Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 30, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
203641 7.5 重要
Local
シトリックス・システムズ
Xen プロジェクト
- Xen の pygrub ブートローダエミュレータにおけるホスト上の任意のファイルを読まれる脆弱性 CWE-20
不適切な入力確認
CVE-2016-9380 2017-02-6 15:48 2016-11-22 Show GitHub Exploit DB Packet Storm
203642 7.9 重要
Local
シトリックス・システムズ
Xen プロジェクト
- Xen の pygrub ブートローダエミュレータにおけるホスト上の任意のファイルを読まれる脆弱性 CWE-20
不適切な入力確認
CVE-2016-9379 2017-02-6 15:48 2016-11-22 Show GitHub Exploit DB Packet Storm
203643 9.8 緊急
Network
OpenSLP - OpenSLP の common/slp_compare.c の SLPFoldWhiteSpace 関数におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2016-7567 2017-02-6 15:48 2016-09-27 Show GitHub Exploit DB Packet Storm
203644 5.5 警告
Local
libdwarf project - libdwarf の dwarf_loc.c の _dwarf_read_loc_section 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-125
境界外読み取り
CVE-2016-7410 2017-02-6 15:48 2016-09-13 Show GitHub Exploit DB Packet Storm
203645 9.8 緊急
Network
MetalGenix - GeniXCMS の inc/lib/Options.class.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2017-5575 2017-02-6 13:48 2017-01-23 Show GitHub Exploit DB Packet Storm
203646 9.8 緊急
Network
MetalGenix - GeniXCMS の register.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2017-5574 2017-02-6 13:48 2017-01-23 Show GitHub Exploit DB Packet Storm
203647 8.8 重要
Network
eClinicalWorks - eClinicalWorks Patient Portal の messageJson.jsp におけるブラインド SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2017-5570 2017-02-6 13:48 2017-01-23 Show GitHub Exploit DB Packet Storm
203648 9.8 緊急
Network
eClinicalWorks - eClinicalWorks Patient Portal の template.jsp におけるブラインド SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2017-5569 2017-02-6 13:48 2017-01-23 Show GitHub Exploit DB Packet Storm
203649 8.8 重要
Network
LibTIFF - LibTIFF の tif_lzw.c におけるヒープベースのバッファオーバーリードの脆弱性 CWE-119
バッファエラー
CVE-2017-5563 2017-02-6 13:48 2017-01-18 Show GitHub Exploit DB Packet Storm
203650 8.1 重要
Network
Foxit Software Inc - Windows 上で稼動する Foxit Reader および PhantomPDF の ConvertToPDF プラグインにおけるサービス運用妨害 (DoS) の脆弱性 CWE-125
境界外読み取り
CVE-2017-5556 2017-02-6 13:48 2017-01-10 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 30, 2026, 4:22 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
292611 - haxx
apple
curl
libcurl
mac_os_x
cURL and libcurl before 7.38.0 allow remote attackers to bypass the Same Origin Policy and set cookies for arbitrary sites by setting a cookie for a top-level domain. CWE-310
Cryptographic Issues
CVE-2014-3620 2024-11-21 11:08 2014-11-19 Show GitHub Exploit DB Packet Storm
292612 - haxx
apple
curl
libcurl
mac_os_x
cURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie domain names, which allows remote attackers to set cookies for or send arbitrary cookies to certain sites, as demonstrat… CWE-310
Cryptographic Issues
CVE-2014-3613 2024-11-21 11:08 2014-11-19 Show GitHub Exploit DB Packet Storm
292613 - apache qpid XML external entity (XXE) vulnerability in the XML Exchange module in Apache Qpid 0.30 allows remote attackers to cause outgoing HTTP connections via a crafted message. CWE-19
 Data Processing Errors
CVE-2014-3629 2024-11-21 11:08 2014-11-18 Show GitHub Exploit DB Packet Storm
292614 - mumble mumble The client in Mumble 1.2.x before 1.2.6 allows remote attackers to force the loading of an external file and cause a denial of service (hang and resource consumption) via a crafted string that is tre… CWE-19
 Data Processing Errors
CVE-2014-3756 2024-11-21 11:08 2014-11-16 Show GitHub Exploit DB Packet Storm
292615 - mumble mumble The QSvg module in Qt, as used in the Mumble client 1.2.x before 1.2.6, allows remote attackers to cause a denial of service (hang and resource consumption) via a local file reference in an (1) image… CWE-399
 Resource Management Errors
CVE-2014-3755 2024-11-21 11:08 2014-11-16 Show GitHub Exploit DB Packet Storm
292616 - apache cordova Apache Cordova Android before 3.5.1 allows remote attackers to open and send data to arbitrary applications via a URL with a crafted URI scheme for an Android intent. CWE-200
Information Exposure
CVE-2014-3502 2024-11-21 11:08 2014-11-16 Show GitHub Exploit DB Packet Storm
292617 - apache cordova Apache Cordova Android before 3.5.1 allows remote attackers to bypass the HTTP whitelist and connect to arbitrary servers by using JavaScript to open WebSocket connections through WebView. CWE-254
 7PK - Security Features
CVE-2014-3501 2024-11-21 11:08 2014-11-16 Show GitHub Exploit DB Packet Storm
292618 - apache cordova Apache Cordova Android before 3.5.1 allows remote attackers to change the start page via a crafted intent URL. CWE-17
Code
CVE-2014-3500 2024-11-21 11:08 2014-11-16 Show GitHub Exploit DB Packet Storm
292619 - canonical
apple
opensuse
oracle
debian
haxx
ubuntu_linux
mac_os_x
opensuse
hyperion
debian_linux
libcurl
The curl_easy_duphandle function in libcurl 7.17.1 through 7.38.0, when running with the CURLOPT_COPYPOSTFIELDS option, does not properly copy HTTP POST data for an easy handle, which triggers an out… CWE-200
Information Exposure
CVE-2014-3707 2024-11-21 11:08 2014-11-16 Show GitHub Exploit DB Packet Storm
292620 - qemu
debian
canonical
qemu
debian_linux
ubuntu_linux
The vmware-vga driver (hw/display/vmware_vga.c) in QEMU allows local guest users to write to qemu memory locations and gain privileges via unspecified parameters related to rectangle handling. CWE-269
 Improper Privilege Management
CVE-2014-3689 2024-11-21 11:08 2014-11-15 Show GitHub Exploit DB Packet Storm