Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 30, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
242301 7.1 危険 IBM - IBM DB2 の Java ストアドプロシージャのインフラストラクチャにおけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2012-2197 2012-07-26 15:38 2012-06-14 Show GitHub Exploit DB Packet Storm
242302 5 警告 IBM - IBM DB2 における任意の XML ファイルを読まれる脆弱性 CWE-200
情報漏えい
CVE-2012-2196 2012-07-26 15:35 2012-06-14 Show GitHub Exploit DB Packet Storm
242303 5 警告 IBM - IBM DB2 の SQLJ.DB2_INSTALL_JAR ストアドプロシージャにおけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2012-2194 2012-07-26 15:31 2012-06-7 Show GitHub Exploit DB Packet Storm
242304 3.6 注意 Puppet - Puppet および Puppet Enterprise における任意のファイルを上書きされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-1989 2012-07-26 14:07 2012-06-27 Show GitHub Exploit DB Packet Storm
242305 3.5 注意 Puppet - Puppet および Puppet Enterprise におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2012-1987 2012-07-26 13:57 2012-05-29 Show GitHub Exploit DB Packet Storm
242306 10 危険 Google
サムスン
- 複数の製品の Chromebook プラットフォーム上で稼働する Google Chrome OS における脆弱性 CWE-noinfo
情報不足
CVE-2012-4050 2012-07-26 11:57 2012-07-23 Show GitHub Exploit DB Packet Storm
242307 2.1 注意 Puppet - Puppet および Puppet Enterprise における任意のファイルを読まれる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-1986 2012-07-25 17:54 2012-05-29 Show GitHub Exploit DB Packet Storm
242308 5 警告 シマンテック - Symantec Web Gateway の管理コンソールにおける任意のパスワードを変更される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-2977 2012-07-25 16:23 2012-07-20 Show GitHub Exploit DB Packet Storm
242309 7.5 危険 シマンテック - Symantec Web Gateway の管理コンソールにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2012-2961 2012-07-25 16:19 2012-07-20 Show GitHub Exploit DB Packet Storm
242310 7.5 危険 シマンテック - Symantec Web Gateway の管理コンソールにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2012-2574 2012-07-25 15:39 2012-07-20 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 30, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
266311 7.5 HIGH
Network
apache shiro Apache Shiro before 1.3.2 allows attackers to bypass intended servlet filters and gain access by leveraging use of a non-root servlet context path. CWE-284
Improper Access Control
CVE-2016-6802 2024-11-21 11:56 2016-09-21 Show GitHub Exploit DB Packet Storm
266312 9.8 CRITICAL
Network
oracle
percona
mariadb
debian
redhat
mysql
percona_server
mariadb
debian_linux
enterprise_linux_desktop
enterprise_linux_workstation
enterprise_linux
openstack
enterprise_linux_server
enterprise_linux_server_t…
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5.51-38.1, 5.6.x befo… CWE-264
Permissions, Privileges, and Access Controls
CVE-2016-6662 2024-11-21 11:56 2016-09-21 Show GitHub Exploit DB Packet Storm
266313 7.5 HIGH
Network
aver eh6108h\+_firmware AVer Information EH6108H+ devices with firmware X9.03.24.00.07l store passwords in a cleartext base64 format and require cleartext credentials in HTTP Cookie headers, which allows context-dependent a… CWE-200
Information Exposure
CVE-2016-6537 2024-11-21 11:56 2016-09-19 Show GitHub Exploit DB Packet Storm
266314 9.8 CRITICAL
Network
aver eh6108h\+_firmware The /setup URI on AVer Information EH6108H+ devices with firmware X9.03.24.00.07l allows remote attackers to bypass intended page-access restrictions or modify passwords by leveraging knowledge of a … CWE-264
Permissions, Privileges, and Access Controls
CVE-2016-6536 2024-11-21 11:56 2016-09-19 Show GitHub Exploit DB Packet Storm
266315 9.8 CRITICAL
Network
aver eh6108h\+_firmware AVer Information EH6108H+ devices with firmware X9.03.24.00.07l have hardcoded accounts, which allows remote attackers to obtain root access by leveraging knowledge of the credentials and establishin… CWE-798
 Use of Hard-coded Credentials
CVE-2016-6535 2024-11-21 11:56 2016-09-19 Show GitHub Exploit DB Packet Storm
266316 6.5 MEDIUM
Network
cisco fog_director Cisco Fog Director 1.0(0) for IOx allows remote authenticated users to bypass intended access restrictions and write to arbitrary files via the Cartridge interface, aka Bug ID CSCuz89368. CWE-20
 Improper Input Validation 
CVE-2016-6405 2024-11-21 11:56 2016-09-19 Show GitHub Exploit DB Packet Storm
266317 6.1 MEDIUM
Network
cisco ios Cross-site scripting (XSS) vulnerability in the web framework in Cisco IOx Local Manager in IOS 15.5(2)T and IOS XE allows remote attackers to inject arbitrary web script or HTML via a crafted URL, a… CWE-79
Cross-site Scripting
CVE-2016-6404 2024-11-21 11:56 2016-09-19 Show GitHub Exploit DB Packet Storm
266318 5.9 MEDIUM
Network
cisco ios The Data in Motion (DMo) application in Cisco IOS 15.6(1)T and IOS XE, when the IOx feature set is enabled, allows remote attackers to cause a denial of service via a crafted packet, aka Bug IDs CSCu… CWE-399
 Resource Management Errors
CVE-2016-6403 2024-11-21 11:56 2016-09-19 Show GitHub Exploit DB Packet Storm
266319 7.8 HIGH
Local
cisco unified_computing_system UCS Manager and UCS 6200 Fabric Interconnects in Cisco Unified Computing System (UCS) through 3.0(2d) allow local users to obtain OS root access via crafted CLI input, aka Bug ID CSCuz91263. CWE-264
Permissions, Privileges, and Access Controls
CVE-2016-6402 2024-11-21 11:56 2016-09-19 Show GitHub Exploit DB Packet Storm
266320 6.1 MEDIUM
Network
emc vipr_srm Cross-site scripting (XSS) vulnerability in EMC ViPR SRM before 3.7.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. CWE-79
Cross-site Scripting
CVE-2016-6643 2024-11-21 11:56 2016-09-18 Show GitHub Exploit DB Packet Storm