Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228711 5 警告 Best Practical Solutions - Request Tracker におけるクロスサイトリクエストフォージェリ (CSRF) 保護メカニズムを回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-4734 2012-11-13 16:12 2012-10-25 Show GitHub Exploit DB Packet Storm
228712 6.8 警告 Best Practical Solutions - Request Tracker におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2012-4732 2012-11-13 16:11 2012-10-25 Show GitHub Exploit DB Packet Storm
228713 4 警告 Best Practical Solutions - Request Tracker 用 FAQ マネージャにおける任意のクラスの任意の記事を作成される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-4731 2012-11-13 16:10 2012-10-25 Show GitHub Exploit DB Packet Storm
228714 3.5 注意 Best Practical Solutions - Request Tracker における任意のメールヘッダを挿入される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-4730 2012-11-13 16:08 2012-10-25 Show GitHub Exploit DB Packet Storm
228715 5 警告 Drupal - Drupal の OpenID モジュールおける任意のファイルを読まれる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-4554 2012-11-13 15:59 2012-10-17 Show GitHub Exploit DB Packet Storm
228716 6.8 警告 Drupal - Drupal における重要な情報を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-4553 2012-11-13 15:58 2012-10-17 Show GitHub Exploit DB Packet Storm
228717 7.5 危険 Quagga
インターネットイニシアティブ
- Quagga の ecommunity_ecom2str 関数におけるにおけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2011-3327 2012-11-13 15:11 2011-09-26 Show GitHub Exploit DB Packet Storm
228718 5 警告 Quagga
インターネットイニシアティブ
- Quagga の ospf_flood 関数におけるサービス運用妨害 (デーモンクラッシュ) の脆弱性 CWE-399
リソース管理の問題
CVE-2011-3326 2012-11-13 15:10 2011-09-26 Show GitHub Exploit DB Packet Storm
228719 5 警告 Quagga
インターネットイニシアティブ
- Quagga の ospfd 内の ospf_packet.c におけるサービス運用妨害 (デーモンクラッシュ) の脆弱性 CWE-399
リソース管理の問題
CVE-2011-3325 2012-11-13 15:09 2011-09-26 Show GitHub Exploit DB Packet Storm
228720 5 警告 Quagga
インターネットイニシアティブ
- Quagga の ospf6_lsa.c 内にある ospf6_lsa_is_changed 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2011-3324 2012-11-13 15:08 2011-09-26 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 25, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
211421 8.8 HIGH
Network
imagely nextgen_gallery In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php. CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2015-9228 2024-11-21 11:40 2017-09-12 Show GitHub Exploit DB Packet Storm
211422 7.2 HIGH
Network
alegrocart alegrocart PHP remote file inclusion vulnerability in the get_file function in upload/admin2/controller/report_logs.php in AlegroCart 1.2.8 allows remote administrators to execute arbitrary PHP code via a URL i… CWE-94
Code Injection
CVE-2015-9227 2024-11-21 11:40 2017-09-12 Show GitHub Exploit DB Packet Storm
211423 7.2 HIGH
Network
alegrocart alegrocart Multiple SQL injection vulnerabilities in AlegroCart 1.2.8 allow remote administrators to execute arbitrary SQL commands via the download parameter in the (1) check_download and possibly (2) check_fi… CWE-89
SQL Injection
CVE-2015-9226 2024-11-21 11:40 2017-09-12 Show GitHub Exploit DB Packet Storm
211424 7.8 HIGH
Local
microsoft windows_rt_8.1
windows_server_2012
windows_7
windows_10
windows_server_2016
windows_8.1
windows_server_2008
windows_vista
The Common Log File System (CLFS) driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Go… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2016-0026 2024-11-21 11:40 2016-11-10 Show GitHub Exploit DB Packet Storm
211425 5.5 MEDIUM
Local
microsoft outlook_web_access Outlook Web Access (OWA) in Microsoft Exchange Server 2013 SP1, Cumulative Update 11, and Cumulative Update 12 and 2016 Gold and Cumulative Update 1 does not properly restrict loading of IMG elements… CWE-200
Information Exposure
CVE-2016-0028 2024-11-21 11:40 2016-06-16 Show GitHub Exploit DB Packet Storm
211426 7.3 HIGH
Local
microsoft word
word_for_mac
office_web_apps
sharepoint_server
office
office_web_apps_server
office_compatibility_pack
office_online_server
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Office 2016, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Automation … CWE-20
 Improper Input Validation 
CVE-2016-0025 2024-11-21 11:40 2016-06-16 Show GitHub Exploit DB Packet Storm
211427 7.8 HIGH
Local
microsoft infopath Microsoft InfoPath 2007 SP3, 2010 SP2, and 2013 SP1 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability." CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2016-0021 2024-11-21 11:40 2016-03-9 Show GitHub Exploit DB Packet Storm
211428 7.8 HIGH
Local
microsoft word
word_for_mac
office
office_web_apps_server
sharepoint_server
office_compatibility_pack
word_viewer
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Viewer, Word Automation … CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2016-0052 2024-11-21 11:40 2016-02-10 Show GitHub Exploit DB Packet Storm
211429 7.8 HIGH
Local
microsoft windows_rt_8.1
windows_server_2012
windows_7
windows_10
windows_8.1
windows_server_2008
windows_vista
The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows … CWE-264
Permissions, Privileges, and Access Controls
CVE-2016-0051 2024-11-21 11:40 2016-02-10 Show GitHub Exploit DB Packet Storm
211430 5.3 MEDIUM
Network
microsoft windows_server_2012
windows_server_2008
Network Policy Server (NPS) in Microsoft Windows Server 2008 SP2 and R2 SP1 and Server 2012 Gold and R2 misparses username queries, which allows remote attackers to cause a denial of service (RADIUS … CWE-20
 Improper Input Validation 
CVE-2016-0050 2024-11-21 11:40 2016-02-10 Show GitHub Exploit DB Packet Storm