Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 25, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
202441 6.8 警告
Physics
Google - Android の providers/settings/SettingsProvider.java における SAFE_BOOT_DISALLOWED 保護メカニズムを回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-3876 2016-09-14 16:46 2016-09-6 Show GitHub Exploit DB Packet Storm
202442 6.8 警告
Physics
Google - Android の server/wm/WindowManagerService.java におけるアクセス制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-3875 2016-09-14 16:45 2016-09-6 Show GitHub Exploit DB Packet Storm
202443 7.8 重要
Local
Google - Nexus 5X デバイス上で稼動する Android の Qualcomm Wi-Fi ドライバの CORE/HDD/src/wlan_hdd_wext.c における権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-3874 2016-09-14 16:45 2016-09-6 Show GitHub Exploit DB Packet Storm
202444 7.8 重要
Local
Google - Nexus 9 デバイス上で稼動する Android の NVIDIA カーネルにおける権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-3873 2016-09-14 16:45 2016-09-6 Show GitHub Exploit DB Packet Storm
202445 7.8 重要
Local
Google - Android のメディアサーバの libstagefright の codecs/on2/dec/SoftVPX.cpp におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2016-3872 2016-09-14 16:45 2016-09-6 Show GitHub Exploit DB Packet Storm
202446 7.8 重要
Local
Google - Android のメディアサーバの libstagefright の codecs/mp3dec/SoftMP3.cpp におけるバッファオーバーフローの脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-3871 2016-09-14 16:45 2016-09-6 Show GitHub Exploit DB Packet Storm
202447 7.8 重要
Local
Google - Android のメディアサーバの libstagefright の omx/SimpleSoftOMXComponent.cpp における権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-3870 2016-09-14 16:45 2016-09-6 Show GitHub Exploit DB Packet Storm
202448 7.8 重要
Local
Google - 複数の Nexus および Pixel C デバイス上で稼動する Android の Broadcom Wi-Fi ドライバにおける権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-3869 2016-09-14 16:45 2016-09-6 Show GitHub Exploit DB Packet Storm
202449 7.8 重要
Local
Google - Nexus 5X および 6P デバイス上で稼動する Android の Qualcomm IPA ドライバにおける権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-3867 2016-09-14 16:45 2016-09-6 Show GitHub Exploit DB Packet Storm
202450 7.8 重要
Local
Google - 複数の Nexus デバイス上で稼動する Android の Qualcomm サウンドドライバにおける権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-3866 2016-09-14 16:45 2016-09-6 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 26, 2026, 4:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
291591 - kde kdelibs kioslave/http/http.cpp in KIO in kdelibs 4.10.3 and earlier allows attackers to discover credentials via a crafted request that triggers an "internal server error," which includes the username and pa… CWE-200
Information Exposure
CVE-2013-2074 2024-11-21 10:50 2014-02-6 Show GitHub Exploit DB Packet Storm
291592 - apache activemq Cross-site scripting (XSS) vulnerability in the Portfolio publisher servlet in the demo web application in Apache ActiveMQ before 5.9.0 allows remote attackers to inject arbitrary web script or HTML … CWE-79
Cross-site Scripting
CVE-2013-1880 2024-11-21 10:50 2014-02-6 Show GitHub Exploit DB Packet Storm
291593 - mediaelementjs
owncloud
mediaelement.js
owncloud
Cross-site scripting (XSS) vulnerability in flashmediaelement.swf in MediaElement.js before 2.11.2, as used in ownCloud Server 5.0.x before 5.0.5 and 4.5.x before 4.5.10, allows remote attackers to i… CWE-79
Cross-site Scripting
CVE-2013-1967 2024-11-21 10:50 2014-02-6 Show GitHub Exploit DB Packet Storm
291594 - kolja_schleich leaguemanager SQL injection vulnerability in leaguemanager.php in the LeagueManager plugin before 3.8.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the league_id parameter in the le… CWE-89
SQL Injection
CVE-2013-1852 2024-11-21 10:50 2014-02-6 Show GitHub Exploit DB Packet Storm
291595 - almanah_project almanah Almanah Diary 0.9.0 and 0.10.0 does not encrypt the database when closed, which allows local users to obtain sensitive information by reading the database. CWE-310
Cryptographic Issues
CVE-2013-1853 2024-11-21 10:50 2014-01-25 Show GitHub Exploit DB Packet Storm
291596 - redhat dogtag_certificate_system
certificate_system
Format string vulnerability in the token processing system (pki-tps) in Red Hat Certificate System (RHCS) 8.1 and possibly Dogtag Certificate System 9 and 10 allows remote authenticated users to caus… CWE-134
Use of Externally-Controlled Format String
CVE-2013-1886 2024-11-21 10:50 2014-01-25 Show GitHub Exploit DB Packet Storm
291597 - redhat dogtag_certificate_system
certificate_system
Multiple cross-site scripting (XSS) vulnerabilities in the token processing system (pki-tps) in Red Hat Certificate System (RHCS) 8.1 and possibly Dogtag Certificate System 9 and 10 allow remote atta… CWE-79
Cross-site Scripting
CVE-2013-1885 2024-11-21 10:50 2014-01-25 Show GitHub Exploit DB Packet Storm
291598 - linux-nfs nfs-utils rpc-gssd in nfs-utils before 1.2.8 performs reverse DNS resolution for server names during GSSAPI authentication, which might allow remote attackers to read otherwise-restricted files via DNS spoofin… CWE-200
Information Exposure
CVE-2013-1923 2024-11-21 10:50 2014-01-22 Show GitHub Exploit DB Packet Storm
291599 - simon_mcvittie telepathy_gabble A certain hashing algorithm in Telepathy Gabble 0.16.x before 0.16.5 and 0.17.x before 0.17.3 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted m… CWE-310
Cryptographic Issues
CVE-2013-1769 2024-11-21 10:50 2014-01-22 Show GitHub Exploit DB Packet Storm
291600 - mozilla network_security_services The ssl_Do1stHandshake function in sslsecur.c in libssl in Mozilla Network Security Services (NSS) before 3.15.4, when the TLS False Start feature is enabled, allows man-in-the-middle attackers to sp… CWE-310
Cryptographic Issues
CVE-2013-1740 2024-11-21 10:50 2014-01-19 Show GitHub Exploit DB Packet Storm