Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 19, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
202361 6.1 警告
Network
シスコシステムズ - Cisco Prime Service Catalog の Web ベースの管理インターフェースにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-1462 2016-08-1 16:55 2016-07-27 Show GitHub Exploit DB Packet Storm
202362 6.5 警告
Adjacent
シスコシステムズ - Cisco Wireless LAN Controller デバイスにおけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2016-1460 2016-08-1 16:55 2016-07-27 Show GitHub Exploit DB Packet Storm
202363 8.8 重要
Network
シスコシステムズ - Cisco Unified Computing System Performance Manager の Web フレームワークにおける任意のコマンドを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2016-1374 2016-08-1 16:55 2016-07-20 Show GitHub Exploit DB Packet Storm
202364 6.2 警告
Local
Debian
openSUSE project
cronic project
- cronic における任意のファイルに書き込まれる脆弱性 CWE-Other
その他
CVE-2016-3992 2016-08-1 16:28 2016-04-11 Show GitHub Exploit DB Packet Storm
202365 7.5 重要
Network
シーメンス - Siemens SIMATIC WinCC における任意の WinCC ステーションファイルを読まれる脆弱性 CWE-200
情報漏えい
CVE-2016-5744 2016-08-1 16:10 2016-07-22 Show GitHub Exploit DB Packet Storm
202366 9.8 緊急
Network
シーメンス - 複数の Siemens SIMATIC 製品における任意のコードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2016-5743 2016-08-1 16:10 2016-07-22 Show GitHub Exploit DB Packet Storm
202367 7.3 重要
Network
Rockwell Automation - Rockwell Automation FactoryTalk EnergyMetrix におけるアクセス権を取得される脆弱性 CWE-Other
その他
CVE-2016-4531 2016-08-1 14:54 2016-07-26 Show GitHub Exploit DB Packet Storm
202368 9.8 緊急
Network
Rockwell Automation - Rockwell Automation FactoryTalk EnergyMetrix における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2016-4522 2016-08-1 14:54 2016-07-26 Show GitHub Exploit DB Packet Storm
202369 9.8 緊急
Network
ICU project - International Components for Unicode の common/uloc.cpp におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2016-6293 2016-08-1 14:12 2016-07-13 Show GitHub Exploit DB Packet Storm
202370 6.1 警告
Network
シーメンス - Siemens SINEMA Remote Connect Server の統合 Web サーバにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-6204 2016-08-1 11:27 2016-07-22 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 19, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
291161 - digineo thumbshooter lib/thumbshooter.rb in the Thumbshooter 0.1.5 gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL. CWE-94
Code Injection
CVE-2013-1898 2024-11-21 10:50 2013-04-10 Show GitHub Exploit DB Packet Storm
291162 - dan_kubb extlib The extlib gem 0.9.15 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-injection attacks and execute arbitrary code, or cau… CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-1802 2024-11-21 10:50 2013-04-10 Show GitHub Exploit DB Packet Storm
291163 - john_nunemaker httparty The httparty gem 0.9.0 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-injection attacks and execute arbitrary code, or ca… CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-1801 2024-11-21 10:50 2013-04-10 Show GitHub Exploit DB Packet Storm
291164 - john_nunemaker crack The crack gem 0.3.1 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-injection attacks and execute arbitrary code, or cause… CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-1800 2024-11-21 10:50 2013-04-10 Show GitHub Exploit DB Packet Storm
291165 - freedesktop poppler poppler/Stream.cc in poppler before 0.22.1 allows context-dependent attackers to have an unspecified impact via vectors that trigger a read of uninitialized memory by the CCITTFaxStream::lookChar fun… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2013-1790 2024-11-21 10:50 2013-04-10 Show GitHub Exploit DB Packet Storm
291166 - freedesktop poppler splash/Splash.cc in poppler before 0.22.1 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to the (1) Splash::arbitraryTransfor… NVD-CWE-Other
CVE-2013-1789 2024-11-21 10:50 2013-04-10 Show GitHub Exploit DB Packet Storm
291167 - freedesktop poppler poppler before 0.22.1 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors that trigger an "invalid memory access" in (1) splash/Spl… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2013-1788 2024-11-21 10:50 2013-04-10 Show GitHub Exploit DB Packet Storm
291168 - apple
todd_miller
mac_os_x
sudo
sudo 1.3.5 through 1.7.10 and 1.8.0 through 1.8.5, when the tty_tickets option is enabled, does not properly validate the controlling terminal device, which allows local users with sudo permissions t… CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-1776 2024-11-21 10:50 2013-04-9 Show GitHub Exploit DB Packet Storm
291169 - linux linux_kernel The clone system-call implementation in the Linux kernel before 3.8.3 does not properly handle a combination of the CLONE_NEWUSER and CLONE_FS flags, which allows local users to gain privileges by ca… CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-1858 2024-11-21 10:50 2013-04-6 Show GitHub Exploit DB Packet Storm
291170 - postgresql postgresql PostgreSQL, possibly 9.2.x before 9.2.4, 9.1.x before 9.1.9, 9.0.x before 9.0.13, 8.4.x before 8.4.17, and 8.3.x before 8.3.23 incorrectly provides the superuser password to scripts related to "graph… CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-1903 2024-11-21 10:50 2013-04-5 Show GitHub Exploit DB Packet Storm