Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 1, 2026, noon

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
214351 7.5 危険 OSClass - Osclass の oc-includes/osclass/controller/ajax.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2014-8084 2015-01-8 19:01 2014-10-9 Show GitHub Exploit DB Packet Storm
214352 5 警告 Tobias Oetiker - Zenoss で使用される Python 用 rrdtool モジュールにおけるフォーマットストリングの脆弱性 CWE-134
書式文字列の問題
CVE-2013-2131 2015-01-8 18:59 2013-06-5 Show GitHub Exploit DB Packet Storm
214353 7.5 危険 OSClass - Osclass の Search::setJsonAlert メソッドにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2014-8083 2015-01-8 18:58 2014-10-9 Show GitHub Exploit DB Packet Storm
214354 6.8 警告 Quick Page/Post Redirect project - WordPress 用 Quick Page/Post Redirect プラグインにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2014-2598 2015-01-8 18:51 2014-04-10 Show GitHub Exploit DB Packet Storm
214355 7.5 危険 CTS Projects & Software - CTS Projects & Software ClassAd の showads.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2014-9455 2015-01-8 18:51 2014-11-9 Show GitHub Exploit DB Packet Storm
214356 6.8 警告 Sandor Kovacs - WordPress 用 Simple Sticky Footer プラグインにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2014-9454 2015-01-8 18:41 2014-11-27 Show GitHub Exploit DB Packet Storm
214357 4.3 警告 Simple Visitor Stat project - WordPress 用 Simple Visitor Stat プラグインの simple-visitor-stat.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-9453 2015-01-8 18:40 2014-12-12 Show GitHub Exploit DB Packet Storm
214358 4.3 警告 Open-Xchange - Open-Xchange AppSuite におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-1679 2015-01-8 18:30 2014-01-29 Show GitHub Exploit DB Packet Storm
214359 7.5 危険 TYPO3 Association - TYPO3 のフロントエンドレンダリングコンポーネントにおける脆弱性 CWE-20
不適切な入力確認
CVE-2014-9509 2015-01-8 18:23 2014-12-9 Show GitHub Exploit DB Packet Storm
214360 4.3 警告 TYPO3 Association - TYPO3 の フロントエンドレンダリングコンポーネントにおける任意のドメインの URL に変更される脆弱性 CWE-59
リンク解釈の問題
CVE-2014-9508 2015-01-8 18:23 2014-12-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 1, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
355761 - freebsd freebsd The accept_filter mechanism in FreeBSD 4 through 4.5 does not properly remove entries from the incomplete listen queue when adding a syncache, which allows remote attackers to cause a denial of servi… NVD-CWE-Other
CVE-2002-0794 2008-09-6 05:28 2002-08-12 Show GitHub Exploit DB Packet Storm
355762 - freebsd freebsd The rc system startup script for FreeBSD 4 through 4.5 allows local users to delete arbitrary files via a symlink attack on X Windows lock files. NVD-CWE-Other
CVE-2002-0795 2008-09-6 05:28 2002-08-12 Show GitHub Exploit DB Packet Storm
355763 - youngzsoft cmailserver Buffer overflow in YoungZSoft CMailServer 3.30 allows remote attackers to execute arbitrary code via a long USER argument. NVD-CWE-Other
CVE-2002-0799 2008-09-6 05:28 2002-08-12 Show GitHub Exploit DB Packet Storm
355764 - working_resources_inc. badblue BadBlue 1.7.0 allows remote attackers to list the contents of directories via a URL with an encoded '%' character at the end. NVD-CWE-Other
CVE-2002-0800 2008-09-6 05:28 2002-08-12 Show GitHub Exploit DB Packet Storm
355765 - macromedia jrun Buffer overflow in the ISAPI DLL filter for Macromedia JRun 3.1 allows remote attackers to execute arbitrary code via a direct request to the filter with a long HTTP host header field in a URL for a … NVD-CWE-Other
CVE-2002-0801 2008-09-6 05:28 2002-08-12 Show GitHub Exploit DB Packet Storm
355766 - mozilla bugzilla Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, when configured to perform reverse DNS lookups, allows remote attackers to bypass IP restrictions by connecting from a system with a spoofed reve… NVD-CWE-Other
CVE-2002-0804 2008-09-6 05:28 2002-08-12 Show GitHub Exploit DB Packet Storm
355767 - mozilla bugzilla Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, (1) creates new directories with world-writable permissions, and (2) creates the params file with world-writable permissions, which allows local … NVD-CWE-Other
CVE-2002-0805 2008-09-6 05:28 2002-08-12 Show GitHub Exploit DB Packet Storm
355768 - yahoo messenger Yahoo! Messenger 5,0,0,1064 and earlier allows remote attackers to execute arbitrary script as other users via the addview parameter of a ymsgr URI. NVD-CWE-Other
CVE-2002-0032 2008-09-6 05:27 2002-07-26 Show GitHub Exploit DB Packet Storm
355769 - ibm lotus_domino_server Lotus Domino Servers 5.x, 4.6x, and 4.5x allows attackers to bypass the intended Reader and Author access list for a document's object via a Notes API call (NSFDbReadObject) that directly accesses th… NVD-CWE-Other
CVE-2002-0037 2008-09-6 05:27 2002-04-22 Show GitHub Exploit DB Packet Storm
355770 - sgi irix rpcbind in SGI IRIX 6.5 through 6.5.15f, and possibly earlier versions, allows remote attackers to cause a denial of service (crash) via malformed RPC packets with invalid lengths. NVD-CWE-Other
CVE-2002-0039 2008-09-6 05:27 2002-03-28 Show GitHub Exploit DB Packet Storm