Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 18, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
202471 4.7 警告 Xen プロジェクト
Linux
オラクル
- Linux Kernel の KVM サブシステムおよび Xen におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2015-8104 2016-07-27 16:14 2015-11-10 Show GitHub Exploit DB Packet Storm
202472 5 警告 Embedthis Software, LLC
オラクル
- Embedthis Appweb におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2014-9708 2016-07-27 15:33 2014-11-27 Show GitHub Exploit DB Packet Storm
202473 6.4 警告 オラクル - Oracle Database における総当りパスワード推測攻撃を実行される脆弱性 CWE-287
不適切な認証
CVE-2012-3137 2016-07-27 15:13 2012-09-21 Show GitHub Exploit DB Packet Storm
202474 6.8 警告 X.Org Foundation
オラクル
- X.org libxcb における整数オーバーフローの脆弱性 CWE-189
数値処理の問題
CVE-2013-2064 2016-07-27 14:53 2013-05-23 Show GitHub Exploit DB Packet Storm
202475 4.7 警告
Network
オラクル - Oracle E-Business Suite の Oracle Email Center における Email Center Agent Console に関する脆弱性 CWE-noinfo
情報不足
CVE-2016-3559 2016-07-27 14:32 2016-07-19 Show GitHub Exploit DB Packet Storm
202476 4.7 警告
Network
オラクル - Oracle E-Business Suite の Oracle Email Center における Email Center Agent Console に関する脆弱性 CWE-noinfo
情報不足
CVE-2016-3558 2016-07-27 14:32 2016-07-19 Show GitHub Exploit DB Packet Storm
202477 5.3 警告
Network
オラクル - Oracle E-Business Suite の Oracle E-Business Suite Secure Enterprise Search における Search Integration Engine に関する脆弱性 CWE-noinfo
情報不足
CVE-2016-3549 2016-07-27 14:32 2016-07-19 Show GitHub Exploit DB Packet Storm
202478 5.3 警告
Network
オラクル - Oracle E-Business Suite の Oracle Marketing における Marketing activity collateral に関する脆弱性 CWE-noinfo
情報不足
CVE-2016-3548 2016-07-27 14:31 2016-07-19 Show GitHub Exploit DB Packet Storm
202479 5.3 警告
Network
オラクル - Oracle E-Business Suite の Oracle One-to-One Fulfillment における Content Manager に関する脆弱性 CWE-noinfo
情報不足
CVE-2016-3547 2016-07-27 14:31 2016-07-19 Show GitHub Exploit DB Packet Storm
202480 9.1 緊急
Network
オラクル - Oracle E-Business Suite の Oracle Advanced Collections における Report JSPs に関する脆弱性 CWE-noinfo
情報不足
CVE-2016-3546 2016-07-27 14:31 2016-07-19 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 18, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
291211 - puppetlabs
puppet
puppet
puppet_enterprise
Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) node request management, (2) live management, and (3) user administration components in the console in Puppet Enterprise (PE) bef… CWE-352
 Origin Validation Error
CVE-2013-1399 2024-11-21 10:49 2014-03-15 Show GitHub Exploit DB Packet Storm
291212 - puppetlabs
puppet
puppet
puppet_enterprise
The pe_mcollective module in Puppet Enterprise (PE) before 2.7.1 does not properly restrict access to a catalog of private SSL keys, which allows remote authenticated users to obtain sensitive inform… CWE-310
Cryptographic Issues
CVE-2013-1398 2024-11-21 10:49 2014-03-15 Show GitHub Exploit DB Packet Storm
291213 - commentluv commentluv Cross-site scripting (XSS) vulnerability in the CommentLuv plugin before 2.92.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the _ajax_nonce parameter to wp-admin/… CWE-79
Cross-site Scripting
CVE-2013-1409 2024-11-21 10:49 2014-03-4 Show GitHub Exploit DB Packet Storm
291214 - i-doit i-doit Multiple cross-site scripting (XSS) vulnerabilities in synetics i-doit open 0.9.9-7, i-doit pro 1.0 and earlier, and i-doit pro 1.0.2 when the 'sanitize user input' flag is not enabled, allow remote … CWE-79
Cross-site Scripting
CVE-2013-1413 2024-11-21 10:49 2014-02-12 Show GitHub Exploit DB Packet Storm
291215 - geeklog geeklog Cross-site scripting (XSS) vulnerability in calendar/index.php in the Calendar plugin in Geeklog before 1.8.2sr1 and 2.0.0 before 2.0.0rc2 allows remote attackers to inject arbitrary web script or HT… CWE-79
Cross-site Scripting
CVE-2013-1470 2024-11-21 10:49 2014-02-6 Show GitHub Exploit DB Packet Storm
291216 - glfusion glfusion Multiple cross-site scripting (XSS) vulnerabilities in glFusion before 1.2.2.pl4 allow remote attackers to inject arbitrary web script or HTML via the (1) subject parameter to profiles.php; (2) addre… CWE-79
Cross-site Scripting
CVE-2013-1466 2024-11-21 10:49 2014-02-6 Show GitHub Exploit DB Packet Storm
291217 - adobe acrobat_reader
acrobat
Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability … CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2013-1376 2024-11-21 10:49 2014-01-31 Show GitHub Exploit DB Packet Storm
291218 - lenovo thinkpad_bluetooth_with_enhanced_data_rate_software Untrusted search path vulnerability in Lenovo Thinkpad Bluetooth with Enhanced Data Rate Software 6.4.0.2900 and earlier allows local users, and possibly remote attackers, to execute arbitrary code a… NVD-CWE-Other
CVE-2013-1361 2024-11-21 10:49 2014-01-22 Show GitHub Exploit DB Packet Storm
291219 - dave_coffin dcraw Unspecified vulnerability in dcraw 0.8.x through 0.8.9, as used in libraw, ufraw, shotwell, and other products, allows context-dependent attackers to cause a denial of service via a crafted photo fil… NVD-CWE-noinfo
CVE-2013-1438 2024-11-21 10:49 2014-01-20 Show GitHub Exploit DB Packet Storm
291220 - zabbix zabbix The user.login function in Zabbix before 1.8.16 and 2.x before 2.0.5rc1 allows remote attackers to override LDAP configuration via the cnf parameter. CWE-287
Improper Authentication
CVE-2013-1364 2024-11-21 10:49 2013-12-15 Show GitHub Exploit DB Packet Storm