|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":June 4, 2026, 4 p.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 203721 | 5.6 |
警告
Network |
Apache Software Foundation | - | Apache Struts において任意のコードを実行可能な脆弱性 |
CWE-20
不適切な入力確認 |
CVE-2016-4438 | 2016-08-3 16:11 | 2016-06-20 | Show | GitHub Exploit DB Packet Storm |
| 203722 | 7.1 |
重要
Network |
西日本電信電話株式会社 東日本電信電話株式会社 |
- | 複数のひかり電話ルータおよびひかり電話対応機器におけるクロスサイトリクエストフォージェリの脆弱性 |
CWE-352
同一生成元ポリシー違反 |
CVE-2016-1228 | 2016-08-3 16:02 | 2016-06-27 | Show | GitHub Exploit DB Packet Storm |
| 203723 | 6.8 |
警告
Adjacent |
西日本電信電話株式会社 東日本電信電話株式会社 |
- | 複数のひかり電話ルータおよびひかり電話対応機器における OS コマンドインジェクションの脆弱性 |
CWE-78
OSコマンド・インジェクション |
CVE-2016-1227 | 2016-08-3 16:02 | 2016-06-27 | Show | GitHub Exploit DB Packet Storm |
| 203724 | 4.7 |
警告
Network |
日立 | - | Hitachi Tuning Manager におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
- | 2016-08-3 15:25 | 2016-05-16 | Show | GitHub Exploit DB Packet Storm |
| 203725 | 3.1 |
低
Network |
日立 | - | Hitachi Command Suite 製品における情報漏えいに関する脆弱性 |
CWE-noinfo
情報不足 |
- | 2016-08-3 15:20 | 2016-05-16 | Show | GitHub Exploit DB Packet Storm |
| 203726 | 8.8 |
重要
Network |
libbpg | - | libbpg にメモリ境界外への書き込みを行う脆弱性 |
CWE-119 CWE-Other |
CVE-2016-5637 | 2016-08-3 15:06 | 2016-07-12 | Show | GitHub Exploit DB Packet Storm |
| 203727 | 6.1 |
警告
Network |
QNAP Systems | - | QNAP QTS におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2015-5664 | 2016-08-3 14:54 | 2016-06-27 | Show | GitHub Exploit DB Packet Storm |
| 203728 | 7.5 |
重要
Network |
フォーティネット Cavium |
- | Cavium Software Development Kit の RSA-CRT の実装における RSA 秘密鍵を取得される脆弱性 |
CWE-200
情報漏えい |
CVE-2015-5738 | 2016-08-3 14:39 | 2015-12-14 | Show | GitHub Exploit DB Packet Storm |
| 203729 | 9.8 |
緊急
Network |
- | 複数の OS 上で稼動する HPE Operations Manager の AdminUI における任意のコマンドを実行される脆弱性 |
CWE-Other
その他 |
CVE-2016-4373 | 2016-08-3 11:26 | 2016-07-25 | Show | GitHub Exploit DB Packet Storm | |
| 203730 | 5 | 警告 | ヒューレット・パッカード 日本電気 Apache Software Foundation |
- | Apache Tomcat の HTTP Digest Access Authentication 実装における完全性保護の要求を回避される脆弱性 |
CWE-264
認可・権限・アクセス制御 |
CVE-2011-5062 | 2016-08-2 17:34 | 2012-01-14 | Show | GitHub Exploit DB Packet Storm |
Update Date:June 5, 2026, 4:11 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 290091 | 5.9 |
MEDIUM
Network |
ovirt-engine-sdk-python_project | ovirt-engine-sdk-python | ovirt-engine-sdk-python before 3.4.0.7 and 3.5.0.4 does not verify that the hostname of the remote endpoint matches the Common Name (CN) or subjectAltName as specified by its x.509 certificate in a T… |
CWE-295
Improper Certificate Validation |
CVE-2014-0161 | 2024-11-21 11:01 | 2020-01-3 | Show | GitHub Exploit DB Packet Storm |
| 290092 | 5.9 |
MEDIUM
Network |
clusterlabs | fence-agents | In fence-agents before 4.0.17 does not verify remote SSL certificates in the fence_cisco_ucs.py script which can potentially allow for man-in-the-middle attackers to spoof SSL servers via arbitrary S… |
CWE-295
Improper Certificate Validation |
CVE-2014-0104 | 2024-11-21 11:01 | 2020-01-3 | Show | GitHub Exploit DB Packet Storm |
| 290093 | 9.8 |
CRITICAL
Network |
docker apache |
docker geode |
An issue was found in Docker before 1.6.0. Some programs and scripts in Docker are downloaded via HTTP and then executed or used in unsafe ways. |
CWE-20
Improper Input Validation |
CVE-2014-0048 | 2024-11-21 11:01 | 2020-01-3 | Show | GitHub Exploit DB Packet Storm |
| 290094 | 5.5 |
MEDIUM
Local |
theforeman redhat |
hammer_cli satellite |
rubygem-hammer_cli_foreman: File /etc/hammer/cli.modules.d/foreman.yml world readable |
CWE-522
Insufficiently Protected Credentials |
CVE-2014-0241 | 2024-11-21 11:01 | 2019-12-13 | Show | GitHub Exploit DB Packet Storm |
| 290095 | 7.5 |
HIGH
Network |
apache | qpid-cpp | qpid-cpp: ACL policies only loaded if the acl-file option specified enabling DoS by consuming all available file descriptors |
CWE-400
Uncontrolled Resource Consumption |
CVE-2014-0212 | 2024-11-21 11:01 | 2019-12-13 | Show | GitHub Exploit DB Packet Storm |
| 290096 | 8.8 |
HIGH
Network |
redhat |
cloudforms cloudforms_management_engine |
CFME: CSRF protection vulnerability via permissive check of the referrer header |
CWE-352
Origin Validation Error |
CVE-2014-0197 | 2024-11-21 11:01 | 2019-12-13 | Show | GitHub Exploit DB Packet Storm |
| 290097 | 9.8 |
CRITICAL
Network |
puppet redhat debian |
marionette_collective openshift debian_linux |
mcollective has a default password set at install |
CWE-798
Use of Hard-coded Credentials |
CVE-2014-0175 | 2024-11-21 11:01 | 2019-12-13 | Show | GitHub Exploit DB Packet Storm |
| 290098 | 8.8 |
HIGH
Network |
redhat | openshift | Openshift has shell command injection flaws due to unsanitized data being passed into shell commands. |
CWE-78
OS Command |
CVE-2014-0163 | 2024-11-21 11:01 | 2019-12-12 | Show | GitHub Exploit DB Packet Storm |
| 290099 | 5.3 |
MEDIUM
Network |
theforeman | foreman | Foreman has improper input validation which could lead to partial Denial of Service |
CWE-20
Improper Input Validation |
CVE-2014-0091 | 2024-11-21 11:01 | 2019-12-12 | Show | GitHub Exploit DB Packet Storm |
| 290100 | 6.5 |
MEDIUM
Network |
redhat | subscription_asset_manager | katello-headpin is vulnerable to CSRF in REST API |
CWE-352
Origin Validation Error |
CVE-2014-0026 | 2024-11-21 11:01 | 2019-12-12 | Show | GitHub Exploit DB Packet Storm |