Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 7, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
201691 8.8 重要
Network
Google
openSUSE project
- Google Chrome で使用される Blink の WebKit/Source/bindings/modules/v8/V8BindingForModules.cpp におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2016-5150 2016-11-18 16:34 2016-08-31 Show GitHub Exploit DB Packet Storm
201692 8.8 重要
Network
Google
openSUSE project
- Google Chrome の拡張サブシステムにおける拡張バインディングインジェクション攻撃を実行される脆弱性 CWE-94
コード・インジェクション
CVE-2016-5149 2016-11-18 16:34 2016-08-31 Show GitHub Exploit DB Packet Storm
201693 5.9 警告
Network
Wireshark - Wireshark の OpenFlow ディセクタにおけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2016-9376 2016-11-18 16:12 2016-11-16 Show GitHub Exploit DB Packet Storm
201694 5.9 警告
Network
Wireshark - Wireshark の DTN ディセクタにおけるサービス運用妨害 (DoS) の脆弱性 CWE-20
CWE-399
CVE-2016-9375 2016-11-18 16:12 2016-11-16 Show GitHub Exploit DB Packet Storm
201695 5.9 警告
Network
Wireshark - Wireshark の AllJoyn ディセクタにおけるサービス運用妨害 (DoS) の脆弱性 CWE-119
CWE-399
CVE-2016-9374 2016-11-18 16:12 2016-11-16 Show GitHub Exploit DB Packet Storm
201696 5.9 警告
Network
Wireshark - Wireshark の DCERPC ディセクタにおけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2016-9373 2016-11-18 16:12 2016-11-16 Show GitHub Exploit DB Packet Storm
201697 5.9 警告
Network
Wireshark - Wireshark の Profinet I/O ディセクタにおけるサービス運用妨害 (DoS) の脆弱性 CWE-20
CWE-399
CVE-2016-9372 2016-11-18 16:12 2016-11-16 Show GitHub Exploit DB Packet Storm
201698 8.8 重要
Network
Google
openSUSE project
- Google Chrome におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2016-5167 2016-11-18 13:59 2016-08-31 Show GitHub Exploit DB Packet Storm
201699 3.1
Network
Google
openSUSE project
- Google Chrome のダウンロードの実装における NetNTLM ハッシュを取得される脆弱性 CWE-200
情報漏えい
CVE-2016-5166 2016-11-18 13:59 2016-08-31 Show GitHub Exploit DB Packet Storm
201700 6.1 警告
Network
Google
openSUSE project
- Google Chrome の Developer Tools サブシステムにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-5165 2016-11-18 13:59 2016-08-31 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 7, 2026, 4:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
289771 - apple safari WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, does not properly validate WebProcess IPC messages, which allows remote attackers to bypass a sandbox protection mechanism and read … CWE-20
 Improper Input Validation 
CVE-2014-1297 2024-11-21 11:04 2014-04-3 Show GitHub Exploit DB Packet Storm
289772 - horde horde_application_framework The framework/Util/lib/Horde/Variables.php script in the Util library in Horde before 5.1.1 allows remote attackers to conduct object injection attacks and execute arbitrary PHP code via a crafted se… CWE-94
Code Injection
CVE-2014-1691 2024-11-21 11:04 2014-04-2 Show GitHub Exploit DB Packet Storm
289773 - mozilla firefox The saltProfileName function in base/GeckoProfileDirectories.java in Mozilla Firefox through 28.0.1 on Android relies on Android's weak approach to seeding the Math.random function, which makes it ea… CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-1516 2024-11-21 11:04 2014-03-30 Show GitHub Exploit DB Packet Storm
289774 - symantec liveupdate_administrator SQL injection vulnerability in forcepasswd.do in the management GUI in Symantec LiveUpdate Administrator (LUA) 2.x before 2.3.2.110 allows remote attackers to execute arbitrary SQL commands via unspe… CWE-89
SQL Injection
CVE-2014-1645 2024-11-21 11:04 2014-03-29 Show GitHub Exploit DB Packet Storm
289775 - symantec liveupdate_administrator The forgotten-password feature in forcepasswd.do in the management GUI in Symantec LiveUpdate Administrator (LUA) 2.x before 2.3.2.110 allows remote attackers to reset arbitrary passwords by providin… CWE-255
Credentials Management
CVE-2014-1644 2024-11-21 11:04 2014-03-29 Show GitHub Exploit DB Packet Storm
289776 - apple safari Heap-based buffer overflow in Apple Safari 7.0.2 allows remote attackers to execute arbitrary code and bypass a sandbox protection mechanism via unspecified vectors, as demonstrated by Liang Chen dur… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2014-1303 2024-11-21 11:04 2014-03-26 Show GitHub Exploit DB Packet Storm
289777 - apple safari Unspecified vulnerability in Apple Safari 7.0.2 on OS X allows remote attackers to execute arbitrary code with root privileges via unknown vectors, as demonstrated by Google during a Pwn4Fun competit… NVD-CWE-noinfo
CVE-2014-1300 2024-11-21 11:04 2014-03-26 Show GitHub Exploit DB Packet Storm
289778 - mozilla firefox Mozilla Firefox before 28.0.1 on Android processes a file: URL by copying a local file onto the SD card, which allows attackers to obtain sensitive information from the Firefox profile directory via … CWE-200
Information Exposure
CVE-2014-1515 2024-11-21 11:04 2014-03-25 Show GitHub Exploit DB Packet Storm
289779 - mozilla network_security_services The cert_TestHostName function in lib/certdb/certdb.c in the certificate-checking implementation in Mozilla Network Security Services (NSS) before 3.16 accepts a wildcard character that is embedded i… CWE-20
 Improper Input Validation 
CVE-2014-1492 2024-11-21 11:04 2014-03-25 Show GitHub Exploit DB Packet Storm
289780 - debian
mantisbt
debian_linux
mantisbt
Multiple SQL injection vulnerabilities in MantisBT before 1.2.16 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to the (1) mc_project_get_attachments function in … CWE-89
SQL Injection
CVE-2014-1609 2024-11-21 11:04 2014-03-21 Show GitHub Exploit DB Packet Storm