Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":July 1, 2026, 4:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
251471 4.3 警告 arizona-dream - Arizona Dream livor の index.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-1919 2012-06-26 15:46 2007-04-10 Show GitHub Exploit DB Packet Storm
251472 6.8 警告 MyBB Group
ecardmax.com
- eCardMAX Hot Editor および HotEditor プラグインの richedit/keyboard.php におけるディレクトリトラバーサルの脆弱性 - CVE-2007-1906 2012-06-26 15:46 2007-04-10 Show GitHub Exploit DB Packet Storm
251473 4.3 警告 AOL - AIM および ICQ におけるディレクトリトラバーサルの脆弱性 - CVE-2007-1904 2012-06-26 15:46 2007-04-10 Show GitHub Exploit DB Packet Storm
251474 9.3 危険 アカマイテクノロジーズ - Akamai Technologies Download Manager ActiveX コントロール (DownloadManagerV2.ocx) におけるスタックベースのバッファオーバーフローの脆弱性 - CVE-2007-1892 2012-06-26 15:46 2007-04-17 Show GitHub Exploit DB Packet Storm
251475 7.2 危険 アドビシステムズ - Adobe ColdFusion MX における任意のコードを実行される脆弱性 - CVE-2007-1874 2012-06-26 15:46 2007-04-10 Show GitHub Exploit DB Packet Storm
251476 4.3 警告 chcounter - chcounter におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-1871 2012-06-26 15:46 2007-04-13 Show GitHub Exploit DB Packet Storm
251477 5 警告 drake team - Drake CMS の classes/captcha/captcha.jpg.php におけるディレクトリトラバーサルの脆弱性 - CVE-2007-1850 2012-06-26 15:46 2007-04-3 Show GitHub Exploit DB Packet Storm
251478 7.5 危険 drake team - Drake CMS の 404.php におけるディレクトリトラバーサルの脆弱性 - CVE-2007-1849 2012-06-26 15:46 2007-04-3 Show GitHub Exploit DB Packet Storm
251479 4.3 警告 drake team - Drake CMS の admin/classes/ui.dta.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-1848 2012-06-26 15:46 2007-04-3 Show GitHub Exploit DB Packet Storm
251480 7.5 危険 avatic - Aardvark Topsites PHP における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-1844 2012-06-26 15:46 2007-04-3 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:July 1, 2026, 4:27 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
275741 9.1 CRITICAL
Network
ibm security_access_manager_9.0_firmware
security_access_manager_for_mobile_8.0_firmware
security_access_manager_for_web_8.0_firmware
IBM Single Sign On for Bluemix could allow a remote attacker to obtain sensitive information, caused by a XML external entity (XXE) error when processing XML data by the XML parser. A remote attacker… CWE-611
XXE
CVE-2016-2908 2024-11-21 11:49 2017-02-2 Show GitHub Exploit DB Packet Storm
275742 5.6 MEDIUM
Network
saltstack salt Salt before 2015.5.10 and 2015.8.x before 2015.8.8, when PAM external authentication is enabled, allows attackers to bypass the configured authentication service by passing an alternate service with … CWE-287
Improper Authentication
CVE-2016-3176 2024-11-21 11:49 2017-02-1 Show GitHub Exploit DB Packet Storm
275743 9.8 CRITICAL
Network
giflib_project giflib Multiple use-after-free and double-free vulnerabilities in gifcolor.c in GIFLIB 5.1.2 have unspecified impact and attack vectors. CWE-415
CWE-416
 Double Free
 Use After Free
CVE-2016-3177 2024-11-21 11:49 2017-01-24 Show GitHub Exploit DB Packet Storm
275744 9.8 CRITICAL
Network
ivanti landesk_management_suite Buffer overflow in the collector.exe listener of the Landesk Management Suite 10.0.0.271 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a lar… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2016-3147 2024-11-21 11:49 2017-01-24 Show GitHub Exploit DB Packet Storm
275745 9.1 CRITICAL
Network
synacor zimbra_collaboration_suite Zimbra Collaboration before 8.7.0 allows remote attackers to conduct deserialization attacks via unspecified vectors, aka bug 102276. CWE-502
 Deserialization of Untrusted Data
CVE-2016-3415 2024-11-21 11:49 2017-01-19 Show GitHub Exploit DB Packet Storm
275746 6.5 MEDIUM
Network
synacor zimbra_collaboration_suite Unspecified vulnerability in Zimbra Collaboration before 8.6.0 Patch 7 allows remote authenticated users to affect availability via unknown vectors, aka bug 102029. NVD-CWE-noinfo
CVE-2016-3414 2024-11-21 11:49 2017-01-19 Show GitHub Exploit DB Packet Storm
275747 7.5 HIGH
Network
synacor zimbra_collaboration_suite Unspecified vulnerability in Zimbra Collaboration before 8.7.0 allows remote attackers to affect integrity via unknown vectors, aka bug 103996. NVD-CWE-noinfo
CVE-2016-3413 2024-11-21 11:49 2017-01-19 Show GitHub Exploit DB Packet Storm
275748 6.1 MEDIUM
Network
synacor zimbra_collaboration_suite Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Collaboration before 8.7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka bugs 103997, 104413… CWE-79
Cross-site Scripting
CVE-2016-3412 2024-11-21 11:49 2017-01-19 Show GitHub Exploit DB Packet Storm
275749 6.1 MEDIUM
Network
synacor zimbra_collaboration_suite Cross-site scripting (XSS) vulnerability in Zimbra Collaboration before 8.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka bug 103609. CWE-79
Cross-site Scripting
CVE-2016-3411 2024-11-21 11:49 2017-01-19 Show GitHub Exploit DB Packet Storm
275750 6.1 MEDIUM
Network
synacor zimbra_collaboration_suite Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Collaboration before 8.7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka bugs 103956, 103995… CWE-79
Cross-site Scripting
CVE-2016-3410 2024-11-21 11:49 2017-01-19 Show GitHub Exploit DB Packet Storm