Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 2, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
251791 6.8 警告 IBM - 複数の IBM 製品の Labor Reporting ページにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2011-1397 2012-03-14 16:22 2012-02-14 Show GitHub Exploit DB Packet Storm
251792 6.5 警告 IBM - 複数の IBM 製品 の KPI コンポーネントにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2011-4816 2012-03-14 16:08 2012-02-14 Show GitHub Exploit DB Packet Storm
251793 4 警告 IBM - 複数の IBM 製品 の Help メニューの About オプションにおける詳細不明な脆弱性 CWE-200
情報漏えい
CVE-2011-4817 2012-03-14 16:07 2012-02-14 Show GitHub Exploit DB Packet Storm
251794 4.3 警告 IBM - IBM Maximo Asset Management および Maximo Asset Management Essentials におけるオープンリダイレクトの脆弱性 CWE-20
不適切な入力確認
CVE-2011-4818 2012-03-14 16:06 2012-02-14 Show GitHub Exploit DB Packet Storm
251795 4.3 警告 IBM - IBM Maximo Asset Management および Maximo Asset Management Essentials におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-4819 2012-03-14 16:05 2012-02-14 Show GitHub Exploit DB Packet Storm
251796 4.3 警告 IBM - 複数の IBM 製品におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-0195 2012-03-14 16:04 2012-02-14 Show GitHub Exploit DB Packet Storm
251797 5 警告 アップル - Apple Safari の WebKit における認証情報をキャプチャされる脆弱性 CWE-200
情報漏えい
CVE-2012-0647 2012-03-14 15:52 2012-03-12 Show GitHub Exploit DB Packet Storm
251798 5 警告 アップル - Apple Safari の WebKit におけるユーザを追跡される脆弱性 CWE-200
情報漏えい
CVE-2012-0640 2012-03-14 15:52 2012-03-12 Show GitHub Exploit DB Packet Storm
251799 6.4 警告 アップル - Windows 上で稼働する Apple Safari の IDN 機能におけるドメイン名を偽装される脆弱性 CWE-20
不適切な入力確認
CVE-2012-0584 2012-03-14 15:34 2012-03-12 Show GitHub Exploit DB Packet Storm
251800 6.4 警告 VMware - VMware vCenter Chargeback Manager における任意のファイルを読まれる脆弱性 CWE-20
不適切な入力確認
CVE-2012-1472 2012-03-14 15:15 2012-03-8 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 2, 2026, 4:18 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
246761 4.8 MEDIUM
Network
sonatype nexus_repository_manager Sonatype Nexus Repository Manager versions 3.x before 3.12.0 has XSS in multiple areas in the Administration UI. CWE-79
Cross-site Scripting
CVE-2018-12100 2024-11-21 12:44 2018-06-11 Show GitHub Exploit DB Packet Storm
246762 6.1 MEDIUM
Network
grafana
netapp
grafana
active_iq_performance_analytics_services
storagegrid_webscale_nas_bridge
Grafana before 5.2.0-beta1 has XSS vulnerabilities in dashboard links. CWE-79
Cross-site Scripting
CVE-2018-12099 2024-11-21 12:44 2018-06-11 Show GitHub Exploit DB Packet Storm
246763 5.4 MEDIUM
Network
oecms_project oecms A Reflected Cross-Site Scripting web vulnerability has been discovered in the OEcms v3.1 web-application. The vulnerability is located in the mod parameter of info.php. CWE-79
Cross-site Scripting
CVE-2018-12095 2024-11-21 12:44 2018-06-11 Show GitHub Exploit DB Packet Storm
246764 5.4 MEDIUM
Network
dimofinf dimofinf_cms Cross-site scripting (XSS) vulnerability in news.php in Dimofinf CMS Version 3.0.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter. CWE-79
Cross-site Scripting
CVE-2018-12094 2024-11-21 12:44 2018-06-11 Show GitHub Exploit DB Packet Storm
246765 7.5 HIGH
Network
tinyexr_project tinyexr tinyexr 0.9.5 has a memory leak in ParseEXRHeaderFromMemory in tinyexr.h. CWE-772
 Missing Release of Resource after Effective Lifetime
CVE-2018-12093 2024-11-21 12:44 2018-06-11 Show GitHub Exploit DB Packet Storm
246766 9.8 CRITICAL
Network
tinyexr_project tinyexr tinyexr 0.9.5 has a heap-based buffer over-read in tinyexr::DecodePixelData in tinyexr.h, related to OpenEXR code. CWE-125
Out-of-bounds Read
CVE-2018-12092 2024-11-21 12:44 2018-06-11 Show GitHub Exploit DB Packet Storm
246767 6.1 MEDIUM
Network
lamsfoundation lams There is unauthenticated reflected cross-site scripting (XSS) in LAMS before 3.1 that allows a remote attacker to introduce arbitrary JavaScript via manipulation of an unsanitized GET parameter durin… CWE-79
Cross-site Scripting
CVE-2018-12090 2024-11-21 12:44 2018-06-11 Show GitHub Exploit DB Packet Storm
246768 7.5 HIGH
Network
octopus octopus_server In Octopus Deploy version 2018.5.1 to 2018.5.7, a user with Task View is able to view a password for a Service Fabric Cluster, when the Service Fabric Cluster target is configured in Azure Active Dir… CWE-200
Information Exposure
CVE-2018-12089 2024-11-21 12:44 2018-06-11 Show GitHub Exploit DB Packet Storm
246769 7.5 HIGH
Network
futurxe futurxe The transferFrom function of a smart contract implementation for FuturXE (FXE), an Ethereum ERC20 token, allows attackers to accomplish an unauthorized transfer of digital assets because of a logic e… CWE-20
CWE-191
 Improper Input Validation 
 Integer Underflow (Wrap or Wraparound)
CVE-2018-12025 2024-11-21 12:44 2018-06-11 Show GitHub Exploit DB Packet Storm
246770 7.5 HIGH
Network
s3ql_project s3ql S3QL before 2.27 mishandles checksumming, and consequently allows replay attacks in which an attacker who controls the backend can present old versions of the filesystem metadata database as up-to-da… CWE-20
 Improper Input Validation 
CVE-2018-12088 2024-11-21 12:44 2018-06-11 Show GitHub Exploit DB Packet Storm