Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 25, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
201951 9.8 緊急
Network
Facebook - Facebook HHVM の bcmath における整数オーバーフローの脆弱性 CWE-190
整数オーバーフローまたはラップアラウンド
CVE-2016-6871 2017-03-7 16:43 2016-08-2 Show GitHub Exploit DB Packet Storm
201952 9.8 緊急
Network
Facebook - Facebook HHVM の複数の関数における境界外書き込みの脆弱性 CWE-787
境界外書き込み
CVE-2016-6870 2017-03-7 16:43 2016-07-2 Show GitHub Exploit DB Packet Storm
201953 7.5 重要
Network
WSO2 - WSO2 Identity Server の XACML フロー機能における XML 外部エンティティの脆弱性 CWE-611
XML 外部エンティティ参照の不適切な制限
CVE-2016-4312 2017-03-7 16:17 2016-08-12 Show GitHub Exploit DB Packet Storm
201954 8.8 重要
Network
WSO2 - WSO2 Identity Server の XACML フロー機能におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2016-4311 2017-03-7 16:17 2016-08-12 Show GitHub Exploit DB Packet Storm
201955 9.8 緊急
Network
Zend Technologies Ltd.
Fedora Project
- Zend Framework の Zend_Db_Select の order および group メソッドにおける SQL インジェクション攻撃を実行される脆弱性 CWE-89
SQLインジェクション
CVE-2016-6233 2017-03-7 15:36 2016-07-13 Show GitHub Exploit DB Packet Storm
201956 5.9 警告
Network
Timo Sirainen - Dovecot の auth コンポーネントにおけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2016-8652 2017-03-7 15:29 2016-12-3 Show GitHub Exploit DB Packet Storm
201957 6.1 警告
Network
Kabona AB - Kabona AB WebDatorCentral (WDC) アプリケーションにおける脆弱性 CWE-601
オープンリダイレクト
CVE-2016-8376 2017-03-7 15:18 2016-10-13 Show GitHub Exploit DB Packet Storm
201958 8.2 重要
Network
Kabona AB - Kabona AB WebDatorCentral (WDC) アプリケーションにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-8356 2017-03-7 15:18 2016-10-13 Show GitHub Exploit DB Packet Storm
201959 9.8 緊急
Network
Algorithm - BINOM3 Universal Multifunctional Electric Power Quality Meter における脆弱性 CWE-798
ハードコードされた認証情報の使用
CVE-2017-5167 2017-03-7 15:15 2017-01-31 Show GitHub Exploit DB Packet Storm
201960 9.8 緊急
Network
Algorithm - BINOM3 Universal Multifunctional Electric Power Quality Meter におけるデバイスへのアクセス権を取得される脆弱性 CWE-200
情報漏えい
CVE-2017-5166 2017-03-7 15:15 2017-01-31 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 25, 2026, 4:04 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
289151 - freelinking_for_case_tracker_project
freelinking_project
freelinking_for_case_tracker
freelinking
The freelinking module for Drupal, as used in the Freelinking for Case Tracker module, does not properly check access permissions for (1) nodes or (2) users, which allows remote attackers to obtain s… CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-5179 2024-11-21 11:11 2014-08-7 Show GitHub Exploit DB Packet Storm
289152 - efssoft easy_file_sharing_web_server Multiple cross-site scripting (XSS) vulnerabilities in Easy File Sharing (EFS) Web Server 6.8 allow remote authenticated users to inject arbitrary web script or HTML via the content parameter when (1… CWE-79
Cross-site Scripting
CVE-2014-5178 2024-11-21 11:11 2014-08-7 Show GitHub Exploit DB Packet Storm
289153 - status2k status2k admin/options/logs.php in Status2k allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the Location field in Add Logs in the Admin Panel. CWE-94
Code Injection
CVE-2014-5090 2024-11-21 11:11 2014-08-7 Show GitHub Exploit DB Packet Storm
289154 - status2k status2k SQL injection vulnerability in admin/options/logs.php in Status2k allows remote authenticated administrators to execute arbitrary SQL commands via the log parameter. CWE-89
SQL Injection
CVE-2014-5089 2024-11-21 11:11 2014-08-7 Show GitHub Exploit DB Packet Storm
289155 - status2k status2k Cross-site scripting (XSS) vulnerability in Status2k allows remote attackers to inject arbitrary web script or HTML via the username to login.php. CWE-79
Cross-site Scripting
CVE-2014-5088 2024-11-21 11:11 2014-08-7 Show GitHub Exploit DB Packet Storm
289156 - sphider sphider Multiple SQL injection vulnerabilities in admin/admin.php in Sphider 1.3.6 and earlier, Sphider Pro, and Sphider-plus allow remote attackers to execute arbitrary SQL commands via the (1) site_id or (… CWE-89
SQL Injection
CVE-2014-5082 2024-11-21 11:11 2014-08-7 Show GitHub Exploit DB Packet Storm
289157 - redhat
opensuse
enterprise_linux
opensuse
enterprise_virtualization
libvirt
libvirt 1.0.0 through 1.2.x before 1.2.5, when fine grained access control is enabled, allows local users to read arbitrary files via a crafted XML document containing an XML external entity declarat… CWE-20
 Improper Input Validation 
CVE-2014-5177 2024-11-21 11:11 2014-08-4 Show GitHub Exploit DB Packet Storm
289158 - wireshark wireshark The dissect_ber_constrained_bitstring function in epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 1.10.x before 1.10.9 does not properly validate padding values, which allows rem… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2014-5165 2024-11-21 11:11 2014-08-1 Show GitHub Exploit DB Packet Storm
289159 - wireshark wireshark The rlc_decode_li function in epan/dissectors/packet-rlc.c in the RLC dissector in Wireshark 1.10.x before 1.10.9 initializes a certain structure member only after this member is used, which allows r… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2014-5164 2024-11-21 11:11 2014-08-1 Show GitHub Exploit DB Packet Storm
289160 - wireshark wireshark The APN decode functionality in (1) epan/dissectors/packet-gtp.c and (2) epan/dissectors/packet-gsm_a_gm.c in the GTP and GSM Management dissectors in Wireshark 1.10.x before 1.10.9 does not complete… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2014-5163 2024-11-21 11:11 2014-08-1 Show GitHub Exploit DB Packet Storm