Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 21, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
200741 8.1 重要
Network
Tor Browser Launcher project - Tor Browser Launcher における PGP 署名の検証を回避される脆弱性 CWE-254
セキュリティ機能
CVE-2016-3180 2017-03-16 15:11 2016-04-3 Show GitHub Exploit DB Packet Storm
200742 8.5 重要
Network
Smiths Medical - Smiths-Medical CADD-Solis Medication Safety Software におけるエンドポイント間の通信チャネルにアクセスされる脆弱性 CWE-346
同一生成元ポリシー違反
CVE-2016-8358 2017-03-16 15:07 2016-12-1 Show GitHub Exploit DB Packet Storm
200743 9.9 緊急
Network
Smiths Medical - Smiths-Medical CADD-Solis Medication Safety Software における SQL データベース上の権限を昇格される脆弱性 CWE-306
重要な機能に対する認証の欠如 解説
CVE-2016-8355 2017-03-16 15:07 2016-12-1 Show GitHub Exploit DB Packet Storm
200744 9.8 緊急
Network
Sensio Labs - Symfony における認証を回避される脆弱性 CWE-287
不適切な認証
CVE-2016-2403 2017-03-16 15:04 2016-05-9 Show GitHub Exploit DB Packet Storm
200745 9.8 緊急
Network
OpenText - OpenText Documentum D2 おける任意のコマンドを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2017-5586 2017-03-16 15:01 2017-02-15 Show GitHub Exploit DB Packet Storm
200746 7.8 重要
Local
GPGTools - GPG Suite の Libmacgpg の installerHelper サブコンポーネントにおける root 権限で任意のコマンドを実行される脆弱性 CWE-77
コマンドインジェクション
CVE-2014-4677 2017-03-16 14:55 2014-06-26 Show GitHub Exploit DB Packet Storm
200747 9.8 緊急
Network
php-gettext project - php-gettext における Eval インジェクションの脆弱性 CWE-94
コード・インジェクション
CVE-2016-6175 2017-03-16 14:51 2016-07-25 Show GitHub Exploit DB Packet Storm
200748 9.8 緊急
Network
アドビシステムズ - Adobe Flash Player の Primetime TVSDK API の機能におけるメモリを破損される脆弱性 CWE-119
バッファエラー
CVE-2017-2998 2017-03-16 14:35 2017-03-14 Show GitHub Exploit DB Packet Storm
200749 9.8 緊急
Network
アドビシステムズ - Adobe Flash Player の Primetime TVSDK におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2017-2997 2017-03-16 14:35 2017-03-14 Show GitHub Exploit DB Packet Storm
200750 7.8 重要
Local
アドビシステムズ - Adobe Shockwave Player における安全でないライブラリを読み込まれる脆弱性 CWE-426
信頼性のない検索パス
CVE-2017-2983 2017-03-16 14:35 2017-03-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 21, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
291761 - getgosoft getgo_download_manager Stack-based buffer overflow in GetGo Download Manager 4.9.0.1982, 4.8.2.1346, 4.4.5.502, and earlier allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a long… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2014-2206 2024-11-21 11:05 2014-03-6 Show GitHub Exploit DB Packet Storm
291762 - apple mac_os_x A certain Apple patch for OpenSSL in Apple OS X 10.9.2 and earlier uses a Trust Evaluation Agent (TEA) feature without terminating certain TLS/SSL handshakes as specified in the SSL_CTX_set_verify ca… CWE-20
 Improper Input Validation 
CVE-2014-2234 2024-11-21 11:05 2014-03-5 Show GitHub Exploit DB Packet Storm
291763 - jordy_meow media_file_renamer Multiple cross-site scripting (XSS) vulnerabilities in the (1) callback_multicheck, (2) callback_radio, and (3) callback_wysiwygin functions in mfrh_class.settings-api.php in the Media File Renamer p… CWE-79
Cross-site Scripting
CVE-2014-2040 2024-11-21 11:05 2014-03-4 Show GitHub Exploit DB Packet Storm
291764 - posh_project posh SQL injection vulnerability in portal/addtoapplication.php in POSH (aka Posh portal or Portaneo) 3.0 before 3.3.0 allows remote attackers to execute arbitrary SQL commands via the rssurl parameter. CWE-89
SQL Injection
CVE-2014-2211 2024-11-21 11:05 2014-03-4 Show GitHub Exploit DB Packet Storm
291765 - artifex mupdf Stack-based buffer overflow in the xps_parse_color function in xps/xps-common.c in MuPDF 1.3 and earlier allows remote attackers to execute arbitrary code via a large number of entries in the Context… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2014-2013 2024-11-21 11:05 2014-03-4 Show GitHub Exploit DB Packet Storm
291766 - mybb mybb Cross-site scripting (XSS) vulnerability in Upload/search.php in MyBB 1.6.12 and earlier allows remote attackers to inject arbitrary web script or HTML via the keywords parameter in a do_search actio… CWE-79
Cross-site Scripting
CVE-2014-1840 2024-11-21 11:05 2014-03-4 Show GitHub Exploit DB Packet Storm
291767 - google
lenovo
android
shareit
java/android/webkit/BrowserFrame.java in Android before 4.4 uses the addJavascriptInterface API in conjunction with creating an object of the SearchBoxImpl class, which allows attackers to execute ar… CWE-94
Code Injection
CVE-2014-1939 2024-11-21 11:05 2014-03-3 Show GitHub Exploit DB Packet Storm
291768 - drinkedin drinkedin_barfinder The DrinkedIn BarFinder application for Android, when Adobe PhoneGap 2.9.0 or earlier is used, allows remote attackers to execute arbitrary JavaScript code, and consequently obtain sensitive fine-geo… CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-1887 2024-11-21 11:05 2014-03-3 Show GitHub Exploit DB Packet Storm
291769 - edinburghtour edinburgh_by_bus The Edinburgh by Bus application for Android, when Adobe PhoneGap 2.9.0 or earlier is used, allows remote attackers to execute arbitrary JavaScript code, and consequently access external-storage reso… CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-1886 2024-11-21 11:05 2014-03-3 Show GitHub Exploit DB Packet Storm
291770 - hsgroup forzearmate The ForzeArmate application for Android, when Adobe PhoneGap 2.9.0 or earlier is used, allows remote attackers to execute arbitrary JavaScript code, and consequently obtain write access to external-s… CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-1885 2024-11-21 11:05 2014-03-3 Show GitHub Exploit DB Packet Storm