Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 8, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
203591 9.8 緊急
Network
マイクロソフト
アドビシステムズ
Google
- Adobe Flash Player における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2016-4274 2016-09-16 16:16 2016-09-13 Show GitHub Exploit DB Packet Storm
203592 9.8 緊急
Network
マイクロソフト
アドビシステムズ
Google
- Adobe Flash Player における任意のコードを実行される脆弱性 CWE-Other
その他
CVE-2016-4272 2016-09-16 16:16 2016-09-13 Show GitHub Exploit DB Packet Storm
203593 7.5 重要
Network
マイクロソフト
アドビシステムズ
Google
- Adobe Flash Player におけるアクセス制限を回避される脆弱性 CWE-200
情報漏えい
CVE-2016-4271 2016-09-16 16:16 2016-09-13 Show GitHub Exploit DB Packet Storm
203594 6.5 警告
Network
マイクロソフト - Microsoft Edge および複数の Microsoft Windows 製品の PDF ライブラリにおける重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2016-3374 2016-09-16 15:40 2016-09-13 Show GitHub Exploit DB Packet Storm
203595 6.5 警告
Network
マイクロソフト - Microsoft Edge および複数の Microsoft Windows 製品の PDF ライブラリにおける重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2016-3370 2016-09-16 15:40 2016-09-13 Show GitHub Exploit DB Packet Storm
203596 5.5 警告
Local
マイクロソフト - 複数の Microsoft Windows 製品の Kernel API における重要なアカウント情報を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-3373 2016-09-16 15:22 2016-09-13 Show GitHub Exploit DB Packet Storm
203597 6.6 警告
Local
マイクロソフト - Microsoft Windows Vista および Windows Server 2008 の Kernel API におけるプロセスを偽装される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-3372 2016-09-16 15:22 2016-09-13 Show GitHub Exploit DB Packet Storm
203598 5.5 警告
Local
マイクロソフト - 複数の Microsoft Windows 製品の Kernel API における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2016-3371 2016-09-16 15:22 2016-09-13 Show GitHub Exploit DB Packet Storm
203599 7.8 重要
Local
マイクロソフト - 複数の Microsoft Windows 製品のカーネルにおけるセッションをハイジャックされる脆弱性 CWE-Other
その他
CVE-2016-3306 2016-09-16 15:22 2016-09-13 Show GitHub Exploit DB Packet Storm
203600 7.8 重要
Local
マイクロソフト - 複数の Microsoft Windows 製品のカーネルにおけるセッションをハイジャックされる脆弱性 CWE-Other
その他
CVE-2016-3305 2016-09-16 15:22 2016-09-13 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 8, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
291731 - pivotal_software
vmware
spring_framework The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolution, which allows remote attackers to read arbitra… CWE-352
CWE-611
 Origin Validation Error
XXE
CVE-2013-6429 2024-11-21 10:59 2014-01-27 Show GitHub Exploit DB Packet Storm
291732 - apple
canonical
cups
ubuntu_linux
lppasswd in CUPS before 1.7.1, when running with setuid privileges, allows local users to read portions of arbitrary files via a modified HOME environment variable and a symlink attack involving .cup… CWE-59
Link Following
CVE-2013-6891 2024-11-21 10:59 2014-01-26 Show GitHub Exploit DB Packet Storm
291733 - yahoo toolbar Cross-site scripting (XSS) vulnerability in clickstream.js in Y! Toolbar plugin for FireFox 3.1.0.20130813024103 for Mac, and 2.5.9.2013418100420 for Windows, allows remote attackers to inject arbitr… CWE-79
Cross-site Scripting
CVE-2013-6853 2024-11-21 10:59 2014-01-26 Show GitHub Exploit DB Packet Storm
291734 - redhat libvirt Multiple race conditions in the (1) virDomainBlockStats, (2) virDomainGetBlockInf, (3) qemuDomainBlockJobImpl, and (4) virDomainGetBlockIoTune functions in libvirt before 1.2.1 do not properly verify… CWE-362
Race Condition
CVE-2013-6458 2024-11-21 10:59 2014-01-25 Show GitHub Exploit DB Packet Storm
291735 - redhat libvirt The libxlDomainGetNumaParameters function in the libxl driver (libxl/libxl_driver.c) in libvirt before 1.2.1 does not properly initialize the nodemap, which allows local users to cause a denial of se… CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-6457 2024-11-21 10:59 2014-01-25 Show GitHub Exploit DB Packet Storm
291736 - redhat enterprise_virtualization_manager The remote-viewer in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.3, when using a native SPICE client invocation method, initially makes insecure connections to the SPICE server, which… CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-6434 2024-11-21 10:59 2014-01-25 Show GitHub Exploit DB Packet Storm
291737 - live555
videolan
streaming_media
vlc_media_player
The parseRTSPRequestString function in Live Networks Live555 Streaming Media 2013.11.26, as used in VideoLAN VLC Media Player, allows remote attackers to cause a denial of service (crash) and possibl… CWE-189
Numeric Errors
CVE-2013-6934 2024-11-21 10:59 2014-01-24 Show GitHub Exploit DB Packet Storm
291738 - live555 streaming_media The parseRTSPRequestString function in Live Networks Live555 Streaming Media 2011.08.13 through 2013.11.25, as used in VideoLAN VLC Media Player, allows remote attackers to cause a denial of service … CWE-119
CWE-189
Incorrect Access of Indexable Resource ('Range Error') 
Numeric Errors
CVE-2013-6933 2024-11-21 10:59 2014-01-24 Show GitHub Exploit DB Packet Storm
291739 - redhat cloudforms
cloudforms_3.0_management_engine
CloudForms 3.0 Management Engine before 5.2.1.6 allows remote attackers to bypass the Ruby on Rails protect_from_forgery mechanism and conduct cross-site request forgery (CSRF) attacks via a destruct… CWE-352
 Origin Validation Error
CVE-2013-6443 2024-11-21 10:59 2014-01-23 Show GitHub Exploit DB Packet Storm
291740 - redhat jboss_seam_2_framework The InterfaceGenerator handler in JBoss Seam Remoting in JBoss Seam 2 framework 2.3.1 and earlier, as used in JBoss Web Framework Kit, allows remote attackers to bypass the WebRemote annotation restr… CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-6448 2024-11-21 10:59 2014-01-23 Show GitHub Exploit DB Packet Storm