Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 27, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
240651 6.8 警告 Joomla! - Joomla! における脆弱性 - CVE-2006-4468 2012-09-25 15:35 2006-08-28 Show GitHub Exploit DB Packet Storm
240652 5 警告 Joomla! - Joomla! における脆弱性 CWE-20
不適切な入力確認
CVE-2006-4466 2012-09-25 15:35 2006-08-31 Show GitHub Exploit DB Packet Storm
240653 5 警告 ノキア - Nokia Browser などにおけるサービス運用妨害 (DoS) の脆弱性 - CVE-2006-4464 2012-09-25 15:35 2006-08-31 Show GitHub Exploit DB Packet Storm
240654 7.5 危険 jetstat.com - Jetstat.com JS ASP Faq Manager の管理者コントロールパネルにおける SQL インジェクションの脆弱性 - CVE-2006-4463 2012-09-25 15:35 2006-08-31 Show GitHub Exploit DB Packet Storm
240655 10 危険 Paessler AG - Paessler IPCheck Server Monitor における脆弱性 - CVE-2006-4461 2012-09-25 15:35 2006-08-31 Show GitHub Exploit DB Packet Storm
240656 4.3 警告 hlstats - HLstats の hlstats.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-4454 2012-09-25 15:35 2006-08-30 Show GitHub Exploit DB Packet Storm
240657 5.1 警告 mybulletinboard - MyBB の attachment.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-4449 2012-09-25 15:35 2006-08-29 Show GitHub Exploit DB Packet Storm
240658 5.1 警告 interact learning community environment - interact における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-4448 2012-09-25 15:35 2006-08-29 Show GitHub Exploit DB Packet Storm
240659 5 警告 OpenBSD - OpenBSD の isakmpd における再生保護を回避される脆弱性 - CVE-2006-4436 2012-09-25 15:35 2006-08-25 Show GitHub Exploit DB Packet Storm
240660 4.9 警告 OpenBSD - OpenBSD におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2006-4435 2012-09-25 15:35 2006-08-25 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 27, 2026, 4:52 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
266901 8.8 HIGH
Network
opensuse
debian
optipng_project
canonical
leap
opensuse
debian_linux
optipng
ubuntu_linux
Off-by-one error in the bmp_rle4_fread function in pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (out-of-bounds read or write access and crash) or possibly e… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2016-3982 2024-11-21 11:51 2016-04-14 Show GitHub Exploit DB Packet Storm
266902 7.8 HIGH
Local
optipng_project
canonical
debian
optipng
ubuntu_linux
debian_linux
Heap-based buffer overflow in the bmp_read_rows function in pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (out-of-bounds read or write access and crash) or p… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2016-3981 2024-11-21 11:51 2016-04-14 Show GitHub Exploit DB Packet Storm
266903 9.8 CRITICAL
Network
opensuse leap
opensuse
Multiple unspecified vulnerabilities in the obs-service-extract_file package before 0.3-5.1 in openSUSE Leap 42.1 and before 0.3-3.1 in openSUSE 13.2 allow attackers to execute arbitrary commands via… NVD-CWE-noinfo
CVE-2016-4007 2024-11-21 11:51 2016-04-13 Show GitHub Exploit DB Packet Storm
266904 4.9 MEDIUM
Network
dell openmanage_server_administrator Directory traversal vulnerability in Dell OpenManage Server Administrator (OMSA) 8.2 allows remote authenticated administrators to read arbitrary files via a ..\ (dot dot backslash) in the file param… CWE-22
Path Traversal
CVE-2016-4004 2024-11-21 11:51 2016-04-13 Show GitHub Exploit DB Packet Storm
266905 6.1 MEDIUM
Network
apache struts Cross-site scripting (XSS) vulnerability in the URLDecoder function in JRE before 1.8, as used in Apache Struts 2.x before 2.3.28, when using a single byte page encoding, allows remote attackers to i… CWE-79
Cross-site Scripting
CVE-2016-4003 2024-11-21 11:51 2016-04-13 Show GitHub Exploit DB Packet Storm
266906 9.8 CRITICAL
Network
trendmicro password_manager The HTTP server in Trend Micro Password Manager allows remote web servers to execute arbitrary commands via the url parameter to (1) api/openUrlInDefaultBrowser or (2) api/showSB. CWE-284
Improper Access Control
CVE-2016-3987 2024-11-21 11:51 2016-04-12 Show GitHub Exploit DB Packet Storm
266907 7.8 HIGH
Local
avast avast Avast allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a crafted PE file, related to authenticode parsing. CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2016-3986 2024-11-21 11:51 2016-04-12 Show GitHub Exploit DB Packet Storm
266908 6.5 MEDIUM
Network
pulsesecure pulse_connect_secure The Terminal Services Remote Desktop Protocol (RDP) client session restrictions feature in Pulse Connect Secure (aka PCS) 8.1R7 and 8.2R1 allow remote authenticated users to bypass intended access re… CWE-284
Improper Access Control
CVE-2016-3985 2024-11-21 11:51 2016-04-12 Show GitHub Exploit DB Packet Storm
266909 5.1 MEDIUM
Local
mcafee data_loss_prevention_endpoint
agent
virusscan_enterprise
host_intrusion_prevention
active_response
data_exchange_layer
endpoint_security
The McAfee VirusScan Console (mcconsol.exe) in McAfee Active Response (MAR) before 1.1.0.161, Agent (MA) 5.x before 5.0.2 Hotfix 1110392 (5.0.2.333), Data Exchange Layer 2.x (DXL) before 2.0.1.140.1,… CWE-284
Improper Access Control
CVE-2016-3984 2024-11-21 11:51 2016-04-9 Show GitHub Exploit DB Packet Storm
266910 7.5 HIGH
Network
mcafee advanced_threat_defense McAfee Advanced Threat Defense (ATD) before 3.4.8.178 might allow remote attackers to bypass malware detection by leveraging information about the parent process. CWE-345
 Insufficient Verification of Data Authenticity
CVE-2016-3983 2024-11-21 11:51 2016-04-9 Show GitHub Exploit DB Packet Storm