Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 28, 2026, 4:09 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
242561 - - John Franklin - ** 削除 ** Drupal 用 Advertisement モジュールにおけるサイトの重要な設定情報を取得される脆弱性 - CVE-2012-3801 2012-06-29 11:03 2012-05-16 Show GitHub Exploit DB Packet Storm
242562 2.1 注意 Moshe Weitzman - Drupal 用 Organic Groups モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-3800 2012-06-29 11:02 2012-06-6 Show GitHub Exploit DB Packet Storm
242563 5.1 警告 Nextide - Drupal 用 Maestro モジュールにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2012-3799 2012-06-29 11:01 2012-06-6 Show GitHub Exploit DB Packet Storm
242564 5 警告 Bryce Hamrick - Drupal 用 Janrain Capture モジュールにおけるパスワードの推測が容易になる脆弱性 CWE-200
情報漏えい
CVE-2012-3798 2012-06-29 10:55 2012-06-13 Show GitHub Exploit DB Packet Storm
242565 2.6 注意 Ricardo Sanz Ante - Drupal 用 Ubercart AJAX Cart における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2012-2731 2012-06-29 10:54 2012-06-13 Show GitHub Exploit DB Packet Storm
242566 7.5 危険 AlexisWilke - Drupal 用 Protected Node モジュールにおけるアクセス制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-2730 2012-06-29 10:52 2012-06-13 Show GitHub Exploit DB Packet Storm
242567 6.8 警告 ADCI LLC - Drupal 用 SimpleMeta モジュールにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2012-2729 2012-06-29 10:52 2012-06-13 Show GitHub Exploit DB Packet Storm
242568 6.8 警告 Ronan Dowling - Drupal 用 Node Hierarchy モジュールにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2012-2728 2012-06-29 10:51 2012-06-13 Show GitHub Exploit DB Packet Storm
242569 5.8 警告 JanRain - Drupal 用の Janrain Capture モジュールにおけるオープンリダイレクトの脆弱性 CWE-20
不適切な入力確認
CVE-2012-2727 2012-06-29 10:51 2012-06-13 Show GitHub Exploit DB Packet Storm
242570 2.1 注意 Alberto Trujillo Gonzalez - Drupal 用の Protest モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-2726 2012-06-29 10:49 2012-06-6 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 28, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
266601 6.5 MEDIUM
Network
libdwarf_project libdwarf The print_exprloc_content function in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file. CWE-125
Out-of-bounds Read
CVE-2016-5033 2024-11-21 11:53 2017-02-18 Show GitHub Exploit DB Packet Storm
266602 6.5 MEDIUM
Network
libdwarf_project libdwarf The dwarf_get_xu_hash_entry function in libdwarf before 20160923 allows remote attackers to cause a denial of service (crash) via a crafted file. CWE-125
Out-of-bounds Read
CVE-2016-5032 2024-11-21 11:53 2017-02-18 Show GitHub Exploit DB Packet Storm
266603 5.5 MEDIUM
Local
libdwarf_project libdwarf The print_frame_inst_bytes function in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file. CWE-125
Out-of-bounds Read
CVE-2016-5031 2024-11-21 11:53 2017-02-18 Show GitHub Exploit DB Packet Storm
266604 6.5 MEDIUM
Network
libdwarf_project libdwarf The _dwarf_calculate_info_section_end_ptr function in libdwarf before 20160923 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file. CWE-476
 NULL Pointer Dereference
CVE-2016-5030 2024-11-21 11:53 2017-02-18 Show GitHub Exploit DB Packet Storm
266605 6.5 MEDIUM
Network
libdwarf_project libdwarf The create_fullest_file_path function in libdwarf before 20160923 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted dwarf file. CWE-476
 NULL Pointer Dereference
CVE-2016-5029 2024-11-21 11:53 2017-02-18 Show GitHub Exploit DB Packet Storm
266606 6.5 MEDIUM
Network
libdwarf_project libdwarf The print_frame_inst_bytes function in libdwarf before 20160923 allows remote attackers to cause a denial of service (NULL pointer dereference) via an object file with empty bss-like sections. CWE-476
 NULL Pointer Dereference
CVE-2016-5028 2024-11-21 11:53 2017-02-18 Show GitHub Exploit DB Packet Storm
266607 9.8 CRITICAL
Network
fedoraproject
zend
fedora
zend_framework
The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.20 might allow remote attackers to conduct SQL injection attacks by leveraging failure to remove comments from … CWE-89
SQL Injection
CVE-2016-4861 2024-11-21 11:53 2017-02-17 Show GitHub Exploit DB Packet Storm
266608 9.8 CRITICAL
Network
froxlor froxlor Froxlor before 0.9.35 uses the PHP rand function for random number generation, which makes it easier for remote attackers to guess the password reset token by predicting a value. CWE-330
 Use of Insufficiently Random Values
CVE-2016-5100 2024-11-21 11:53 2017-02-14 Show GitHub Exploit DB Packet Storm
266609 6.1 MEDIUM
Network
jenkins build_failure_analyzer Cross-site scripting (XSS) vulnerability in the Build Failure Analyzer plugin before 1.16.0 in Jenkins allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter. CWE-79
Cross-site Scripting
CVE-2016-4988 2024-11-21 11:53 2017-02-10 Show GitHub Exploit DB Packet Storm
266610 6.5 MEDIUM
Network
jenkins image_gallery Directory traversal vulnerability in the Image Gallery plugin before 1.4 in Jenkins allows remote attackers to list arbitrary directories and read arbitrary files via unspecified form fields. CWE-22
Path Traversal
CVE-2016-4987 2024-11-21 11:53 2017-02-10 Show GitHub Exploit DB Packet Storm