Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
214841 2.1 注意 ヒューレット・パッカード - 複数の HP 製品における権限を取得される脆弱性 CWE-noinfo
情報不足
CVE-2013-6216 2014-04-15 14:04 2013-10-21 Show GitHub Exploit DB Packet Storm
214842 9.3 危険 BlackBerry - Blackberry Z10 デバイスのソフトウェアの qconnDoor におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2014-2389 2014-04-15 13:46 2014-04-8 Show GitHub Exploit DB Packet Storm
214843 5 警告 シスコシステムズ - Cisco ONS 15454 コントローラカードのソフトウェアにおけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2014-2142 2014-04-15 12:26 2014-04-7 Show GitHub Exploit DB Packet Storm
214844 5 警告 シスコシステムズ - Cisco ONS 15454 コントローラカードのソフトウェアにおけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2014-2140 2014-04-15 12:26 2014-04-8 Show GitHub Exploit DB Packet Storm
214845 5 警告 シスコシステムズ - Cisco ONS 15454 コントローラカードのソフトウェアにおけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2014-2139 2014-04-15 12:25 2014-04-8 Show GitHub Exploit DB Packet Storm
214846 7.5 危険 SAP - SAP エンタープライズポータルにおける権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-7367 2014-04-15 12:21 2013-02-21 Show GitHub Exploit DB Packet Storm
214847 5 警告 SAP - SAP ソフトウェアデプロイメントマネージャにおけるサービス運用妨害 (DoS) の脆弱性 CWE-287
不適切な認証
CVE-2013-7366 2014-04-15 12:20 2013-02-21 Show GitHub Exploit DB Packet Storm
214848 4.3 警告 SAP - SAP エンタープライズポータルにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-7365 2014-04-15 12:20 2013-02-21 Show GitHub Exploit DB Packet Storm
214849 7.5 危険 SAP - SAP NetWeaver の J2EE エンジンの不特定の J2EE コアサービスにおける任意のファイルを読まれる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-7364 2014-04-15 12:19 2013-02-21 Show GitHub Exploit DB Packet Storm
214850 7.5 危険 SAP - SAP Solution Manager の Diagnostics エージェントにおける重要な情報を取得される脆弱性 CWE-noinfo
情報不足
CVE-2013-7363 2014-04-15 12:19 2013-02-21 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 25, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
298151 - celoxis celoxis Cross-site scripting (XSS) vulnerability in user.do in Celoxis Technologies Celoxis allows remote attackers to inject arbitrary web script or HTML via the ni.smessage parameter. CWE-79
Cross-site Scripting
CVE-2008-6094 2017-08-8 10:33 2009-02-10 Show GitHub Exploit DB Packet Storm
298152 - opennms opennms Cross-site scripting (XSS) vulnerability in surveillanceView.htm in OpenNMS 1.5.94 allows remote attackers to inject arbitrary web script or HTML via the viewName parameter. CWE-79
Cross-site Scripting
CVE-2008-6095 2017-08-8 10:33 2009-02-10 Show GitHub Exploit DB Packet Storm
298153 - wikyblog wikyblog Multiple cross-site scripting (XSS) vulnerabilities in WikyBlog before 1.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) key parameter to index.php/Special/Main/keywordS… CWE-79
Cross-site Scripting
CVE-2008-6097 2017-08-8 10:33 2009-02-10 Show GitHub Exploit DB Packet Storm
298154 - mozilla bugzilla Bugzilla 3.2 before 3.2 RC2, 3.0 before 3.0.6, 2.22 before 2.22.6, 2.20 before 2.20.7, and other versions after 2.17.4 allows remote authenticated users to bypass moderation to approve and disapprove… CWE-264
Permissions, Privileges, and Access Controls
CVE-2008-6098 2017-08-8 10:33 2009-02-10 Show GitHub Exploit DB Packet Storm
298155 - a4desk a4desk_flash_event_calendar PHP remote file inclusion vulnerability in index.php in A4Desk Event Calendar, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the v parameter. CWE-94
Code Injection
CVE-2008-6103 2017-08-8 10:33 2009-02-11 Show GitHub Exploit DB Packet Storm
298156 - linux linux_kernel The (1) sys32_mremap function in arch/sparc64/kernel/sys_sparc32.c, the (2) sparc_mmap_check function in arch/sparc/kernel/sys_sparc.c, and the (3) sparc64_mmap_check function in arch/sparc64/kernel/… CWE-399
 Resource Management Errors
CVE-2008-6107 2017-08-8 10:33 2009-02-11 Show GitHub Exploit DB Packet Storm
298157 - shelter_manager animal_shelter_manager Robin Rawson-Tetley Animal Shelter Manager (ASM) before 2.2.2 does not properly enforce the privileges of user accounts, which allows local users to bypass intended access restrictions by (1) opening… CWE-264
Permissions, Privileges, and Access Controls
CVE-2008-6109 2017-08-8 10:33 2009-02-11 Show GitHub Exploit DB Packet Storm
298158 - semanticscuttle semanticscuttle Cross-site scripting (XSS) vulnerability in SemanticScuttle before 0.90 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to the (1) username and (2) pro… CWE-79
Cross-site Scripting
CVE-2008-6113 2017-08-8 10:33 2009-02-12 Show GitHub Exploit DB Packet Storm
298159 - goople_cms goople_cms Static code injection vulnerability in gooplecms/admin/account/action/editpass.php in Goople CMS 1.7 allows remote attackers to inject arbitrary PHP code into admin/userandpass.php via the (1) userna… CWE-20
 Improper Input Validation 
CVE-2008-6119 2017-08-8 10:33 2009-02-12 Show GitHub Exploit DB Packet Storm
298160 - socialengine socialengine SQL injection vulnerability in profile_comments.php in SocialEngine (SE) 2.7 and earlier allows remote attackers to execute arbitrary SQL commands via the comment_secure parameter. CWE-89
SQL Injection
CVE-2008-6120 2017-08-8 10:33 2009-02-12 Show GitHub Exploit DB Packet Storm