Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 2, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
201331 8.8 重要
Network
ImageMagick - ImageMagick の MagickCore/draw.c の DrawDashPolygon 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2016-4562 2016-11-16 17:19 2016-05-6 Show GitHub Exploit DB Packet Storm
201332 6.8 警告 Debian
openSUSE project
Google
- Google Chrome の Developer Tools サブシステムにおけるアクセス制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-1627 2016-11-16 16:32 2016-02-9 Show GitHub Exploit DB Packet Storm
201333 6.8 警告 Debian
openSUSE project
Google
- Google Chrome で使用される Brotli の dec/decode.c の ProcessCommandsInternal 関数における整数アンダーフローの脆弱性 CWE-119
バッファエラー
CVE-2016-1624 2016-11-16 16:32 2016-02-9 Show GitHub Exploit DB Packet Storm
201334 4.3 警告 Debian
openSUSE project
Google
- Google Chrome の PDFium で使用される OpenJPEG の pi.c の opj_pi_update_decode_poc 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2016-1626 2016-11-16 16:32 2016-02-9 Show GitHub Exploit DB Packet Storm
201335 5.5 警告
Local
Linux
オラクル
- Linux Kernel のファイルシステムレイヤにおけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2016-6198 2016-11-16 16:10 2016-05-18 Show GitHub Exploit DB Packet Storm
201336 5.5 警告
Local
Linux
オラクル
- Linux Kernel の OverlayFS ファイルシステムの実装の fs/overlayfs/dir.c におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2016-6197 2016-11-16 16:09 2016-03-21 Show GitHub Exploit DB Packet Storm
201337 8.8 重要
Network
シトリックス・システムズ
Xen プロジェクト
- Xen の arch/x86/mm.c の PV のページテーブルのコードにおけるホスト OS の権限を取得される脆弱性 CWE-Other
その他
CVE-2016-6258 2016-11-16 16:09 2015-07-26 Show GitHub Exploit DB Packet Storm
201338 8.8 重要
Network
アップル
Debian
Canonical
- 複数の Apple 製品で使用される libxml2 の xmlStrncat 関数におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2016-1834 2016-11-16 16:04 2016-05-16 Show GitHub Exploit DB Packet Storm
201339 8.8 重要
Network
アップル
Debian
Canonical
- 複数の Apple 製品で使用される libxml2 の htmlCurrentChar 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2016-1833 2016-11-16 16:04 2016-05-16 Show GitHub Exploit DB Packet Storm
201340 8.8 重要
Network
アップル
Debian
Canonical
- 複数の Apple 製品で使用される libxml2 の xmlFAParsePosCharGroup 関数におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2016-1840 2016-11-16 16:04 2016-05-16 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 3, 2026, 4:18 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
290921 - hp service_manager Cross-site scripting (XSS) vulnerability in the Mobility Web Client and Service Request Catalog (SRC) components in HP Service Manager (SM) 7.21 and 9.x before 9.34 allows remote attackers to inject … CWE-79
Cross-site Scripting
CVE-2013-6222 2024-11-21 10:58 2014-08-24 Show GitHub Exploit DB Packet Storm
290922 - ibm power_760_firmware
power_770
power_780
power_795
power_ese
power_740_firmware
power_710
power_720
power_730
power_740
power_770_firmware
power_750
power_760
pow…
Unspecified vulnerability on IBM Power 7 Systems 740 before 740.70 01Ax740_121, 760 before 760.40 Ax760_078, and 770 before 770.30 01Ax770_062 allows local users to gain Service Processor privileges … NVD-CWE-noinfo
CVE-2013-6306 2024-11-21 10:58 2014-08-23 Show GitHub Exploit DB Packet Storm
290923 - yealink sip-t38g cgi-bin/cgiServer.exx in Yealink VoIP Phone SIP-T38G allows remote authenticated users to execute arbitrary commands by calling the system method in the body of a request, as demonstrated by running … CWE-78
OS Command 
CVE-2013-5758 2024-11-21 10:58 2014-08-4 Show GitHub Exploit DB Packet Storm
290924 - yealink sip-t38g Absolute path traversal vulnerability in Yealink VoIP Phone SIP-T38G allows remote authenticated users to read arbitrary files via a full pathname in the dumpConfigFile function in the command parame… CWE-22
Path Traversal
CVE-2013-5757 2024-11-21 10:58 2014-08-4 Show GitHub Exploit DB Packet Storm
290925 - yealink sip-t38g Directory traversal vulnerability in Yealink VoIP Phone SIP-T38G allows remote authenticated users to read arbitrary files via a .. (dot dot) in the page parameter to cgi-bin/cgiServer.exx. CWE-22
Path Traversal
CVE-2013-5756 2024-11-21 10:58 2014-08-4 Show GitHub Exploit DB Packet Storm
290926 - oracle mojarra Oracle Mojarra 2.2.x before 2.2.6 and 2.1.x before 2.1.28 does not perform appropriate encoding when a (1) <h:outputText> tag or (2) EL expression is used after a scriptor style block, which allows r… CWE-79
Cross-site Scripting
CVE-2013-5855 2024-11-21 10:58 2014-07-17 Show GitHub Exploit DB Packet Storm
290927 - yealink sip-t38g config/.htpasswd in Yealink IP Phone SIP-T38G has a hardcoded password of (1) user (s7C9Cx.rLsWFA) for the user account, (2) admin (uoCbM.VEiKQto) for the admin account, and (3) var (jhl3iZAe./qXM) f… CWE-255
Credentials Management
CVE-2013-5755 2024-11-21 10:58 2014-07-16 Show GitHub Exploit DB Packet Storm
290928 - dahuasecurity dvr_firmware Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive information including user credentials, change user passwords, clear log files, and perfo… CWE-287
Improper Authentication
CVE-2013-6117 2024-11-21 10:58 2014-07-12 Show GitHub Exploit DB Packet Storm
290929 - ibm marketing_platform SQL injection vulnerability in IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. CWE-89
SQL Injection
CVE-2013-6311 2024-11-21 10:58 2014-06-28 Show GitHub Exploit DB Packet Storm
290930 - ibm marketing_platform Cross-site scripting (XSS) vulnerability in IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. CWE-79
Cross-site Scripting
CVE-2013-6310 2024-11-21 10:58 2014-06-28 Show GitHub Exploit DB Packet Storm