remote attackers to conduct deserialization attacks via unspecified vectors, aka bug 102276. CWE-502
 Deserialization of Untrusted Data
CVE-2016-3415 2024-11-21 11:49 2017-01-19 Show GitHub Exploit DB Packet Storm
266879 6.5 MEDIUM
Network
synacor zimbra_collaboration_suite Unspecified vulnerability in Zimbra Collaboration before 8.6.0 Patch 7 allows remote authenticated users to affect availability via unknown vectors, aka bug 102029. NVD-CWE-noinfo
CVE-2016-3414 2024-11-21 11:49 2017-01-19 Show GitHub Exploit DB Packet Storm
266880 7.5 HIGH
Network
synacor zimbra_collaboration_suite Unspecified vulnerability in Zimbra Collaboration before 8.7.0 allows remote attackers to affect integrity via unknown vectors, aka bug 103996. NVD-CWE-noinfo
CVE-2016-3413 2024-11-21 11:49 2017-01-19 Show GitHub Exploit DB Packet Storm