Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 9, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
201321 7.5 重要
Network
Python Software Foundation - Python priority ライブラリを使用してビルドされた HTTP/2 の実装における CPU 資源の高い消費状態を引き起こされる脆弱性 CWE-399
リソース管理の問題
CVE-2016-6580 2017-01-23 16:12 2016-08-4 Show GitHub Exploit DB Packet Storm
201322 9.8 緊急
Network
eClinicalWorks - eClinicalWorks Population Health におけるセッションの固定化の脆弱性 CWE-284
CWE-384
CVE-2015-4594 2017-01-23 16:00 2015-06-16 Show GitHub Exploit DB Packet Storm
201323 7.5 重要
Network
The Chicken Team - CHICKEN の "http-client" egg におけるすべての HTTP リクエストをプロキシ経由にされる脆弱性 CWE-19
データ処理
CVE-2016-6287 2017-01-23 15:33 2016-07-21 Show GitHub Exploit DB Packet Storm
201324 7.5 重要
Network
The Chicken Team - CHICKEN の "spiffy-cgi-handlers" egg の CGI プログラムにおける攻撃者が指定した HTTP プロキシサーバの使用を強制される脆弱性 CWE-19
データ処理
CVE-2016-6286 2017-01-23 15:33 2016-07-21 Show GitHub Exploit DB Packet Storm
201325 9.8 緊急
Network
Pivotal Software, Inc. - Pivotal GemFire for PCF の gfsh エンドポイントにおけるサービス運用妨害 (DoS) の脆弱性 CWE-200
CWE-254
CVE-2016-9885 2017-01-23 14:54 2016-12-6 Show GitHub Exploit DB Packet Storm
201326 7.5 重要
Network
Pivotal Software, Inc.
IBM
- Pivotal Spring Security におけるセキュリティ制約を回避される脆弱性 CWE-417
チャネルおよびパスのエラー
CVE-2016-9879 2017-01-23 14:54 2016-12-28 Show GitHub Exploit DB Packet Storm
201327 9.8 緊急
Network
Lexmark - Lexmark Perspective Document Filters の変換機能の Bzip2 構文解析におけるスタックベースのバッファオーバーフローの脆弱性 CWE-787
境界外書き込み
CVE-2016-4336 2017-01-23 12:28 2016-08-6 Show GitHub Exploit DB Packet Storm
201328 7.5 重要
Network
The Chicken Team - CHICKEN の "process-execute" および "process-spawn" プロシージャにおけるリソースの枯渇の脆弱性 CWE-400
リソースの枯渇
CVE-2016-6831 2017-01-23 12:25 2016-08-12 Show GitHub Exploit DB Packet Storm
201329 9.8 緊急
Network
The Chicken Team - CHICKEN Scheme の "process-execute" および "process-spawn" プロシージャにおけるバッファオーバーランの脆弱性 CWE-119
バッファエラー
CVE-2016-6830 2017-01-23 12:25 2016-08-12 Show GitHub Exploit DB Packet Storm
201330 9.8 緊急
Network
Ruby-lang.org - Ruby の Fiddle::Function.new の "初期化" 関数におけるヒープオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2016-2339 2017-01-23 12:07 2016-06-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 9, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
291501 - neo4j neo4j Multiple cross-site request forgery (CSRF) vulnerabilities in Neo4J 1.9.2 allow remote attackers to hijack the authentication of administrators for requests that execute arbitrary code, as demonstrat… CWE-352
CWE-78
 Origin Validation Error
OS Command 
CVE-2013-7259 2024-11-21 11:00 2014-04-29 Show GitHub Exploit DB Packet Storm
291502 - simplemachines simple_machines_forum Simple Machines Forum (SMF) 2.0.6, 1.1.19, and earlier allows remote attackers to impersonate arbitrary users via a Unicode homoglyph character in a username. CWE-20
 Improper Input Validation 
CVE-2013-7236 2024-11-21 11:00 2014-04-29 Show GitHub Exploit DB Packet Storm
291503 - simplemachines simple_machines_forum Simple Machines Forum (SMF) before 1.1.19 and 2.x before 2.0.6 allows remote attackers to impersonate arbitrary users via multiple space characters characters. CWE-20
 Improper Input Validation 
CVE-2013-7235 2024-11-21 11:00 2014-04-29 Show GitHub Exploit DB Packet Storm
291504 - simplemachines simple_machines_forum Simple Machines Forum (SMF) before 1.1.19 and 2.x before 2.0.6 allows remote attackers to conduct clickjacking attacks via an X-Frame-Options header. CWE-20
 Improper Input Validation 
CVE-2013-7234 2024-11-21 11:00 2014-04-29 Show GitHub Exploit DB Packet Storm
291505 - gnome gnome-shell The automatic screen lock functionality in GNOME Shell (aka gnome-shell) before 3.10 does not prevent access to the "Enter a Command" dialog, which allows physically proximate attackers to execute ar… CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-7221 2024-11-21 11:00 2014-04-29 Show GitHub Exploit DB Packet Storm
291506 - gnome gnome-shell js/ui/screenShield.js in GNOME Shell (aka gnome-shell) before 3.8 allows physically proximate attackers to execute arbitrary commands by leveraging an unattended workstation with the keyboard focus o… NVD-CWE-Other
CVE-2013-7220 2024-11-21 11:00 2014-04-29 Show GitHub Exploit DB Packet Storm
291507 - phusion juvia Juvia uses the same secret key for all installations, which allows remote attackers to have unspecified impact by leveraging the secret key in app/config/initializers/secret_token.rb, related to cook… CWE-255
Credentials Management
CVE-2013-7134 2024-11-21 11:00 2014-04-29 Show GitHub Exploit DB Packet Storm
291508 - basespace_ruby_sdk_project basespace_ruby_sdk The put_call function in the API client (api/api_client.rb) in the BaseSpace Ruby SDK (aka bio-basespace-sdk) gem 0.1.7 for Ruby uses the API_KEY on the command line, which allows remote attackers to… CWE-200
Information Exposure
CVE-2013-7111 2024-11-21 11:00 2014-04-29 Show GitHub Exploit DB Packet Storm
291509 - entity_reference_project entityreference The Entity reference module 7.x-1.x before 7.x-1.1-rc1 for Drupal allows remote attackers to read private nodes titles by leveraging edit permissions to a node that references a private node. CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-7066 2024-11-21 11:00 2014-04-29 Show GitHub Exploit DB Packet Storm
291510 - organic_groups_project organic_groups The Organic Groups (OG) module 7.x-2.x before 7.x-2.3 for Drupal allows remote authenticated users to bypass group restrictions on nodes with all groups set to optional input via an empty group field. CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-7068 2024-11-21 11:00 2014-04-29 Show GitHub Exploit DB Packet Storm