Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 27, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
202551 7.8 危険 ヒューレット・パッカード
Apache Software Foundation
オラクル
- Apache Tomcat におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2014-0230 2016-09-7 16:52 2014-06-24 Show GitHub Exploit DB Packet Storm
202552 8.1 重要
Network
シスコシステムズ - Cisco Virtual Media Packager の Media Origination System Suite Software における認証を回避される脆弱性 CWE-287
不適切な認証
CVE-2016-6377 2016-09-7 14:14 2016-08-31 Show GitHub Exploit DB Packet Storm
202553 5.3 警告
Network
アップル
Google
マイクロソフト
Mozilla Foundation
Opera Software ASA
- HTTP/2 プロトコルにおける平文データを取得される脆弱性 CWE-200
情報漏えい
CVE-2016-7153 2016-09-7 13:58 2016-08-4 Show GitHub Exploit DB Packet Storm
202554 5.3 警告
Network
アップル
Google
マイクロソフト
Mozilla Foundation
Opera Software ASA
- HTTPS プロトコルにおける平文データを取得される脆弱性 CWE-200
情報漏えい
CVE-2016-7152 2016-09-7 13:58 2016-08-4 Show GitHub Exploit DB Packet Storm
202555 7.8 重要
Local
シスコシステムズ - Cisco WebEx Meetings Player における任意のコードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2016-1464 2016-09-7 12:05 2016-08-31 Show GitHub Exploit DB Packet Storm
202556 5.5 警告
Local
シスコシステムズ - Cisco WebEx Meetings Player におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2016-1415 2016-09-7 12:05 2016-08-31 Show GitHub Exploit DB Packet Storm
202557 9.8 緊急
Network
MISP project - Malware Information Sharing Platform における PHP オブジェクトインジェクション攻撃を実行される脆弱性 CWE-94
コード・インジェクション
CVE-2015-5721 2016-09-7 11:49 2015-07-1 Show GitHub Exploit DB Packet Storm
202558 6.1 警告
Network
MISP project - Malware Information Sharing Platform の template-creation 機能におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2015-5720 2016-09-7 11:49 2015-07-1 Show GitHub Exploit DB Packet Storm
202559 9.8 緊急
Network
MISP project - Malware Information Sharing Platform の app/Controller/TemplatesController.php における脆弱性 CWE-noinfo
情報不足
CVE-2015-5719 2016-09-7 11:49 2015-07-1 Show GitHub Exploit DB Packet Storm
202560 5.5 警告
Local
Google
Bouncy Castle
- Android で使用される RFC 5084 の AES-GCM の要件における暗号保護メカニズムを破られる脆弱性 CWE-200
情報漏えい
CVE-2016-2427 2016-09-6 16:27 2016-04-4 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 27, 2026, 4:52 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
291721 - redhat
theforeman
network_satellite
katello
The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action, which allows remote authenticated users to gain privileges by se… CWE-20
 Improper Input Validation 
CVE-2013-2143 2024-11-21 10:51 2014-04-17 Show GitHub Exploit DB Packet Storm
291722 - roberta_bramski uploader Multiple cross-site scripting (XSS) vulnerabilities in views/notify.php in the Uploader plugin 1.0.4 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) notify or … CWE-79
Cross-site Scripting
CVE-2013-2287 2024-11-21 10:51 2014-04-4 Show GitHub Exploit DB Packet Storm
291723 - jgaa warftpd Unspecified vulnerability in War FTP Daemon (warftpd) 1.82, when running as a Windows service, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unk… NVD-CWE-noinfo
CVE-2013-2278 2024-11-21 10:51 2014-04-1 Show GitHub Exploit DB Packet Storm
291724 - getsymphony symphony SQL injection vulnerability in Symphony CMS before 2.3.2 allows remote authenticated users to execute arbitrary SQL commands via the sort parameter to system/authors/. NOTE: this can be leveraged us… CWE-89
SQL Injection
CVE-2013-2559 2024-11-21 10:51 2014-03-28 Show GitHub Exploit DB Packet Storm
291725 - owncloud owncloud Multiple cross-site scripting (XSS) vulnerabilities in js/viewer.js in ownCloud before 4.5.12 and 5.x before 5.0.7 allow remote attackers to inject arbitrary web script or HTML via vectors related to… CWE-79
Cross-site Scripting
CVE-2013-2150 2024-11-21 10:51 2014-03-15 Show GitHub Exploit DB Packet Storm
291726 - owncloud owncloud Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 4.0.16 and 5.x before 5.0.7 allow remote authenticated users to inject arbitrary web script or HTML via vectors related to share… CWE-79
Cross-site Scripting
CVE-2013-2149 2024-11-21 10:51 2014-03-15 Show GitHub Exploit DB Packet Storm
291727 - owncloud owncloud Incomplete blacklist vulnerability in ownCloud before 5.0.6 allows remote authenticated users to execute arbitrary PHP code by uploading a crafted file, then accessing it via a direct request to the … NVD-CWE-Other
CVE-2013-2089 2024-11-21 10:51 2014-03-15 Show GitHub Exploit DB Packet Storm
291728 - owncloud owncloud The configuration loader in ownCloud 5.0.x before 5.0.6 allows remote attackers to obtain CSRF tokens and other sensitive information by reading an unspecified JavaScript file. CWE-200
Information Exposure
CVE-2013-2086 2024-11-21 10:51 2014-03-15 Show GitHub Exploit DB Packet Storm
291729 - owncloud owncloud Directory traversal vulnerability in apps/files_trashbin/index.php in ownCloud Server before 5.0.6 allows remote authenticated users to access arbitrary files via a .. (dot dot) in the dir parameter. CWE-22
Path Traversal
CVE-2013-2085 2024-11-21 10:51 2014-03-15 Show GitHub Exploit DB Packet Storm
291730 - brother mfc-9970cdw_firmware
mfc-9970cdw
Multiple cross-site scripting (XSS) vulnerabilities in the Brother MFC-9970CDW printer with firmware G (1.03) allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to… CWE-79
Cross-site Scripting
CVE-2013-2507 2024-11-21 10:51 2014-03-14 Show GitHub Exploit DB Packet Storm