Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 28, 2026, 4:09 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
202501 9.8 緊急
Network
AVer Information Inc. - AVer Information EH6108H+ デバイスのファームウェアにおける root アクセス権を取得される脆弱性 CWE-Other
その他
CVE-2016-6535 2016-09-26 14:19 2016-09-13 Show GitHub Exploit DB Packet Storm
202502 5.9 警告
Network
DELL EMC (旧 EMC Corporation) - EMC RSA BSAFE Micro Edition Suite のクライアントにおける暗号保護メカニズムを破られる脆弱性 CWE-Other
その他
CVE-2016-0923 2016-09-26 11:47 2016-09-15 Show GitHub Exploit DB Packet Storm
202503 7.5 重要
Local
ABB - ABB DataManagerPro における権限を取得される脆弱性 CWE-Other
その他
CVE-2016-4526 2016-09-26 11:43 2016-08-18 Show GitHub Exploit DB Packet Storm
202504 5.3 警告
Network
トレイン・ジャパン株式会社 - Trane Tracer SC の Web サーバにおける重要な設定ファイルを読まれる脆弱性 CWE-200
情報漏えい
CVE-2016-0870 2016-09-26 11:32 2016-09-15 Show GitHub Exploit DB Packet Storm
202505 9.8 緊急
Network
ICU project - International Components for Unicode の common/locid.cpp の Locale クラスにおけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2016-7415 2016-09-26 09:39 2016-09-13 Show GitHub Exploit DB Packet Storm
202506 5.5 警告
Local
SUSE
libarchive
Canonical
- libarchive の archive_read_support_format_rar.c の copy_from_lzss_window 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2015-8934 2016-09-23 16:33 2015-06-20 Show GitHub Exploit DB Packet Storm
202507 5.5 警告
Local
SUSE
libarchive
Canonical
- libarchive の archive_read_support_format_tar.c の archive_read_format_tar_skip 関数における整数オーバーフローの脆弱性 CWE-Other
その他
CVE-2015-8933 2016-09-23 16:33 2015-08-9 Show GitHub Exploit DB Packet Storm
202508 5.5 警告
Local
SUSE
libarchive
Debian
Canonical
- libarchive の archive_read_support_filter_compress.c の compress_bidder_init 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2015-8932 2016-09-23 16:33 2015-08-9 Show GitHub Exploit DB Packet Storm
202509 7.8 重要
Local
SUSE
libarchive
Debian
Canonical
- libarchive の archive_read_support_format_mtree.c の get_time_t_max および get_time_t_min 関数における整数オーバーフローの脆弱性 CWE-Other
その他
CVE-2015-8931 2016-09-23 16:33 2015-05-17 Show GitHub Exploit DB Packet Storm
202510 7.5 重要
Network
SUSE
libarchive
Canonical
- libarchive の bsdtar におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2015-8930 2016-09-23 16:33 2015-04-12 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 28, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
289641 - ajaxplorer ajaxplorer Directory traversal vulnerability in plugins/editor.zoho/agent/save_zoho.php in the Zoho plugin in Pydio (formerly AjaXplorer) before 5.0.4 allows remote attackers to read or delete arbitrary files v… CWE-22
Path Traversal
CVE-2013-6226 2024-11-21 10:58 2013-11-15 Show GitHub Exploit DB Packet Storm
289642 - zikula zikula_application_framework Cross-site scripting (XSS) vulnerability in Zikula Application Framework before 1.3.6 allows remote attackers to inject arbitrary web script or HTML via the returnpage parameter to index.php. CWE-79
Cross-site Scripting
CVE-2013-6168 2024-11-21 10:58 2013-11-15 Show GitHub Exploit DB Packet Storm
289643 - projeqtor projeqtor SQL injection vulnerability in view/objectDetail.php in Project'Or RIA 3.4.0 allows remote attackers to execute arbitrary SQL commands via the objectId parameter. CWE-89
SQL Injection
CVE-2013-6164 2024-11-21 10:58 2013-11-15 Show GitHub Exploit DB Packet Storm
289644 - projeqtor projeqtor Multiple cross-site scripting (XSS) vulnerabilities in ProjeQtOr (formerly Project'Or RIA) before 4.0.0 allow remote attackers to inject arbitrary web script or HTML via the (1) type parameter to vie… CWE-79
Cross-site Scripting
CVE-2013-6163 2024-11-21 10:58 2013-11-15 Show GitHub Exploit DB Packet Storm
289645 - apprain apprain SQL injection vulnerability in appRain CMF 3.0.2 and earlier allows remote attackers to execute arbitrary SQL commands via the PATH_INFO to blog-by-cat/. CWE-89
SQL Injection
CVE-2013-6058 2024-11-21 10:58 2013-11-15 Show GitHub Exploit DB Packet Storm
289646 - justsystems ichitaro_pro
ichitaro_portable_with_oreplug
ichitaro
ichitaro_viewer
Unspecified vulnerability in JustSystems Ichitaro 2006 through 2011; Ichitaro Government 6, 7, and 2006 through 2010; Ichitaro 2011 Sou; Ichitaro 2012 Shou; Ichitaro 2013 Gen and Gen Trial Edition; I… NVD-CWE-noinfo
CVE-2013-5990 2024-11-21 10:58 2013-11-14 Show GitHub Exploit DB Packet Storm
289647 - tapbots tweetbot Tweetbot 1.3.3 for Mac, and 2.8.5 for iPad and iPhone, does not require confirmation of (1) follow or (2) favorite actions, which allows remote attackers to automatically force the user to perform un… CWE-352
 Origin Validation Error
CVE-2013-5726 2024-11-21 10:58 2013-11-13 Show GitHub Exploit DB Packet Storm
289648 - qualcomm quic_mobile_station_modem_kernel goodix_tool.c in the Goodix gt915 touchscreen driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not properly… CWE-20
 Improper Input Validation 
CVE-2013-6122 2024-11-21 10:58 2013-11-12 Show GitHub Exploit DB Packet Storm
289649 - isc bind The Winsock WSAIoctl API in Microsoft Windows Server 2008, as used in ISC BIND 9.6-ESV before 9.6-ESV-R10-P1, 9.8 before 9.8.6-P1, 9.9 before 9.9.4-P1, 9.9.3-S1, 9.9.4-S1, and other products, does no… CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-6230 2024-11-21 10:58 2013-11-8 Show GitHub Exploit DB Packet Storm
289650 - roundcube webmail steps/utils/save_pref.inc in Roundcube webmail before 0.8.7 and 0.9.x before 0.9.5 allows remote attackers to modify configuration settings via the _session parameter, which can be leveraged to read … CWE-89
SQL Injection
CVE-2013-6172 2024-11-21 10:58 2013-11-6 Show GitHub Exploit DB Packet Storm