Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 15, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
203101 7.5 重要
Network
openSUSE project
Fedora Project
The Go Project
- Go の crypto/dsa/dsa.go の Verify 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2016-3959 2016-05-27 15:54 2016-04-6 Show GitHub Exploit DB Packet Storm
203102 7.8 重要
Local
The Go Project - Windows 上で稼動する Go における権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-3958 2016-05-27 15:54 2016-04-2 Show GitHub Exploit DB Packet Storm
203103 7.4 重要
Network
トレンドマイクロ - Apple iOS 用 Trend Micro Mobile Security におけるモバイルアプリケーションのログインサーバになりすまされる脆弱性 CWE-200
情報漏えい
CVE-2016-3664 2016-05-27 15:03 2016-04-22 Show GitHub Exploit DB Packet Storm
203104 6.3 警告
Network
エヌ・ティ・ティ・ブロードバンドプラットフォーム株式会社 - Japan Connected-free Wi-Fi におけるアクセス制限不備の脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2015-5629 2016-05-27 12:12 2015-09-11 Show GitHub Exploit DB Packet Storm
203105 7.5 重要
Adjacent
Huawei - 複数の Huawei デバイス製品のソフトウェアの Smart DNS 機能におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2016-4577 2016-05-27 11:23 2016-05-11 Show GitHub Exploit DB Packet Storm
203106 9.8 緊急
Network
Huawei - 複数の Huawei デバイス製品のソフトウェアの Application Specific Packet Filtering 機能におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2016-4576 2016-05-27 11:23 2016-05-11 Show GitHub Exploit DB Packet Storm
203107 8.1 重要
Network
Huawei - Huawei S12700 および S5700 スイッチのソフトウェアにおけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2016-4087 2016-05-27 11:23 2016-04-27 Show GitHub Exploit DB Packet Storm
203108 7.8 重要
Local
Huawei - Huawei Mobile Broadband HL Service における SYSTEM 権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-2855 2016-05-27 11:23 2016-05-12 Show GitHub Exploit DB Packet Storm
203109 4.4 警告
Local
Fabrice Bellard
Fedora Project
- QEMU の hw/usb/hcd-ehci.c の ehci_advance_state 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2016-4037 2016-05-27 10:08 2016-04-19 Show GitHub Exploit DB Packet Storm
203110 6.5 警告
Local
Fabrice Bellard - QEMU の hw/i386/kvmvapic.c の patch_instruction 関数におけるホストスタックメモリから重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2016-4020 2016-05-27 10:08 2016-05-23 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 15, 2026, 4:28 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
290741 6.1 MEDIUM
Network
mahara mahara Cross-site Scripting (XSS) in Mahara before 1.5.9 and 1.6.x before 1.6.4 allows remote attackers to inject arbitrary web script or HTML via the TinyMCE editor. CWE-79
Cross-site Scripting
CVE-2013-1426 2024-11-21 10:49 2019-11-8 Show GitHub Exploit DB Packet Storm
290742 5.5 MEDIUM
Local
ldap_git_backup_project
debian
ldap_git_backup
debian_linux
ldap-git-backup before 1.0.4 exposes password hashes due to incorrect directory permissions. CWE-276
Incorrect Default Permissions 
CVE-2013-1425 2024-11-21 10:49 2019-11-8 Show GitHub Exploit DB Packet Storm
290743 7.5 HIGH
Network
huntcctv
capturecctv
hachi
novuscctv
vsp
dvr-04ch_firmware
dvr-04nc_firmware
dvr-08ch_firmware
dvr-08nc_firmware
dvr-16ch_firmware
dr6-704a4h_firmware
dr6-708a4h_firmware
dr6-7316a4h_firmware
dr6-7316a4hl_firmware
Authentication bypass vulnerability in the the web interface in Hunt CCTV, Capture CCTV, Hachi CCTV, NoVus CCTV, and Well-Vision Inc DVR systems allows a remote attacker to retrieve the device config… CWE-287
Improper Authentication
CVE-2013-1391 2024-11-21 10:49 2019-10-31 Show GitHub Exploit DB Packet Storm
290744 9.8 CRITICAL
Network
neutrinolabs
debian
xrdp
debian_linux
An issue was discovered in xrdp before 0.9.1. When successfully logging in using RDP into an xrdp session, the file ~/.vnc/sesman_${username}_passwd is created. Its content is the equivalent of the u… CWE-255
Credentials Management
CVE-2013-1430 2024-11-21 10:49 2016-12-16 Show GitHub Exploit DB Packet Storm
290745 - xmonad xmonad-contrab The XMonad.Hooks.DynamicLog module in xmonad-contrib before 0.11.2 allows remote attackers to execute arbitrary commands via a web page title, which activates the commands when the user clicks on the… CWE-94
Code Injection
CVE-2013-1436 2024-11-21 10:49 2014-10-7 Show GitHub Exploit DB Packet Storm
290746 - dleviet datalife_engine DataLife Engine (DLE) 9.7 allows remote attackers to execute arbitrary PHP code via the catlist[] parameter to engine/preview.php, which is used in a preg_replace function call with an e modifier. CWE-94
Code Injection
CVE-2013-1412 2024-11-21 10:49 2014-06-3 Show GitHub Exploit DB Packet Storm
290747 - sensiolabs symfony Symfony 2.0.x before 2.0.22, 2.1.x before 2.1.7, and 2.2.x remote attackers to execute arbitrary PHP code via a serialized PHP object to the (1) Yaml::parse or (2) Yaml\Parser::parse function, a diff… CWE-94
Code Injection
CVE-2013-1397 2024-11-21 10:49 2014-06-3 Show GitHub Exploit DB Packet Storm
290748 - sensiolabs symfony The Yaml::parse function in Symfony 2.0.x before 2.0.22 remote attackers to execute arbitrary PHP code via a PHP file, a different vulnerability than CVE-2013-1397. CWE-94
Code Injection
CVE-2013-1348 2024-11-21 10:49 2014-06-3 Show GitHub Exploit DB Packet Storm
290749 - cisco nx-os
nexus_7000
nexus_7000_10-slot
nexus_7000_18-slot
nexus_7000_9-slot
Cisco NX-OS 6.1 before 6.1(5) on Nexus 7000 devices, when local authentication and multiple VDCs are enabled, allows remote authenticated users to gain privileges within an unintended VDC via crafted… CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-1191 2024-11-21 10:49 2014-05-26 Show GitHub Exploit DB Packet Storm
290750 - netweblogic events_manager
events_manager_pro
Multiple cross-site scripting (XSS) vulnerabilities in the Events Manager plugin before 5.3.5 and Events Manager Pro plugin before 2.2.9 for WordPress allow remote attackers to inject arbitrary web s… CWE-79
Cross-site Scripting
CVE-2013-1407 2024-11-21 10:49 2014-05-13 Show GitHub Exploit DB Packet Storm