Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 17, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
202691 7.5 重要
Network
シスコシステムズ - 複数の Cisco Integrated Services Router デバイス上で稼動する Cisco IOS におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2015-6289 2016-06-24 14:57 2015-08-17 Show GitHub Exploit DB Packet Storm
202692 6.3 警告
Network
DELL EMC (旧 EMC Corporation) - 複数の EMC Documentum 製品におけるアクセス制限を回避される脆弱性 CWE-Other
その他
CVE-2016-0914 2016-06-24 14:54 2016-06-22 Show GitHub Exploit DB Packet Storm
202693 6.5 警告
Network
OSIsoft - OSIsoft PI SQL Data Access Server におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2016-4530 2016-06-24 14:14 2016-05-10 Show GitHub Exploit DB Packet Storm
202694 4.3 警告
Network
サイボウズ - サイボウズ ガルーンのログ出力機能におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2016-1192 2016-06-23 17:49 2016-05-30 Show GitHub Exploit DB Packet Storm
202695 4.3 警告
Network
サイボウズ - サイボウズ ガルーンにおけるアクセス制限不備の脆弱性 CWE-Other
その他
CVE-2015-7776 2016-06-23 17:42 2016-05-30 Show GitHub Exploit DB Packet Storm
202696 5.3 警告
Network
サイボウズ - サイボウズ ガルーンのファイル管理機能におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2016-1191 2016-06-23 17:39 2016-05-30 Show GitHub Exploit DB Packet Storm
202697 5.6 警告
Network
エヌ・ティ・ティ・ブロードバンドプラットフォーム株式会社 - Japan Connected-free Wi-Fi における任意の API が実行可能な脆弱性 CWE-Other
その他
CVE-2016-4811 2016-06-23 17:37 2016-05-27 Show GitHub Exploit DB Packet Storm
202698 4.3 警告
Network
サイボウズ - サイボウズ ガルーンにおけるアクセス制限不備の脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-1196 2016-06-23 17:32 2016-05-30 Show GitHub Exploit DB Packet Storm
202699 5.3 警告
Network
奥 一穂 - H2O における解放済みメモリ使用 (use-after-free) の脆弱性 CWE-399
リソース管理の問題
CVE-2016-4817 2016-06-23 17:22 2016-05-27 Show GitHub Exploit DB Packet Storm
202700 4.3 警告
Network
株式会社アイ・オー・データ機器 - ETX-R におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2016-4820 2016-06-23 17:11 2016-06-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 17, 2026, 4:15 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
291141 6.1 MEDIUM
Network
mahara mahara Cross-site Scripting (XSS) in Mahara before 1.5.9 and 1.6.x before 1.6.4 allows remote attackers to inject arbitrary web script or HTML via the TinyMCE editor. CWE-79
Cross-site Scripting
CVE-2013-1426 2024-11-21 10:49 2019-11-8 Show GitHub Exploit DB Packet Storm
291142 5.5 MEDIUM
Local
ldap_git_backup_project
debian
ldap_git_backup
debian_linux
ldap-git-backup before 1.0.4 exposes password hashes due to incorrect directory permissions. CWE-276
Incorrect Default Permissions 
CVE-2013-1425 2024-11-21 10:49 2019-11-8 Show GitHub Exploit DB Packet Storm
291143 7.5 HIGH
Network
huntcctv
capturecctv
hachi
novuscctv
vsp
dvr-04ch_firmware
dvr-04nc_firmware
dvr-08ch_firmware
dvr-08nc_firmware
dvr-16ch_firmware
dr6-704a4h_firmware
dr6-708a4h_firmware
dr6-7316a4h_firmware
dr6-7316a4hl_firmware
Authentication bypass vulnerability in the the web interface in Hunt CCTV, Capture CCTV, Hachi CCTV, NoVus CCTV, and Well-Vision Inc DVR systems allows a remote attacker to retrieve the device config… CWE-287
Improper Authentication
CVE-2013-1391 2024-11-21 10:49 2019-10-31 Show GitHub Exploit DB Packet Storm
291144 9.8 CRITICAL
Network
neutrinolabs
debian
xrdp
debian_linux
An issue was discovered in xrdp before 0.9.1. When successfully logging in using RDP into an xrdp session, the file ~/.vnc/sesman_${username}_passwd is created. Its content is the equivalent of the u… CWE-255
Credentials Management
CVE-2013-1430 2024-11-21 10:49 2016-12-16 Show GitHub Exploit DB Packet Storm
291145 - xmonad xmonad-contrab The XMonad.Hooks.DynamicLog module in xmonad-contrib before 0.11.2 allows remote attackers to execute arbitrary commands via a web page title, which activates the commands when the user clicks on the… CWE-94
Code Injection
CVE-2013-1436 2024-11-21 10:49 2014-10-7 Show GitHub Exploit DB Packet Storm
291146 - dleviet datalife_engine DataLife Engine (DLE) 9.7 allows remote attackers to execute arbitrary PHP code via the catlist[] parameter to engine/preview.php, which is used in a preg_replace function call with an e modifier. CWE-94
Code Injection
CVE-2013-1412 2024-11-21 10:49 2014-06-3 Show GitHub Exploit DB Packet Storm
291147 - sensiolabs symfony Symfony 2.0.x before 2.0.22, 2.1.x before 2.1.7, and 2.2.x remote attackers to execute arbitrary PHP code via a serialized PHP object to the (1) Yaml::parse or (2) Yaml\Parser::parse function, a diff… CWE-94
Code Injection
CVE-2013-1397 2024-11-21 10:49 2014-06-3 Show GitHub Exploit DB Packet Storm
291148 - sensiolabs symfony The Yaml::parse function in Symfony 2.0.x before 2.0.22 remote attackers to execute arbitrary PHP code via a PHP file, a different vulnerability than CVE-2013-1397. CWE-94
Code Injection
CVE-2013-1348 2024-11-21 10:49 2014-06-3 Show GitHub Exploit DB Packet Storm
291149 - cisco nx-os
nexus_7000
nexus_7000_10-slot
nexus_7000_18-slot
nexus_7000_9-slot
Cisco NX-OS 6.1 before 6.1(5) on Nexus 7000 devices, when local authentication and multiple VDCs are enabled, allows remote authenticated users to gain privileges within an unintended VDC via crafted… CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-1191 2024-11-21 10:49 2014-05-26 Show GitHub Exploit DB Packet Storm
291150 - netweblogic events_manager
events_manager_pro
Multiple cross-site scripting (XSS) vulnerabilities in the Events Manager plugin before 5.3.5 and Events Manager Pro plugin before 2.2.9 for WordPress allow remote attackers to inject arbitrary web s… CWE-79
Cross-site Scripting
CVE-2013-1407 2024-11-21 10:49 2014-05-13 Show GitHub Exploit DB Packet Storm