Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 20, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
202251 9.8 緊急
Network
Navis - Cargotec Navis WebAccess のニュースページにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2016-5817 2016-08-23 17:16 2016-08-18 Show GitHub Exploit DB Packet Storm
202252 9.8 緊急
Network
Debian
DBD::mysql project
- DBD::mysql におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2014-9906 2016-08-23 16:57 2014-12-8 Show GitHub Exploit DB Packet Storm
202253 9.8 緊急
Network
Debian
DBD::mysql project
- DBD::mysql の my_login 関数における脆弱性 CWE-Other
その他
CVE-2015-8949 2016-08-23 16:57 2015-12-15 Show GitHub Exploit DB Packet Storm
202254 5.4 警告
Network
The Foreman - Foreman の app/assets/javascripts/host_edit_interfaces.js におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-6320 2016-08-23 16:51 2016-08-9 Show GitHub Exploit DB Packet Storm
202255 6.1 警告
Network
The Foreman - Remote Execution などのプラグインによって使用される Foreman におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-6319 2016-08-23 16:51 2016-08-10 Show GitHub Exploit DB Packet Storm
202256 5.3 警告
Network
The Foreman - Foreman における重要なネットワークインターフェース情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2016-5390 2016-08-23 16:51 2016-07-19 Show GitHub Exploit DB Packet Storm
202257 5.3 警告
Network
The Foreman - Foreman における重要なホスト設定情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2016-4995 2016-08-23 16:51 2016-07-13 Show GitHub Exploit DB Packet Storm
202258 8.8 重要
Network
The Foreman - Foreman の Organization および Locations API ならびに UI における組織およびロケーションの制限を回避される脆弱性 CWE-Other
その他
CVE-2016-4475 2016-08-23 16:51 2016-06-23 Show GitHub Exploit DB Packet Storm
202259 5 警告
Network
The Foreman - Foreman の Organization および Locations API における組織およびロケーションの制限を回避される脆弱性 CWE-Other
その他
CVE-2016-4451 2016-08-23 16:51 2016-05-27 Show GitHub Exploit DB Packet Storm
202260 8.1 重要
Network
DELL EMC (旧 EMC Corporation) - EMC RSA Authentication Manager Prime Self-Service のセルフサービスポータルにおけるサービス運用妨害 (DoS) の脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-0915 2016-08-23 15:01 2016-08-8 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 20, 2026, 4:14 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
290301 - ge
catapultsoftware
intelligent_platforms_proficy_dnp3_i\/o_driver
intelligent_platforms_proficy_hmi\/scada_cimplicity
catapult_dnp3_i\/o_driver
intelligent_platforms_proficy_hmi\/scada_ifix
The (1) Catapult DNP3 I/O driver before 7.2.0.60 and the (2) GE Intelligent Platforms Proficy DNP3 I/O driver before 7.20k, as used in DNPDrv.exe (aka the DNP master station server) in GE Intelligent… CWE-20
 Improper Input Validation 
CVE-2013-2811 2024-11-21 10:52 2013-11-22 Show GitHub Exploit DB Packet Storm
290302 - dlink dir865l_firmware
dir865l
Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR865L router (Rev. A1) with firmware before 1.05b07 allow remote attackers to hijack the authentication of administrators for re… CWE-352
 Origin Validation Error
CVE-2013-3095 2024-11-21 10:52 2013-11-20 Show GitHub Exploit DB Packet Storm
290303 - ibm cognos_business_intelligence The servlet gateway in IBM Cognos Business Intelligence 8.4.1 before IF3, 10.1.0 before IF4, 10.1.1 before IF4, 10.2.0 before IF4, 10.2.1 before IF2, and 10.2.1.1 before IF1 allows remote attackers t… CWE-20
 Improper Input Validation 
CVE-2013-3030 2024-11-21 10:52 2013-11-18 Show GitHub Exploit DB Packet Storm
290304 - google chrome Multiple unspecified vulnerabilities in Google Chrome before 31.0.1650.48 allow attackers to execute arbitrary code or possibly have other impact via unknown vectors. NVD-CWE-noinfo
CVE-2013-2931 2024-11-21 10:52 2013-11-14 Show GitHub Exploit DB Packet Storm
290305 - silverstripe silverstripe security/MemberLoginForm.php in SilverStripe 3.0.3 supports login using a GET request, which makes it easier for remote attackers to conduct phishing attacks without detection by the victim. CWE-20
 Improper Input Validation 
CVE-2013-2653 2024-11-21 10:52 2013-11-13 Show GitHub Exploit DB Packet Storm
290306 - ibm lotus_sametime The Enterprise Meeting Server in IBM Lotus Sametime 8.5.2 and 8.5.2.1 allows remote authenticated users to share crafted links via the Library function. CWE-20
 Improper Input Validation 
CVE-2013-3045 2024-11-21 10:52 2013-11-9 Show GitHub Exploit DB Packet Storm
290307 - ibm lotus_sametime The Enterprise Meeting Server in IBM Lotus Sametime 8.5.2 and 8.5.2.1 allows remote authenticated users to spoof the origin of chat messages, or compose anonymous chat messages, by leveraging meeting… CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-3044 2024-11-21 10:52 2013-11-9 Show GitHub Exploit DB Packet Storm
290308 - andrew_simpson webcollab CRLF injection vulnerability in help/help_language.php in WebCollab 3.30 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the item … CWE-79
Cross-site Scripting
CVE-2013-2652 2024-11-21 10:52 2013-11-3 Show GitHub Exploit DB Packet Storm
290309 - linksalpha social_sharing_toolkit_plugin Cross-site request forgery (CSRF) vulnerability in the Social Sharing Toolkit plugin 2.1.1 for WordPress allows remote attackers to hijack the authentication of administrators for requests that manip… CWE-352
 Origin Validation Error
CVE-2013-2701 2024-11-21 10:52 2013-11-2 Show GitHub Exploit DB Packet Storm
290310 - boltwire boltwire Multiple cross-site scripting (XSS) vulnerabilities in BoltWire 3.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) "p" or (2) content parameter to index.php. CWE-79
Cross-site Scripting
CVE-2013-2651 2024-11-21 10:52 2013-10-24 Show GitHub Exploit DB Packet Storm