Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 11, 2026, 6:13 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
201521 7.4 重要
Network
MetalGenix - GeniXCMS のメディアファイルアップロード機能における SSRF 攻撃を実行される脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2017-5518 2017-01-30 10:44 2017-01-13 Show GitHub Exploit DB Packet Storm
201522 5.5 警告
Local
PHPMailer project - PHPMailer の msgHTML メソッドにおける画像の相対 URL が絶対ローカルファイルパスとして処理される脆弱性 CWE-200
情報漏えい
CVE-2017-5223 2017-01-30 10:20 2017-01-9 Show GitHub Exploit DB Packet Storm
201523 9.8 緊急
Network
GNU Project
Fedora Project
- GNU Guile の REPL サーバにおける任意のコードを実行される脆弱性 CWE-284
不適切なアクセス制御
CVE-2016-8606 2017-01-27 18:26 2016-10-11 Show GitHub Exploit DB Packet Storm
201524 5.3 警告
Network
GNU Project
Fedora Project
- GNU Guile の mkdir プロシージャにおけるプロセスの umask をゼロに変更される脆弱性 CWE-275
パーミッションの問題
CVE-2016-8605 2017-01-27 18:25 2016-10-11 Show GitHub Exploit DB Packet Storm
201525 7 重要
Local
Linux - Synaptics タッチスクリーンドライバにおける権限を昇格される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-8451 2017-01-27 17:00 2016-10-13 Show GitHub Exploit DB Packet Storm
201526 7.8 重要
Local
Google - Linux 用 MediaTek ドライバの camera_fdvt.c の MT6573FDVT_SetRegHW 関数における権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-6492 2017-01-27 17:00 2016-12-5 Show GitHub Exploit DB Packet Storm
201527 5.5 警告
Local
Google - Audioserver における情報を公開される脆弱性 CWE-200
情報漏えい
CVE-2017-0398 2017-01-27 16:58 2017-01-3 Show GitHub Exploit DB Packet Storm
201528 7 重要
Local
Google - Broadcom Wi-Fi ドライバにおける権限を昇格される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-9910 2017-01-27 16:50 2016-12-5 Show GitHub Exploit DB Packet Storm
201529 7 重要
Local
Google - Broadcom Wi-Fi ドライバにおける権限を昇格される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-9909 2017-01-27 16:50 2016-12-5 Show GitHub Exploit DB Packet Storm
201530 7.5 重要
Network
GStreamer - GStreamer の mpegts デコーダの gst_mpegts_section_new 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-125
境界外読み取り
CVE-2016-9812 2017-01-27 15:48 2016-11-29 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 11, 2026, 5:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
292071 - ovirt ovirt The REST API in oVirt 3.4.0 and earlier stores session IDs in HTML5 local storage, which allows remote attackers to obtain sensitive information via a crafted web page. CWE-200
Information Exposure
CVE-2014-0153 2024-11-21 11:01 2014-09-8 Show GitHub Exploit DB Packet Storm
292072 - ovirt
redhat
ovirt
ovirt-engine
Session fixation vulnerability in the web admin interface in oVirt 3.4.0 and earlier allows remote attackers to hijack web sessions via unspecified vectors. NVD-CWE-Other
CVE-2014-0152 2024-11-21 11:01 2014-09-8 Show GitHub Exploit DB Packet Storm
292073 - apache ofbiz Multiple cross-site scripting (XSS) vulnerabilities in framework/common/webcommon/includes/messages.ftl in Apache OFBiz 11.04.01 before 11.04.05 and 12.04.01 before 12.04.04 allow remote attackers to… CWE-79
Cross-site Scripting
CVE-2014-0232 2024-11-21 11:01 2014-08-22 Show GitHub Exploit DB Packet Storm
292074 - iridium open_port
pilot_below_deck_equipment
The Terminal Upgrade Tool in the Pilot Below Deck Equipment (BDE) and OpenPort implementations on Iridium satellite terminals allows remote attackers to execute arbitrary code by uploading new firmwa… NVD-CWE-Other
CVE-2014-0327 2024-11-21 11:01 2014-08-18 Show GitHub Exploit DB Packet Storm
292075 - iridium open_port
pilot_below_deck_equipment
The Pilot Below Deck Equipment (BDE) and OpenPort implementations on Iridium satellite terminals allow remote attackers to read hardcoded credentials via the web interface. NVD-CWE-Other
CVE-2014-0326 2024-11-21 11:01 2014-08-18 Show GitHub Exploit DB Packet Storm
292076 - cobham ailor_6110_mini-c_gmdss
sailor_6006_message_terminal
sailor_6222_vhf
sailor_6300_mf_\/_hf
The thraneLINK protocol implementation on Cobham devices does not verify firmware signatures, which allows attackers to execute arbitrary code by leveraging physical access or terminal access to send… NVD-CWE-Other
CVE-2014-0328 2024-11-21 11:01 2014-08-15 Show GitHub Exploit DB Packet Storm
292077 - microsoft windows_server_2008
windows_rt
windows_8.1
windows_7
windows_rt_8.1
windows_vista
windows_8
windows_server_2012
windows_server_2003
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and … CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-0318 2024-11-21 11:01 2014-08-13 Show GitHub Exploit DB Packet Storm
292078 - microsoft windows_server_2008
windows_server_2012
windows_rt
windows_8.1
windows_7
windows_rt_8.1
windows_8
Memory leak in the Local RPC (LRPC) server implementation in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 … CWE-399
 Resource Management Errors
CVE-2014-0316 2024-11-21 11:01 2014-08-13 Show GitHub Exploit DB Packet Storm
292079 - redhat
opensuse
libvirt
enterprise_linux
opensuse
enterprise_virtualization
libvirt 0.7.5 through 1.2.x before 1.2.5 allows local users to cause a denial of service (read block and hang) via a crafted XML document containing an XML external entity declaration in conjunction … CWE-20
 Improper Input Validation 
CVE-2014-0179 2024-11-21 11:01 2014-08-4 Show GitHub Exploit DB Packet Storm
292080 - zarafa
fedoraproject
zarafa
webapp
fedora
WebAccess in Zarafa before 7.1.10 and WebApp before 1.6 stores credentials in cleartext, which allows local Apache users to obtain sensitive information by reading the PHP session files. CWE-310
Cryptographic Issues
CVE-2014-0103 2024-11-21 11:01 2014-07-29 Show GitHub Exploit DB Packet Storm