Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 27, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
250821 10 危険 オラクル - Oracle Fusion Middleware の Oracle WebLogic Server コンポーネントにおける Node Manager の処理に関する脆弱性 CWE-noinfo
情報不足
CVE-2010-3510 2012-03-27 18:42 2011-01-19 Show GitHub Exploit DB Packet Storm
250822 3 注意 オラクル - Oracle Sun Products Suite の Oracle Explorer (Sun Explorer) コンポーネントにおける脆弱性 CWE-noinfo
情報不足
CVE-2010-3506 2012-03-27 18:42 2010-10-13 Show GitHub Exploit DB Packet Storm
250823 4.3 警告 オラクル - Oracle E-Business Suite の Oracle Applications Technology Stack コンポーネントにおける脆弱性 CWE-noinfo
情報不足
CVE-2010-3504 2012-03-27 18:42 2010-10-13 Show GitHub Exploit DB Packet Storm
250824 4 警告 オラクル - Oracle Siebel Suite の Siebel Core コンポーネントにおける脆弱性 CWE-noinfo
情報不足
CVE-2010-3502 2012-03-27 18:42 2010-10-13 Show GitHub Exploit DB Packet Storm
250825 6 警告 オラクル - Oracle Siebel Suite の Siebel Core - Highly Interactive Client コンポーネントにおける脆弱性 CWE-noinfo
情報不足
CVE-2010-3500 2012-03-27 18:42 2010-10-13 Show GitHub Exploit DB Packet Storm
250826 10 危険 TIBCO Software - TIBCO ActiveMatrix Service Grid などで使用される ActiveMatrix Runtime コンポーネントにおける任意のコードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2010-3491 2012-03-27 18:42 2010-10-19 Show GitHub Exploit DB Packet Storm
250827 6.5 警告 FreePBX - FreePBX の設定インターフェース の System Recordings コンポーネントにおけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2010-3490 2012-03-27 18:42 2010-09-28 Show GitHub Exploit DB Packet Storm
250828 4.3 警告 digitalworkroom - CMS Digital Workroom の netautor/napro4/home/login2.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-3489 2012-03-27 18:42 2010-09-22 Show GitHub Exploit DB Packet Storm
250829 5 警告 houbysoft - QuickShare におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2010-3488 2012-03-27 18:42 2010-09-22 Show GitHub Exploit DB Packet Storm
250830 5 警告 yellosoft - YelloSoft Pinky におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2010-3487 2012-03-27 18:42 2010-09-22 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 28, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
268561 5.3 MEDIUM
Network
debian
drupal
debian_linux
drupal
The "have you forgotten your password" links in the User module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allow remote attackers to obtain sensitive username information by leveraging a configur… CWE-200
Information Exposure
CVE-2016-3170 2024-11-21 11:49 2016-04-13 Show GitHub Exploit DB Packet Storm
268562 8.1 HIGH
Network
debian
drupal
debian_linux
drupal
The User module in Drupal 6.x before 6.38 and 7.x before 7.43 allows remote attackers to gain privileges by leveraging contributed or custom code that calls the user_save function with an explicit ca… CWE-264
Permissions, Privileges, and Access Controls
CVE-2016-3169 2024-11-21 11:49 2016-04-13 Show GitHub Exploit DB Packet Storm
268563 6.4 MEDIUM
Network
drupal
debian
drupal
debian_linux
The System module in Drupal 6.x before 6.38 and 7.x before 7.43 might allow remote attackers to hijack the authentication of site administrators for requests that download and run files with arbitrar… CWE-254
 7PK - Security Features
CVE-2016-3168 2024-11-21 11:49 2016-04-13 Show GitHub Exploit DB Packet Storm
268564 7.4 HIGH
Network
drupal
debian
drupal
debian_linux
Open redirect vulnerability in the drupal_goto function in Drupal 6.x before 6.38, when used with PHP before 5.4.7, allows remote attackers to redirect users to arbitrary web sites and conduct phishi… NVD-CWE-Other
CVE-2016-3167 2024-11-21 11:49 2016-04-13 Show GitHub Exploit DB Packet Storm
268565 5.9 MEDIUM
Network
debian
drupal
debian_linux
drupal
CRLF injection vulnerability in the drupal_set_header function in Drupal 6.x before 6.38, when used with PHP before 5.1.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP re… NVD-CWE-Other
CVE-2016-3166 2024-11-21 11:49 2016-04-13 Show GitHub Exploit DB Packet Storm
268566 7.5 HIGH
Network
drupal drupal The Form API in Drupal 6.x before 6.38 ignores access restrictions on submit buttons, which might allow remote attackers to bypass intended access restrictions by leveraging permission to submit a fo… CWE-284
Improper Access Control
CVE-2016-3165 2024-11-21 11:49 2016-04-13 Show GitHub Exploit DB Packet Storm
268567 7.4 HIGH
Network
drupal
debian
drupal
debian_linux
Drupal 6.x before 6.38, 7.x before 7.43, and 8.x before 8.0.4 might allow remote attackers to conduct open redirect attacks by leveraging (1) custom code or (2) a form shown on a 404 error page, rela… NVD-CWE-Other
CVE-2016-3164 2024-11-21 11:49 2016-04-13 Show GitHub Exploit DB Packet Storm
268568 7.5 HIGH
Network
debian
drupal
debian_linux
drupal
The XML-RPC system in Drupal 6.x before 6.38 and 7.x before 7.43 might make it easier for remote attackers to conduct brute-force attacks via a large number of calls made at once to the same method. CWE-254
 7PK - Security Features
CVE-2016-3163 2024-11-21 11:49 2016-04-13 Show GitHub Exploit DB Packet Storm
268569 8.1 HIGH
Network
drupal
debian
drupal
debian_linux
The File module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allows remote authenticated users to bypass access restrictions and read, delete, or substitute a link to a file uploaded to an unproces… CWE-284
Improper Access Control
CVE-2016-3162 2024-11-21 11:49 2016-04-13 Show GitHub Exploit DB Packet Storm
268570 9.1 CRITICAL
Network
postgresql postgresql The (1) brin_page_type and (2) brin_metapage_info functions in the pageinspect extension in PostgreSQL before 9.5.x before 9.5.2 allows attackers to bypass intended access restrictions and consequent… CWE-264
Permissions, Privileges, and Access Controls
CVE-2016-3065 2024-11-21 11:49 2016-04-12 Show GitHub Exploit DB Packet Storm