Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 1, 2026, 2:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
240561 7.5 危険 phil taylor - Mambo 用の shambo2 コンポーネントにおける PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-6049 2012-09-25 15:36 2006-11-21 Show GitHub Exploit DB Packet Storm
240562 6.8 警告 Oliver - Oliver の loginform-inc.php における任意の PHP コードを実行される脆弱性 - CVE-2006-6043 2012-09-25 15:36 2006-11-21 Show GitHub Exploit DB Packet Storm
240563 7.5 危険 laurent van den reysen - Laurent Van den Reysen WORK system e-commerce における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2006-6041 2012-09-25 15:36 2006-11-21 Show GitHub Exploit DB Packet Storm
240564 6.8 警告 vBulletin Solutions, Inc. - Jelsoft vBulletin の admincp/index.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-6040 2012-09-25 15:36 2006-11-21 Show GitHub Exploit DB Packet Storm
240565 6.8 警告 leinir - Dan Jensen Travelsized CMS の index.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-6037 2012-09-25 15:36 2006-11-21 Show GitHub Exploit DB Packet Storm
240566 7.2 危険 NetBSD - NetBSD カーネルにおける脆弱性 - CVE-2006-6014 2012-09-25 15:36 2006-11-21 Show GitHub Exploit DB Packet Storm
240567 4.3 警告 mginternet - MGinternet CSM の csm/asp/listings.asp におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-6012 2012-09-25 15:36 2006-11-21 Show GitHub Exploit DB Packet Storm
240568 6.5 警告 Netkit - Linux Netkit の ftpd における権限を取得される脆弱性 - CVE-2006-6008 2012-09-25 15:36 2006-11-10 Show GitHub Exploit DB Packet Storm
240569 5 警告 マイクロソフト - Active Directory が稼動している Windows 2000 Advanced Server SP4 におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2006-5988 2012-09-25 15:36 2006-11-20 Show GitHub Exploit DB Packet Storm
240570 6 警告 JBMC Software - JBMC Software DirectAdmin におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-5983 2012-09-25 15:36 2006-11-20 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 1, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
266451 6.5 MEDIUM
Network
huawei fusioncompute Huawei FusionCompute before V100R005C10CP7002 stores cleartext AES keys in a file, which allows remote authenticated users to obtain sensitive information via unspecified vectors. CWE-200
Information Exposure
CVE-2016-6827 2024-11-21 11:56 2016-09-27 Show GitHub Exploit DB Packet Storm
266452 6.5 MEDIUM
Network
huawei anyoffice_secureapp Huawei AnyMail before 2.6.0301.0060 allows remote attackers to cause a denial of service (application crash) via a crafted compressed email attachment. CWE-284
Improper Access Control
CVE-2016-6826 2024-11-21 11:56 2016-09-27 Show GitHub Exploit DB Packet Storm
266453 7.5 HIGH
Network
huawei s5300_firmware
s12700_firmware
s6300_firmware
s7700_firmware
s5700_firmware
s6700_firmware
s9700_firmware
s9300_firmware
Memory leak in Huawei S9300, S5300, S5700, S6700, S7700, S9700, and S12700 devices allows remote attackers to cause a denial of service (memory consumption and restart) via a large number of malforme… CWE-399
 Resource Management Errors
CVE-2016-6518 2024-11-21 11:56 2016-09-27 Show GitHub Exploit DB Packet Storm
266454 6.1 MEDIUM
Network
huawei oceanstor_ism Cross-site scripting (XSS) vulnerability in the management interface in Huawei OceanStor ISM before V200R001C04SPC200 allows remote attackers to inject arbitrary web script or HTML via the loginName … CWE-79
Cross-site Scripting
CVE-2016-6840 2024-11-21 11:56 2016-09-26 Show GitHub Exploit DB Packet Storm
266455 9.8 CRITICAL
Network
dexis imaging_suite DEXIS Imaging Suite 10 has a hardcoded password for the sa account, which allows remote attackers to obtain administrative access by entering this password in a DEXIS_DATA SQL Server session. CWE-798
 Use of Hard-coded Credentials
CVE-2016-6532 2024-11-21 11:56 2016-09-24 Show GitHub Exploit DB Packet Storm
266456 9.8 CRITICAL
Network
opendental opendental Open Dental 16.1 and earlier has a hardcoded MySQL root password, which allows remote attackers to obtain administrative access by leveraging access to intranet TCP port 3306. NOTE: the vendor dispu… CWE-255
Credentials Management
CVE-2016-6531 2024-11-21 11:56 2016-09-24 Show GitHub Exploit DB Packet Storm
266457 7.8 HIGH
Local
cisco application_policy_infrastructure_controller The installation procedure on Cisco Application Policy Infrastructure Controller (APIC) devices 1.3(2f) mishandles binary files, which allows local users to obtain root access via unspecified vectors… CWE-264
Permissions, Privileges, and Access Controls
CVE-2016-6413 2024-11-21 11:56 2016-09-24 Show GitHub Exploit DB Packet Storm
266458 6.5 MEDIUM
Network
cisco ios The Cisco Application-hosting Framework (CAF) component in Cisco IOS 15.6(1)T1 and IOS XE, when the IOx feature set is enabled, allows man-in-the-middle attackers to trigger arbitrary downloads via c… CWE-20
 Improper Input Validation 
CVE-2016-6412 2024-11-21 11:56 2016-09-24 Show GitHub Exploit DB Packet Storm
266459 7.5 HIGH
Network
cisco firesight_system_software Cisco Firepower Management Center and FireSIGHT System Software 6.0.1 mishandle comparisons between URLs and X.509 certificates, which allows remote attackers to bypass intended do-not-decrypt settin… CWE-20
 Improper Input Validation 
CVE-2016-6411 2024-11-21 11:56 2016-09-24 Show GitHub Exploit DB Packet Storm
266460 6.5 MEDIUM
Network
cisco ios The Cisco Application-hosting Framework (CAF) component in Cisco IOS 15.6(1)T1 and IOS XE, when the IOx feature set is enabled, allows remote authenticated users to read arbitrary files via unspecifi… CWE-20
 Improper Input Validation 
CVE-2016-6410 2024-11-21 11:56 2016-09-24 Show GitHub Exploit DB Packet Storm