Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 24, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
209381 3.5 注意 Moodle - Moodle の survey モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2015-5336 2016-03-3 15:48 2015-11-16 Show GitHub Exploit DB Packet Storm
209382 4.3 警告 Moodle - Moodle の admin/registration/register.php におけるクロスサイトリクエストフォージェリの脆弱性 CWE-200
CWE-352
CVE-2015-5335 2016-03-3 15:48 2015-11-16 Show GitHub Exploit DB Packet Storm
209383 7.1 危険 Moodle - Moodle の Atto におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2015-5332 2016-03-3 15:48 2015-11-16 Show GitHub Exploit DB Packet Storm
209384 4 警告 Moodle - Moodle におけるアクセス制限を回避される脆弱性 CWE-Other
その他
CVE-2015-5331 2016-03-3 15:48 2015-11-16 Show GitHub Exploit DB Packet Storm
209385 4 警告 Moodle - Moodle の Forum モジュールにおける任意のグループに投稿される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2015-5272 2016-03-3 15:48 2015-09-21 Show GitHub Exploit DB Packet Storm
209386 4.9 警告 Moodle - Moodle の enrol/meta/locallib.php の enrol_meta_sync 関数における管理者権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2015-5266 2016-03-3 15:46 2015-09-21 Show GitHub Exploit DB Packet Storm
209387 4.3 警告 IBM - IBM Business Process Manager の Process Portal におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2015-8524 2016-03-3 14:05 2015-12-8 Show GitHub Exploit DB Packet Storm
209388 5 警告 IBM - IBM WebSphere Commerce Enterprise のアップデートインストーラにおける重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2015-7444 2016-03-3 14:05 2015-09-29 Show GitHub Exploit DB Packet Storm
209389 5 警告 QNAP Systems - QNAP Signage Station における認証を回避される脆弱性 CWE-Other
その他
CVE-2015-6036 2016-03-3 12:21 2016-02-25 Show GitHub Exploit DB Packet Storm
209390 4.3 警告 Huawei - Huawei Agile Controller-Campus のソフトウェアの不特定のポータル認証ページにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-2214 2016-03-3 11:35 2016-02-3 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 24, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
298621 - ubuntu metal_as_a_service Cross-site scripting (XSS) vulnerability in the API in Ubuntu Metal as a Service (MaaS) 1.2 and 1.4 allows remote attackers to inject arbitrary web script or HTML via the op parameter to nodes/. CWE-79
Cross-site Scripting
CVE-2013-1070 2024-11-21 10:48 2014-02-18 Show GitHub Exploit DB Packet Storm
298622 - ubuntu metal_as_a_service Ubuntu Metal as a Service (MaaS) 1.2 and 1.4 uses world-readable permissions for txlongpoll.yaml, which allows local users to obtain RabbitMQ authentication credentials by reading the file. CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-1069 2024-11-21 10:48 2014-02-18 Show GitHub Exploit DB Packet Storm
298623 - novell identity_manager_roles_based_provisioning_module Cross-site scripting (XSS) vulnerability in the Roles Based Provisioning Module 4.0.2 before Field Patch D for Novell Identity Manager (aka IDM) allows remote attackers to inject arbitrary web script… CWE-79
Cross-site Scripting
CVE-2013-1096 2024-11-21 10:48 2013-12-28 Show GitHub Exploit DB Packet Storm
298624 - ffmpeg ffmpeg The add_doubles_metadata function in libavcodec/tiff.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via a negative or zero count value in a TIFF image, which triggers an… CWE-189
Numeric Errors
CVE-2013-0859 2024-11-21 10:48 2013-12-8 Show GitHub Exploit DB Packet Storm
298625 - debian
ffmpeg
debian_linux
ffmpeg
The atrac3_decode_init function in libavcodec/atrac3.c in FFmpeg before 1.0.4 allows remote attackers to have an unspecified impact via ATRAC3 data with the joint stereo coding mode set and fewer tha… NVD-CWE-noinfo
CVE-2013-0858 2024-11-21 10:48 2013-12-8 Show GitHub Exploit DB Packet Storm
298626 - ffmpeg ffmpeg The decode_frame_ilbm function in libavcodec/iff.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via a crafted height value in IFF PBM/ILBM bitmap data. CWE-20
 Improper Input Validation 
CVE-2013-0857 2024-11-21 10:48 2013-12-8 Show GitHub Exploit DB Packet Storm
298627 - ffmpeg ffmpeg The lpc_prediction function in libavcodec/alac.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted Apple Lossless Audio Codec (ALAC) data, related to a large nb_s… CWE-20
 Improper Input Validation 
CVE-2013-0856 2024-11-21 10:48 2013-12-8 Show GitHub Exploit DB Packet Storm
298628 - ffmpeg ffmpeg Integer overflow in the alac_decode_close function in libavcodec/alac.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via a large number of samples per frame in Apple Los… CWE-189
Numeric Errors
CVE-2013-0855 2024-11-21 10:48 2013-12-8 Show GitHub Exploit DB Packet Storm
298629 - ffmpeg ffmpeg The mjpeg_decode_scan_progressive_ac function in libavcodec/mjpegdec.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted MJPEG data. CWE-20
 Improper Input Validation 
CVE-2013-0854 2024-11-21 10:48 2013-12-8 Show GitHub Exploit DB Packet Storm
298630 - ffmpeg ffmpeg The wavpack_decode_frame function in libavcodec/wavpack.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted WavPack data, which triggers an out-of-bounds array ac… CWE-189
Numeric Errors
CVE-2013-0853 2024-11-21 10:48 2013-12-8 Show GitHub Exploit DB Packet Storm