Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 21, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
201911 9.8 緊急
Network
Zoho Corporation - ZOHO WebNMS Framework における認証を回避される脆弱性 CWE-20
不適切な入力確認
CVE-2016-6603 2017-02-7 14:23 2016-07-4 Show GitHub Exploit DB Packet Storm
201912 9.8 緊急
Network
Zoho Corporation - ZOHO WebNMS Framework における平文のパスワードを取得される脆弱性 CWE-327
不完全、または危険な暗号アルゴリズムの使用
CVE-2016-6602 2017-02-7 14:23 2016-07-4 Show GitHub Exploit DB Packet Storm
201913 7.5 重要
Network
Zoho Corporation - ZOHO WebNMS Framework のファイルダウンロード機能におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2016-6601 2017-02-7 14:23 2016-07-4 Show GitHub Exploit DB Packet Storm
201914 9.8 緊急
Network
Zoho Corporation - ZOHO WebNMS Framework のファイルアップロード機能におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2016-6600 2017-02-7 14:23 2016-07-4 Show GitHub Exploit DB Packet Storm
201915 9.8 緊急
Network
Michael Davis - python-jose における脆弱性 CWE-361
時間とステータス
CVE-2016-7036 2017-02-7 14:20 2016-09-5 Show GitHub Exploit DB Packet Storm
201916 9.8 緊急
Network
The GIFLIB project - GIFLIB の gifcolor.c における脆弱性 CWE-415
CWE-416
CVE-2016-3177 2017-02-7 14:19 2016-03-15 Show GitHub Exploit DB Packet Storm
201917 6.5 警告
Network
moment project - Node.js 用 moment パッケージの duration 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2016-4055 2017-02-7 13:38 2016-01-27 Show GitHub Exploit DB Packet Storm
201918 8.8 重要
Network
Grails project - Grails Console におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2016-6521 2017-02-7 12:02 2016-07-1 Show GitHub Exploit DB Packet Storm
201919 7.5 重要
Network
Dominik Reichl - KeePass の自動更新機能における任意のコードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2016-5119 2017-02-7 11:54 2016-06-1 Show GitHub Exploit DB Packet Storm
201920 6.1 警告
Network
mustache project - Node.js 用 mustache パッケージにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2015-8862 2017-02-7 11:48 2015-12-15 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 21, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
292901 - ibm rational_requirements_composer
rational_doors_next_generation
Unspecified vulnerability in IBM Rational Requirements Composer 3.x before 3.0.1.6 iFix2 and 4.x before 4.0.6, and Rational DOORS Next Generation 4.x before 4.0.6, allows remote authenticated users t… NVD-CWE-noinfo
CVE-2014-0844 2024-11-21 11:02 2014-03-5 Show GitHub Exploit DB Packet Storm
292902 - ibm rational_collaborative_lifecycle_management Unspecified vulnerability in Jazz Team Server in IBM Rational Collaborative Lifecycle Management (CLM) 3.x before 3.0.1.6 iFix 2 and 4.x before 4.0.6 allows remote attackers to execute arbitrary code… NVD-CWE-noinfo
CVE-2014-0862 2024-11-21 11:02 2014-03-2 Show GitHub Exploit DB Packet Storm
292903 - ibm content_navigator Cross-site scripting (XSS) vulnerability in IBM Content Navigator 2.x before 2.0.2.2-ICN-FP002 allows remote authenticated users to inject arbitrary web script or HTML via an unspecified parameter. CWE-79
Cross-site Scripting
CVE-2014-0874 2024-11-21 11:02 2014-02-28 Show GitHub Exploit DB Packet Storm
292904 - schneider-electric ofs_test_client_tlxcdlfofs33
ofs_test_client_tlxcdsuofs33
ofs_test_client_tlxcdltofs33
ofs_test_client_tlxcdstofs33
ofs_test_client_tlxcdluofs33
opc_factory_server
Stack-based buffer overflow in the C++ sample client in Schneider Electric OPC Factory Server (OFS) TLXCDSUOFS33 - 3.35, TLXCDSTOFS33 - 3.35, TLXCDLUOFS33 - 3.35, TLXCDLTOFS33 - 3.35, and TLXCDLFOFS3… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2014-0774 2024-11-21 11:02 2014-02-28 Show GitHub Exploit DB Packet Storm
292905 - schneider-electric floating_license_manager Unquoted Windows search path vulnerability in Schneider Electric Floating License Manager 1.0.0 through 1.4.0 allows local users to gain privileges via a Trojan horse application with a name composed… NVD-CWE-Other
CVE-2014-0759 2024-11-21 11:02 2014-02-28 Show GitHub Exploit DB Packet Storm
292906 - ibm content_navigator IBM Content Navigator 2.x before 2.0.2.2-ICN-FP002 allows remote authenticated users to bypass intended access restrictions and conduct deleteAction attacks via a modified URL. CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-0858 2024-11-21 11:02 2014-02-28 Show GitHub Exploit DB Packet Storm
292907 - cisco prime_infrastructure Cisco Prime Infrastructure 1.2 and 1.3 before 1.3.0.20-2, 1.4 before 1.4.0.45-2, and 2.0 before 2.0.0.0.294-2 allows remote authenticated users to execute arbitrary commands with root privileges via … CWE-20
 Improper Input Validation 
CVE-2014-0679 2024-11-21 11:02 2014-02-28 Show GitHub Exploit DB Packet Storm
292908 - cybozu garoon SQL injection vulnerability in the download feature in Cybozu Garoon 2.x through 2.5.4 and 3.x through 3.7 SP3 allows remote authenticated users to execute arbitrary SQL commands via unspecified vect… CWE-89
SQL Injection
CVE-2014-0821 2024-11-21 11:02 2014-02-27 Show GitHub Exploit DB Packet Storm
292909 - cybozu garoon Directory traversal vulnerability in the download feature in Cybozu Garoon 2.x through 2.5.4 and 3.x through 3.7 SP3 allows remote authenticated users to read arbitrary files via unspecified vectors. CWE-22
Path Traversal
CVE-2014-0820 2024-11-21 11:02 2014-02-27 Show GitHub Exploit DB Packet Storm
292910 - cybozu garoon Cybozu Garoon 2.x through 2.5.4 and 3.x through 3.7 SP3 does not properly manage sessions, which allows remote authenticated users to impersonate arbitrary users via unspecified vectors. CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-0817 2024-11-21 11:02 2014-02-27 Show GitHub Exploit DB Packet Storm