Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 21, 2026, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
240591 7.5 危険 デル - SonicWall ViewPoint における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2011-5169 2012-09-19 16:03 2011-09-26 Show GitHub Exploit DB Packet Storm
240592 7.5 危険 Banana Dance - Banana Dance の user.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2011-5168 2012-09-19 16:01 2011-10-2 Show GitHub Exploit DB Packet Storm
240593 9.3 危険 オラクル
Tidestone
- Oracle Formula One ActiveX コントロールにおけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2011-5167 2012-09-19 16:00 2012-09-15 Show GitHub Exploit DB Packet Storm
240594 7.5 危険 Elif Keir - KnFTP におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2011-5166 2012-09-19 15:59 2012-09-15 Show GitHub Exploit DB Packet Storm
240595 9.3 危険 Cleanersoft Software - Free MP3 CD Ripper におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2011-5165 2012-09-19 15:57 2012-09-15 Show GitHub Exploit DB Packet Storm
240596 9.3 危険 VanDyke Software - VanDyke Software AbsoluteFTP におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2011-5164 2012-09-19 15:56 2012-09-15 Show GitHub Exploit DB Packet Storm
240597 4.6 警告 Schneider Electric
三菱電機
- Schneider Electric CitectSCADA および Mitsubishi MX4 SCADA 用 Batch モジュールにおけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2011-5163 2012-09-19 15:54 2011-11-8 Show GitHub Exploit DB Packet Storm
240598 9.3 危険 Gretech - GOM Player におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2011-5162 2012-09-19 15:40 2012-09-15 Show GitHub Exploit DB Packet Storm
240599 3.5 注意 WordPress.org - WordPress の wp-admin/plugins.php におけるプラグインを変更される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-4422 2012-09-19 11:24 2012-09-6 Show GitHub Exploit DB Packet Storm
240600 4 警告 WordPress.org - WordPress の wp-includes/class-wp-atom-server.php におけるアクセス制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-4421 2012-09-19 11:24 2012-09-6 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 21, 2026, 4:10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
266941 7.3 HIGH
Network
prepopulate_project prepopulate The _prepopulate_request_walk function in the Prepopulate module 7.x-2.x before 7.x-2.1 for Drupal allows remote attackers to modify the (1) actions, (2) container, (3) token, (4) password, (5) passw… CWE-264
Permissions, Privileges, and Access Controls
CVE-2016-3188 2024-11-21 11:49 2016-04-8 Show GitHub Exploit DB Packet Storm
266942 7.3 HIGH
Network
prepopulate_project prepopulate The Prepopulate module 7.x-2.x before 7.x-2.1 for Drupal allows remote attackers to modify the REQUEST superglobal array, and consequently have unspecified impact, via a base64-encoded pp parameter. CWE-264
Permissions, Privileges, and Access Controls
CVE-2016-3187 2024-11-21 11:49 2016-04-8 Show GitHub Exploit DB Packet Storm
266943 9.8 CRITICAL
Network
spip spip The encoder_contexte_ajax function in ecrire/inc/filtres.php in SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows remote attackers to conduct PHP object injection attacks and… CWE-94
Code Injection
CVE-2016-3154 2024-11-21 11:49 2016-04-8 Show GitHub Exploit DB Packet Storm
266944 9.8 CRITICAL
Network
debian
spip
debian_linux
spip
SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows remote attackers to execute arbitrary PHP code by adding content, related to the filtrer_entites function. CWE-94
Code Injection
CVE-2016-3153 2024-11-21 11:49 2016-04-8 Show GitHub Exploit DB Packet Storm
266945 6.5 MEDIUM
Network
broadcom api_gateway CRLF injection vulnerability in CA API Gateway (formerly Layer7 API Gateway) 7.1 before 7.1.04, 8.0 through 8.3 before 8.3.01, and 8.4 before 8.4.01 allows remote attackers to have an unspecified imp… NVD-CWE-Other
CVE-2016-3118 2024-11-21 11:49 2016-04-6 Show GitHub Exploit DB Packet Storm
266946 7.5 HIGH
Network
proftpd
opensuse
fedoraproject
proftpd
opensuse
fedora
The mod_tls module in ProFTPD before 1.3.5b and 1.3.6 before 1.3.6rc2 does not properly handle the TLSDHParamFile directive, which might cause a weaker than intended Diffie-Hellman (DH) key to be use… CWE-310
CWE-254
Cryptographic Issues
 7PK - Security Features
CVE-2016-3125 2024-11-21 11:49 2016-04-6 Show GitHub Exploit DB Packet Storm
266947 8.2 HIGH
Network
php
apple
php
mac_os_x
The phar_parse_zipfile function in zip.c in the PHAR extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to obtain sensitive information from process memory or cause a deni… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2016-3142 2024-11-21 11:49 2016-04-1 Show GitHub Exploit DB Packet Storm
266948 9.8 CRITICAL
Network
apple
php
mac_os_x
php
Use-after-free vulnerability in wddx.c in the WDDX extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to cause a denial of service (memory corruption and application crash… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2016-3141 2024-11-21 11:49 2016-04-1 Show GitHub Exploit DB Packet Storm
266949 5.3 MEDIUM
Network
opensuse
mit
leap
opensuse
kerberos_5
The process_db_args function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in the LDAP KDB module in kadmind in MIT Kerberos 5 (aka krb5) through 1.13.4 and 1.14.x through 1.14.1 mishandles the D… NVD-CWE-Other
CVE-2016-3119 2024-11-21 11:49 2016-03-26 Show GitHub Exploit DB Packet Storm
266950 6.4 MEDIUM
Network
dropbear_ssh_project dropbear_ssh CRLF injection vulnerability in Dropbear SSH before 2016.72 allows remote authenticated users to bypass intended shell-command restrictions via crafted X11 forwarding data. NVD-CWE-Other
CVE-2016-3116 2024-11-21 11:49 2016-03-22 Show GitHub Exploit DB Packet Storm