Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 6, 2026, noon

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
241211 6.5 警告 Hastymail - Hastymail における任意の SMTP コマンドを送信される脆弱性 CWE-20
不適切な入力確認
CVE-2006-5313 2012-09-25 15:36 2006-10-17 Show GitHub Exploit DB Packet Storm
241212 6.8 警告 j-pierre dezelus
phpmyconferences
- J-Pierre DEZELUS Les Visiteursにおける PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2006-5310 2012-09-25 15:36 2006-10-17 Show GitHub Exploit DB Packet Storm
241213 7.5 危険 open conference systems - OCS における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-5308 2012-09-25 15:36 2006-10-17 Show GitHub Exploit DB Packet Storm
241214 7.5 危険 inccms technology - IncCMS Core の inc/settings.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-5304 2012-09-25 15:36 2006-10-17 Show GitHub Exploit DB Packet Storm
241215 6.5 警告 ヒューレット・パッカード - HP Version Control Agent における権限を取得される脆弱性 - CVE-2006-5300 2012-09-25 15:36 2006-10-17 Show GitHub Exploit DB Packet Storm
241216 1.2 注意 Mutt - Mutt mail client の mutt_adv_mktemp 関数におけるファイルを作成される脆弱性 - CVE-2006-5298 2012-09-25 15:36 2006-10-16 Show GitHub Exploit DB Packet Storm
241217 4.3 警告 マイクロソフト - Microsoft Office 2003 の PowerPoint におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2006-5296 2012-09-25 15:36 2006-10-16 Show GitHub Exploit DB Packet Storm
241218 5 警告 Novell - Novell BorderManager の IKE.NLM におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2006-5286 2012-09-25 15:36 2006-10-13 Show GitHub Exploit DB Packet Storm
241219 5.1 警告 php news reader - Shen Cheng-Da PHP News Reader の auth/phpbb.inc.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-5284 2012-09-25 15:36 2006-10-13 Show GitHub Exploit DB Packet Storm
241220 7.5 危険 minichat - Minichat の ftag.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-5283 2012-09-25 15:36 2006-10-13 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 6, 2026, 4:18 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
265921 4.7 MEDIUM
Network
wordpress wordpress WordPress through 4.8.2, when domain-based flashmediaelement.swf sandboxing is not used, allows remote attackers to conduct cross-domain Flash injection (XSF) attacks by leveraging code contained wit… CWE-20
 Improper Input Validation 
CVE-2016-9263 2024-11-21 12:00 2017-10-13 Show GitHub Exploit DB Packet Storm
265922 9.8 CRITICAL
Network
ibm tivoli_storage_manager The IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) default authentication protocol is vulnerable to a brute force attack due to disclosing too much information during authentication. A… CWE-287
Improper Authentication
CVE-2016-8937 2024-11-21 12:00 2017-10-6 Show GitHub Exploit DB Packet Storm
265923 5.4 MEDIUM
Network
ibm emptoris_strategic_supply_management
emptoris_supplier_lifecycle_management
IBM Emptoris Supplier Lifecycle Management 10.0.x and 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-craf… CWE-601
Open Redirect
CVE-2016-8949 2024-11-21 12:00 2017-08-10 Show GitHub Exploit DB Packet Storm
265924 5.4 MEDIUM
Network
ibm rhapsody_design_manager IBM Rhapsody DM 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentiall… CWE-79
Cross-site Scripting
CVE-2016-8975 2024-11-21 12:00 2017-07-25 Show GitHub Exploit DB Packet Storm
265925 9.8 CRITICAL
Network
ibm license_metric_tool
bigfix_inventory
IBM BigFix Inventory v9 9.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 118853. CWE-200
CWE-254
Information Exposure
 7PK - Security Features
CVE-2016-8964 2024-11-21 12:00 2017-07-14 Show GitHub Exploit DB Packet Storm
265926 5.4 MEDIUM
Network
ibm emptoris_strategic_supply_management IBM Emptoris Strategic Supply Management Platform 10.0.0.x through 10.1.1.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thu… CWE-79
Cross-site Scripting
CVE-2016-8952 2024-11-21 12:00 2017-07-14 Show GitHub Exploit DB Packet Storm
265927 7.5 HIGH
Network
ibm emptoris_strategic_supply_management IBM Emptoris Strategic Supply Management Platform 10.0.0.x through 10.1.1.x is vulnerable to a denial of service attack. An attacker can exploit a vulnerability in the authentication features that co… CWE-287
Improper Authentication
CVE-2016-8951 2024-11-21 12:00 2017-07-14 Show GitHub Exploit DB Packet Storm
265928 5.4 MEDIUM
Network
ibm emptoris_sourcing IBM Emptoris Sourcing 9.5.x through 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a re… CWE-601
Open Redirect
CVE-2016-8953 2024-11-21 12:00 2017-07-13 Show GitHub Exploit DB Packet Storm
265929 5.4 MEDIUM
Network
ibm emptoris_sourcing IBM Emptoris Sourcing 9.5.x through 10.1.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functiona… CWE-79
Cross-site Scripting
CVE-2016-8950 2024-11-21 12:00 2017-07-13 Show GitHub Exploit DB Packet Storm
265930 5.4 MEDIUM
Network
ibm emptoris_sourcing IBM Emptoris Sourcing 9.5.x through 10.1.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functiona… CWE-79
Cross-site Scripting
CVE-2016-8948 2024-11-21 12:00 2017-07-13 Show GitHub Exploit DB Packet Storm