Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 12, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
241491 4.3 警告 Drupal
chris shattuck
- Drupal の Ajax Table モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-3121 2012-06-26 16:18 2009-08-26 Show GitHub Exploit DB Packet Storm
241492 4.3 警告 BIGACE - BIGACE Web CMS の public/index.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-3120 2012-06-26 16:18 2009-09-9 Show GitHub Exploit DB Packet Storm
241493 7.5 危険 danneo - Danneo CMS の mod/poll/comment.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-3118 2012-06-26 16:18 2009-09-9 Show GitHub Exploit DB Packet Storm
241494 10 危険 ASUSTeK Computer Inc. - ASUS WL-500W 無線ルータにおける詳細不明な脆弱性 CWE-noinfo
情報不足
CVE-2009-3093 2012-06-26 16:18 2009-09-8 Show GitHub Exploit DB Packet Storm
241495 10 危険 ASUSTeK Computer Inc. - ASUS WL-500W 無線ルータにおけるバッファオーバーフローの脆弱性 CWE-noinfo
情報不足
CVE-2009-3092 2012-06-26 16:18 2009-09-8 Show GitHub Exploit DB Packet Storm
241496 10 危険 ASUSTeK Computer Inc. - ASUS WL-330gE における詳細不明な脆弱性 CWE-noinfo
情報不足
CVE-2009-3091 2012-06-26 16:18 2009-09-8 Show GitHub Exploit DB Packet Storm
241497 7.5 危険 alqa6ari - Alqatari Q R Script の lesson.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-3061 2012-06-26 16:18 2009-09-3 Show GitHub Exploit DB Packet Storm
241498 4.3 警告 allpublication - Joker Board におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-3060 2012-06-26 16:18 2009-09-3 Show GitHub Exploit DB Packet Storm
241499 7.5 危険 allpublication - Joker Board における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-3059 2012-06-26 16:18 2009-09-3 Show GitHub Exploit DB Packet Storm
241500 9.3 危険 aksoft - akPlayer におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-3058 2012-06-26 16:18 2009-09-3 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 13, 2026, 5:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
268501 3.1 LOW
Network
ibm websphere_mq IBM WebSphere MQ 7.5 before 7.5.0.7 and 8.0 before 8.0.0.5 mishandles protocol flows, which allows remote authenticated users to cause a denial of service (channel outage) by leveraging queue-manager… CWE-19
 Data Processing Errors
CVE-2016-0379 2024-11-21 11:41 2016-09-26 Show GitHub Exploit DB Packet Storm
268502 3.7 LOW
Network
ibm security_guardium IBM Security Guardium 9.0 before p700 and 10.0 before p100 allows man-in-the-middle attackers to obtain sensitive query-string information from SSL sessions via unspecified vectors. CWE-200
Information Exposure
CVE-2016-0248 2024-11-21 11:41 2016-09-26 Show GitHub Exploit DB Packet Storm
268503 6.5 MEDIUM
Network
microsoft office The Visual Basic macros in Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2016 export a certificate-store private key during a document-save operation, which allows attackers to obtain sensitive … CWE-200
Information Exposure
CVE-2016-0141 2024-11-21 11:41 2016-09-14 Show GitHub Exploit DB Packet Storm
268504 4.3 MEDIUM
Network
microsoft exchange_server Microsoft Exchange Server 2007 SP3, 2010 SP3, 2013 SP1, 2013 Cumulative Update 12, 2013 Cumulative Update 13, 2016 Cumulative Update 1, and 2016 Cumulative Update 2 misparses e-mail messages, which a… CWE-200
Information Exposure
CVE-2016-0138 2024-11-21 11:41 2016-09-14 Show GitHub Exploit DB Packet Storm
268505 3.3 LOW
Local
microsoft office The Click-to-Run (C2R) implementation in Microsoft Office 2013 SP1 and 2016 allows local users to bypass the ASLR protection mechanism via a crafted application, aka "Microsoft APP-V ASLR Bypass." CWE-254
 7PK - Security Features
CVE-2016-0137 2024-11-21 11:41 2016-09-14 Show GitHub Exploit DB Packet Storm
268506 5.4 MEDIUM
Network
ibm rational_team_concert
rational_collaborative_lifecycle_management
Cross-site scripting (XSS) vulnerability in IBM Rational Team Concert 6.0.1 and 6.0.2 before 6.0.2 iFix2 and Rational Collaborative Lifecycle Management 6.0.1 and 6.0.2 before 6.0.2 iFix2 allows remo… CWE-79
Cross-site Scripting
CVE-2016-0331 2024-11-21 11:41 2016-09-12 Show GitHub Exploit DB Packet Storm
268507 3.1 LOW
Network
ibm websphere_application_server Buffer overflow in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.43, 8.0 before 8.0.0.13, 8.5 before 8.5.5.10, 9.0 before 9.0.0.1, and Liberty before 16.0.0.3, when HttpSessionIdReuse is en… CWE-119
CWE-200
Incorrect Access of Indexable Resource ('Range Error') 
Information Exposure
CVE-2016-0385 2024-11-21 11:41 2016-09-1 Show GitHub Exploit DB Packet Storm
268508 2.7 LOW
Network
ibm forms_experience_builder Cross-site scripting (XSS) vulnerability in IBM Forms Experience Builder 8.5.x and 8.6.x before 8.6.3 allows remote authenticated users to inject arbitrary web script or HTML via crafted input to an … CWE-79
Cross-site Scripting
CVE-2016-0370 2024-11-21 11:41 2016-09-1 Show GitHub Exploit DB Packet Storm
268509 6.1 MEDIUM
Network
ibm bigfix_platform Cross-site scripting (XSS) vulnerability in IBM BigFix Platform (formerly Tivoli Endpoint Manager) 9.x before 9.1.8 and 9.2.x before 9.2.8 allows remote attackers to inject arbitrary web script or HT… CWE-79
Cross-site Scripting
CVE-2016-0293 2024-11-21 11:41 2016-09-1 Show GitHub Exploit DB Packet Storm
268510 5.9 MEDIUM
Network
ibm bigfix_webreports WebReports in IBM BigFix Platform (formerly Tivoli Endpoint Manager) 9.x before 9.5.2 allows remote attackers to obtain sensitive information by sniffing the network for HTTP traffic. CWE-200
Information Exposure
CVE-2016-0397 2024-11-21 11:41 2016-08-31 Show GitHub Exploit DB Packet Storm