Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 14, 2026, 2 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
201121 7.8 重要
Local
Artifex Software - Artifex Software, Inc. の MuJS の jsrun.c 内の jsR_setproperty 関数における整数オーバーフローの脆弱性 CWE-190
整数オーバーフローまたはラップアラウンド
CVE-2017-5627 2017-02-15 11:11 2017-01-24 Show GitHub Exploit DB Packet Storm
201122 5.9 警告
Network
NTP Project - NTP の ntpq の getresponse 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-400
CWE-835
CVE-2015-8158 2017-02-14 19:49 2015-10-16 Show GitHub Exploit DB Packet Storm
201123 4.8 警告
Network
NTP Project - NTP の ntpq プロトコルにおける反射攻撃を実行される脆弱性 CWE-284
CWE-294
CVE-2015-8140 2017-02-14 19:49 2015-10-16 Show GitHub Exploit DB Packet Storm
201124 5.3 警告
Network
NTP Project - NTP の ntpq における開始タイムスタンプを取得される脆弱性 CWE-200
CWE-284
CVE-2015-8139 2017-02-14 19:49 2015-10-16 Show GitHub Exploit DB Packet Storm
201125 7.5 重要
Network
NTP Project - NTP におけるサービス運用妨害 (DoS) の脆弱性 CWE-400
リソースの枯渇
CVE-2015-7978 2017-02-14 19:49 2015-10-16 Show GitHub Exploit DB Packet Storm
201126 6.2 警告
Local
NTP Project - NTP の nextvar 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
CWE-20
CVE-2015-7975 2017-02-14 19:49 2015-10-16 Show GitHub Exploit DB Packet Storm
201127 5.5 警告
Local
ImageMagick - ImageMagick の MagickCore/fx.c の WaveletDenoiseImage 関数におけるヒープオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2016-9298 2017-02-14 16:56 2016-11-1 Show GitHub Exploit DB Packet Storm
201128 7.5 重要
Network
uClibc-ng project
Erik Andersen
- uClibc および uClibc-ng の libc/string/arm/memset.S における整数符号エラーの脆弱性 CWE-119
バッファエラー
CVE-2016-6264 2017-02-14 16:54 2016-06-20 Show GitHub Exploit DB Packet Storm
201129 5.5 警告
Local
サムスン - Samsung KNOX の ClipboardDataMgr における KNOX クリップボードデータを読まれる脆弱性 CWE-200
情報漏えい
CVE-2016-3996 2017-02-14 15:35 2016-04-16 Show GitHub Exploit DB Packet Storm
201130 7.8 重要
Local
openSUSE project
LibTIFF
- LibTiff の t2p_readwrite_pdf_image_tile 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-787
境界外書き込み
CVE-2016-9453 2017-02-14 15:08 2016-10-8 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 14, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
290231 - invisionpower
invisioncommunity
ip.nexus
invision_power_board
Cross-site scripting (XSS) vulnerability in Invision Power IP.Board (aka IPB or Power Board) 3.3.x and 3.4.x through 3.4.6, as downloaded before 20140424, or IP.Nexus 1.5.x through 1.5.9, as download… CWE-79
Cross-site Scripting
CVE-2014-3149 2024-11-21 11:07 2014-07-3 Show GitHub Exploit DB Packet Storm
290232 - spamtitan spamtitan Cross-site scripting (XSS) vulnerability in auth-settings-x.php in SpamTitan before 6.04 allows remote attackers to inject arbitrary web script or HTML via the sortdir parameter. CWE-79
Cross-site Scripting
CVE-2014-2965 2024-11-21 11:07 2014-07-3 Show GitHub Exploit DB Packet Storm
290233 - cisco universal_small_cell_series_firmware The DHCP client implementation in Universal Small Cell firmware on Cisco Small Cell products allows remote attackers to execute arbitrary commands via crafted DHCP messages, aka Bug ID CSCup47513. NVD-CWE-Other
CVE-2014-3307 2024-11-21 11:07 2014-07-2 Show GitHub Exploit DB Packet Storm
290234 - cisco cloud_portal Form Data Viewer in Cisco Intelligent Automation for Cloud in Cisco Cloud Portal places passwords in form data, which allows remote authenticated users to obtain sensitive information by reading HTML… CWE-255
Credentials Management
CVE-2014-3298 2024-11-21 11:07 2014-07-2 Show GitHub Exploit DB Packet Storm
290235 - cisco cloud_portal Cisco Intelligent Automation for Cloud in Cisco Cloud Portal does not properly restrict the content of MyServices action URLs, which allows remote authenticated users to obtain sensitive information … CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-3297 2024-11-21 11:07 2014-07-2 Show GitHub Exploit DB Packet Storm
290236 - ibm vios
aix
The runtime linker in IBM AIX 6.1 and 7.1 and VIOS 2.2.x allows local users to create a mode-666 root-owned file, and consequently gain privileges, by setting crafted MALLOCOPTIONS and MALLOCBUCKETS … CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-3074 2024-11-21 11:07 2014-07-2 Show GitHub Exploit DB Packet Storm
290237 - ibm tivoli_endpoint_manager IBM Tivoli Endpoint Manager 9.1 before 9.1.1088.0 allows remote attackers to read arbitrary files via XML data containing an external entity declaration in conjunction with an entity reference, relat… CWE-200
Information Exposure
CVE-2014-3066 2024-11-21 11:07 2014-07-2 Show GitHub Exploit DB Packet Storm
290238 - google android Stack-based buffer overflow in the encode_key function in /system/bin/keystore in the KeyStore service in Android 4.3 allows attackers to execute arbitrary code, and consequently obtain sensitive key… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2014-3100 2024-11-21 11:07 2014-07-2 Show GitHub Exploit DB Packet Storm
290239 - ibm sametime_meeting_server stconf.nsf in IBM Sametime Meeting Server 8.5.1 relies on the client to validate the file format used in wAttach?OpenForm multipart/form-data POST requests, which allows remote authenticated users to… CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-3088 2024-11-21 11:07 2014-07-2 Show GitHub Exploit DB Packet Storm
290240 - ibm openpages_grc_platform IBM OpenPages GRC Platform 6.1.0.1 before IF4 allows remote attackers to conduct link injection attacks via unspecified vectors. CWE-94
Code Injection
CVE-2014-3011 2024-11-21 11:07 2014-06-28 Show GitHub Exploit DB Packet Storm