Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 20, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
241221 4.3 警告 T-dah - T-dah WebMail におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-2573 2012-08-14 16:34 2012-08-12 Show GitHub Exploit DB Packet Storm
241222 4.3 警告 WinWebMail - WinWebMail Servert におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-2571 2012-08-14 16:33 2012-08-12 Show GitHub Exploit DB Packet Storm
241223 10 危険 Amazon.com, Inc. - Amazon Kindle Touch における任意のコマンドを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2012-4249 2012-08-14 16:31 2012-08-12 Show GitHub Exploit DB Packet Storm
241224 9.3 危険 Amazon.com, Inc. - Amazon Kindle Touch における脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-4248 2012-08-14 16:30 2012-08-12 Show GitHub Exploit DB Packet Storm
241225 7.5 危険 Dir2web - Dir2web における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2012-4070 2012-08-14 16:29 2012-08-12 Show GitHub Exploit DB Packet Storm
241226 5 警告 Dir2web - Dir2web におけるデータベースをダウンロードされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-4069 2012-08-14 16:26 2012-08-12 Show GitHub Exploit DB Packet Storm
241227 4.3 警告 Alt-N - Alt-N MDaemon フリー版におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-2584 2012-08-14 16:22 2012-08-12 Show GitHub Exploit DB Packet Storm
241228 6.4 警告 Caucho Technology - Resin に同梱されている Caucho Quercus におけるファイル名の拡張子による制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-2969 2012-08-14 16:16 2012-08-12 Show GitHub Exploit DB Packet Storm
241229 5 警告 Caucho Technology - Resin に同梱されている Caucho Quercus におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2012-2968 2012-08-14 16:09 2012-08-12 Show GitHub Exploit DB Packet Storm
241230 7.5 危険 Caucho Technology - Resin に同梱されている Caucho Quercus における脆弱性 CWE-Other
その他
CVE-2012-2967 2012-08-14 16:08 2012-08-12 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 21, 2026, 4:10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
266571 2.7 LOW
Network
ibm security_access_manager_9.0_firmware
security_access_manager_for_mobile_8.0_firmware
security_access_manager_for_web_7.0_firmware
security_access_manager_for_web_8.0_firmware
IBM Security Access Manager for Web could allow an authenticated attacker to obtain sensitive information from error message using a specially crafted HTTP request. CWE-200
Information Exposure
CVE-2016-3021 2024-11-21 11:49 2017-02-2 Show GitHub Exploit DB Packet Storm
266572 6.1 MEDIUM
Network
ibm security_access_manager
security_access_manager_for_mobile
security_access_manager_for_web
IBM Security Access Manager for Web is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality po… CWE-79
Cross-site Scripting
CVE-2016-3018 2024-11-21 11:49 2017-02-2 Show GitHub Exploit DB Packet Storm
266573 7.5 HIGH
Network
ibm security_access_manager_9.0_firmware
security_access_manager_for_mobile_8.0_firmware
security_access_manager_for_web_7.0_firmware
security_access_manager_for_web_8.0_firmware
IBM Security Access Manager for Web could allow a remote attacker to obtain sensitive information due to security misconfigurations. CWE-358
 Improperly Implemented Security Check for Standard
CVE-2016-3017 2024-11-21 11:49 2017-02-2 Show GitHub Exploit DB Packet Storm
266574 4.4 MEDIUM
Network
ibm security_access_manager_9.0_firmware
security_access_manager_for_mobile_8.0_firmware
security_access_manager_for_web_7.0_firmware
security_access_manager_for_web_8.0_firmware
IBM Security Access Manager for Web processes patches, image backups and other updates without sufficiently verifying the origin and integrity of the code, which could allow an authenticated attacker… CWE-345
 Insufficient Verification of Data Authenticity
CVE-2016-3016 2024-11-21 11:49 2017-02-2 Show GitHub Exploit DB Packet Storm
266575 4.3 MEDIUM
Network
ibm rational_rhapsody_design_manager
rational_software_architect_design_manager
rational_quality_manager
rational_team_concert
rational_doors_next_generation
rational_engineering_lifecycle…
An undisclosed vulnerability in CLM applications may result in some administrative deployment parameters being shown to an attacker. CWE-200
Information Exposure
CVE-2016-2987 2024-11-21 11:49 2017-02-2 Show GitHub Exploit DB Packet Storm
266576 6.1 MEDIUM
Network
ibm inotes
domino
IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cred… CWE-79
Cross-site Scripting
CVE-2016-2939 2024-11-21 11:49 2017-02-2 Show GitHub Exploit DB Packet Storm
266577 6.1 MEDIUM
Network
ibm inotes
domino
IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cred… CWE-79
Cross-site Scripting
CVE-2016-2938 2024-11-21 11:49 2017-02-2 Show GitHub Exploit DB Packet Storm
266578 9.1 CRITICAL
Network
ibm security_access_manager_9.0_firmware
security_access_manager_for_mobile_8.0_firmware
security_access_manager_for_web_8.0_firmware
IBM Single Sign On for Bluemix could allow a remote attacker to obtain sensitive information, caused by a XML external entity (XXE) error when processing XML data by the XML parser. A remote attacker… CWE-611
XXE
CVE-2016-2908 2024-11-21 11:49 2017-02-2 Show GitHub Exploit DB Packet Storm
266579 5.6 MEDIUM
Network
saltstack salt Salt before 2015.5.10 and 2015.8.x before 2015.8.8, when PAM external authentication is enabled, allows attackers to bypass the configured authentication service by passing an alternate service with … CWE-287
Improper Authentication
CVE-2016-3176 2024-11-21 11:49 2017-02-1 Show GitHub Exploit DB Packet Storm
266580 9.8 CRITICAL
Network
giflib_project giflib Multiple use-after-free and double-free vulnerabilities in gifcolor.c in GIFLIB 5.1.2 have unspecified impact and attack vectors. CWE-415
CWE-416
 Double Free
 Use After Free
CVE-2016-3177 2024-11-21 11:49 2017-01-24 Show GitHub Exploit DB Packet Storm