Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 6, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
201321 5.3 警告
Network
オラクル - Oracle Fusion Middleware の Oracle WebLogic Server における Web Container に関する脆弱性 CWE-noinfo
情報不足
CVE-2016-3445 2016-12-9 16:05 2016-07-19 Show GitHub Exploit DB Packet Storm
201322 5.9 警告
Network
レッドハット
openSUSE project
MariaDB Corporation Ab.
オラクル
- MariaDB などの製品の sql-common/client.c の ssl_verify_server_cert 関数における SSL サーバになりすまされる脆弱性 CWE-Other
その他
CVE-2016-2047 2016-12-9 16:05 2016-01-26 Show GitHub Exploit DB Packet Storm
201323 6.8 警告 Mozilla Foundation
openSUSE project
SUSE
オラクル
- Mozilla Firefox の nsScannerString::AppendUnicodeTo 関数における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2016-1974 2016-12-9 15:27 2016-03-8 Show GitHub Exploit DB Packet Storm
201324 6.8 警告 Mozilla Foundation
オラクル
- Mozilla Firefox の WebRTC の実装の GetStaticInstance 関数における任意のコードを実行される脆弱性 CWE-Other
その他
CVE-2016-1973 2016-12-9 15:27 2016-03-8 Show GitHub Exploit DB Packet Storm
201325 6.8 警告 SIL International
Mozilla Foundation
openSUSE project
SUSE
オラクル
- Mozilla Firefox で使用される Graphite2 における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2016-1977 2016-12-9 15:27 2016-03-8 Show GitHub Exploit DB Packet Storm
201326 6.8 警告 Mozilla Foundation
openSUSE project
オラクル
- Mozilla Firefox の dom/plugins/base/nsJSNPRuntime.cpp における任意のコードを実行される脆弱性 CWE-Other
その他
CVE-2016-1966 2016-12-9 15:27 2016-03-8 Show GitHub Exploit DB Packet Storm
201327 7.5 重要
Network
BlueZ Project - BlueZ の monitor/packet.c ソースファイルの packet_hexdump 関数における境界外読み取りの脆弱性 CWE-125
境界外読み取り
CVE-2016-9918 2016-12-9 11:57 2016-11-15 Show GitHub Exploit DB Packet Storm
201328 7.5 重要
Network
BlueZ Project - BlueZ の tools/hcidump.c ソースファイルの read_n 関数におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2016-9917 2016-12-9 11:57 2016-11-14 Show GitHub Exploit DB Packet Storm
201329 7.5 重要
Network
UMN - MapServer における情報漏えいの脆弱性 CWE-200
情報漏えい
CVE-2016-9839 2016-12-9 11:56 2016-11-29 Show GitHub Exploit DB Packet Storm
201330 5.5 警告
Local
GNOME Project - GNOME Structured File Library の gsf-infile-tar.c のtar_directory_for_file() 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-476
NULL ポインタデリファレンス
CVE-2016-9888 2016-12-9 11:30 2016-12-3 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 6, 2026, 4:18 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
289941 9.8 CRITICAL
Network
karo_project karo The karo gem 2.3.8 for Ruby allows Remote command injection via the host field. CWE-77
Command Injection
CVE-2014-10075 2024-11-21 11:03 2018-10-5 Show GitHub Exploit DB Packet Storm
289942 9.8 CRITICAL
Network
umbraco umbraco_cms Umbraco before 7.2.0 has a remote PHP code execution vulnerability because Umbraco.Web.UI/config/umbracoSettings.Release.config does not block the upload of .php files. CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2014-10074 2024-11-21 11:03 2018-08-27 Show GitHub Exploit DB Packet Storm
289943 7.5 HIGH
Network
fancy-server_project fancy-server Versions less than 0.1.4 of the static file server module fancy-server are vulnerable to directory traversal. An attacker can provide input such as `../` to read files outside of the served directory. CWE-22
Path Traversal
CVE-2014-10066 2024-11-21 11:03 2018-06-1 Show GitHub Exploit DB Packet Storm
289944 6.1 MEDIUM
Network
remarkable_project remarkable Certain input when passed into remarkable before 1.4.1 will bypass the bad protocol check that disallows the javascript: scheme allowing for javascript: url's to be injected into the rendered content. CWE-79
Cross-site Scripting
CVE-2014-10065 2024-11-21 11:03 2018-06-1 Show GitHub Exploit DB Packet Storm
289945 7.5 HIGH
Network
qs_project qs The qs module before 1.0.0 does not have an option or default for specifying object depth and when parsing a string representing a deeply nested object will block the event loop for long periods of t… CWE-399
 Resource Management Errors
CVE-2014-10064 2024-11-21 11:03 2018-06-1 Show GitHub Exploit DB Packet Storm
289946 7.5 HIGH
Network
hapi inert The inert directory handler in inert node module before 1.1.1 always allows files in hidden directories to be served, even when `showHidden` is false. CWE-22
Path Traversal
CVE-2014-10068 2024-11-21 11:03 2018-05-30 Show GitHub Exploit DB Packet Storm
289947 5.9 MEDIUM
Network
paypal-ipn_project paypal-ipn paypal-ipn before 3.0.0 uses the `test_ipn` parameter (which is set by the PayPal IPN simulator) to determine if it should use the production PayPal site or the sandbox. With a bit of time, an attack… CWE-287
Improper Authentication
CVE-2014-10067 2024-11-21 11:03 2018-05-30 Show GitHub Exploit DB Packet Storm
289948 7.1 HIGH
Network
ibm rational_clearquest Multiple XML external entity (XXE) vulnerabilities in (1) CQWeb / CM Server, (2) ClearQuest Native client, (3) ClearQuest Eclipse client, and (4) ClearQuest Eclipse Designer components in IBM Rationa… CWE-611
XXE
CVE-2014-0950 2024-11-21 11:03 2018-04-21 Show GitHub Exploit DB Packet Storm
289949 9.1 CRITICAL
Network
ibm rational_clearcase Multiple XML external entity (XXE) vulnerabilities in the (1) CCRC WAN Server / CM Server, (2) Perl CC/CQ integration trigger scripts, (3) CMAPI Java interface, (4) ClearCase remote client, and (5) C… CWE-611
XXE
CVE-2014-0931 2024-11-21 11:03 2018-04-21 Show GitHub Exploit DB Packet Storm
289950 8.1 HIGH
Network
ibm sterling_b2b_integrator
sterling_file_gateway
The ActiveMQ admin user interface in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows remote attackers to bypass authentication by leveraging knowledge of the port… CWE-287
Improper Authentication
CVE-2014-0927 2024-11-21 11:03 2018-04-21 Show GitHub Exploit DB Packet Storm