Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
209161 4.3 警告 IBM - 複数の IBM 製品におけるセッションをハイジャックされる脆弱性 CWE-310
暗号の問題
CVE-2014-6176 2014-12-19 14:26 2014-12-12 Show GitHub Exploit DB Packet Storm
209162 3.5 注意 MIT Kerberos - MIT Kerberos 5 の plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2014-5354 2014-12-19 14:12 2014-11-19 Show GitHub Exploit DB Packet Storm
209163 10 危険 Zoho Corporation - ZOHO ManageEngine NetFlow Analyzer の CollectorConfInfoServlet サーブレットにおけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2014-9373 2014-12-19 13:51 2014-08-18 Show GitHub Exploit DB Packet Storm
209164 6.4 警告 Zoho Corporation - ZOHO ManageEngine Password Manager Pro の UploadAccountActivities サーブレットにおけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2014-9372 2014-12-19 13:50 2014-08-18 Show GitHub Exploit DB Packet Storm
209165 10 危険 Zoho Corporation - ZOHO ManageEngine Desktop Central MSP の NativeAppServlet における任意のコードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2014-9371 2014-12-19 13:50 2014-08-18 Show GitHub Exploit DB Packet Storm
209166 6.4 警告 Docker - Docker におけるパストラバーサル攻撃を実行される脆弱性 CWE-20
不適切な入力確認
CVE-2014-9358 2014-12-19 13:31 2014-12-11 Show GitHub Exploit DB Packet Storm
209167 10 危険 Docker - Docker におけるルート権限で任意のコードを実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-9357 2014-12-19 13:31 2014-12-11 Show GitHub Exploit DB Packet Storm
209168 4.3 警告 Splunk - Splunk Enterprise の Splunk Web の Dashboard におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-5466 2014-12-19 12:08 2014-11-19 Show GitHub Exploit DB Packet Storm
209169 4 警告 IBM - IBM Business Process Manager の Process Center の エクスポート機能におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2014-6182 2014-12-19 11:49 2014-12-12 Show GitHub Exploit DB Packet Storm
209170 6.5 警告 IBM - IBM Business Process Manager のインポート/エクスポート機能におけるアクセス制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-4844 2014-12-19 11:49 2014-12-12 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 26, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
251321 - - - The stripImages and stripIframes methods didn't properly process inputs, leading to XSS vectors. - CVE-2024-40743 2024-10-31 00:35 2024-08-21 Show GitHub Exploit DB Packet Storm
251322 - - - A stored cross-site scripting (XSS) vulnerability in October CMS Bloghub Plugin v1.3.8 and lower allows attackers to execute arbitrary web scripts or HTML via a crafted payload into the Comments sect… - CVE-2024-25837 2024-10-31 00:35 2024-08-17 Show GitHub Exploit DB Packet Storm
251323 8.8 HIGH
Network
hitachienergy microscada_x_sys600
microscada_pro_sys600
The MicroSCADA Pro/X SYS600 product allows an authenticated user input to control or influence paths or file names that are used in filesystem operations. If exploited the vulnerability allows the at… CWE-22
Path Traversal
CVE-2024-3980 2024-10-31 00:33 2024-08-27 Show GitHub Exploit DB Packet Storm
251324 8.2 HIGH
Local
hitachienergy microscada_x_sys600 An attacker with local access to machine where MicroSCADA X SYS600 is installed, could enable the session logging supporting the product and try to exploit a session hijacking of an already establish… CWE-294
Authentication Bypass by Capture-replay 
CVE-2024-3982 2024-10-31 00:32 2024-08-27 Show GitHub Exploit DB Packet Storm
251325 8.8 HIGH
Network
hitachienergy microscada_x_sys600
microscada_pro_sys600
A vulnerability exists in the query validation of the MicroSCADA Pro/X SYS600 product. If exploited this could allow an authenticated attacker to inject code towards persistent data. Note that to suc… NVD-CWE-Other
CVE-2024-4872 2024-10-31 00:31 2024-08-27 Show GitHub Exploit DB Packet Storm
251326 4.3 MEDIUM
Network
hitachienergy microscada_x_sys600 An HTTP parameter may contain a URL value and could cause the web application to redirect the request to the specified URL. By modifying the URL value to a malicious site, an attacker may successfull… CWE-601
Open Redirect
CVE-2024-7941 2024-10-31 00:29 2024-08-27 Show GitHub Exploit DB Packet Storm
251327 7.2 HIGH
Network
anujkumar medical_card_generation_system A vulnerability was found in PHPGurukul Medical Card Generation System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/card-bwdate… CWE-89
SQL Injection
CVE-2024-10296 2024-10-31 00:13 2024-10-24 Show GitHub Exploit DB Packet Storm
251328 7.5 HIGH
Network
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tcp: fix mptcp DSS corruption due to large pmtu xmit Syzkaller was able to trigger a DSS corruption: TCP: request_sock_subflow… NVD-CWE-noinfo
CVE-2024-50083 2024-10-31 00:07 2024-10-29 Show GitHub Exploit DB Packet Storm
251329 7.5 HIGH
Network
zzcms zzcms A vulnerability, which was classified as problematic, was found in ZZCMS 2023. This affects an unknown part of the file 3/qq-connect2.0/API/com/inc.php. The manipulation leads to information disclosu… NVD-CWE-noinfo
CVE-2024-10290 2024-10-31 00:06 2024-10-24 Show GitHub Exploit DB Packet Storm
251330 8.8 HIGH
Network
liferay digital_experience_platform
liferay_portal
Cross-site request forgery (CSRF) vulnerability in the My Account widget in Liferay Portal 7.4.3.75 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 up… CWE-352
 Origin Validation Error
CVE-2024-26271 2024-10-31 00:04 2024-10-23 Show GitHub Exploit DB Packet Storm