Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 23, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
215471 5.8 警告 Insite - Drupal 用 Node basket モジュールにおけるオープンリダイレクトの脆弱性 CWE-Other
その他
CVE-2015-3383 2015-04-24 16:55 2015-02-11 Show GitHub Exploit DB Packet Storm
215472 5.8 警告 Insite - Drupal 用 Node basket モジュールにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2015-3382 2015-04-24 16:55 2015-02-11 Show GitHub Exploit DB Packet Storm
215473 3.5 注意 Insite - Drupal 用 Node basket モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2015-3381 2015-04-24 16:55 2015-02-11 Show GitHub Exploit DB Packet Storm
215474 3.5 注意 Frederic Marand - Drupal 用 Taxonews モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2015-3369 2015-04-24 16:52 2015-01-18 Show GitHub Exploit DB Packet Storm
215475 3.5 注意 OSInet - Drupal 用 Classified Ads モジュールの管理ユーザインターフェースおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2015-3368 2015-04-24 16:52 2015-01-15 Show GitHub Exploit DB Packet Storm
215476 6.8 警告 Patterns project - Drupal 用 Patterns モジュールにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2015-3367 2015-04-24 16:52 2015-01-21 Show GitHub Exploit DB Packet Storm
215477 5.8 警告 Sergio Martin Morillas - Drupal 用 nodeauthor モジュールにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2015-3366 2015-04-24 16:52 2015-01-21 Show GitHub Exploit DB Packet Storm
215478 3.5 注意 nodeauthor project - Drupal 用 nodeauthor モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2015-3365 2015-04-24 16:52 2015-01-14 Show GitHub Exploit DB Packet Storm
215479 4.3 警告 LevelTen Interactive - Drupal 用 Content Analysis モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2015-3364 2015-04-24 16:52 2015-01-14 Show GitHub Exploit DB Packet Storm
215480 6.8 警告 Joshi Consultancy Services - Drupal 用 Contact Form Fields モジュールにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2015-3363 2015-04-24 16:52 2015-01-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 23, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
295811 - xen xen Use-after-free vulnerability in the libxl_list_cpupool function in the libxl toolstack library in Xen 4.2.x and 4.3.x, when running "under memory pressure," returns the original pointer when the real… CWE-399
 Resource Management Errors
CVE-2013-4371 2024-11-21 10:55 2013-10-18 Show GitHub Exploit DB Packet Storm
295812 - xen xen The ocaml binding for the xc_vcpu_getaffinity function in Xen 4.2.x and 4.3.x frees certain memory that may still be intended for use, which allows local users to cause a denial of service (heap corr… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2013-4370 2024-11-21 10:55 2013-10-18 Show GitHub Exploit DB Packet Storm
295813 - xen xen The xlu_vif_parse_rate function in the libxlu library in Xen 4.2.x and 4.3.x allows local users to cause a denial of service (NULL pointer dereference) by using the "@" character as the VIF rate conf… NVD-CWE-Other
CVE-2013-4369 2024-11-21 10:55 2013-10-18 Show GitHub Exploit DB Packet Storm
295814 - xen xen The outs instruction emulation in Xen 3.1.x, 4.2.x, 4.3.x, and earlier, when using FS: or GS: segment override, uses an uninitialized variable as a segment base, which allows local 64-bit PV guests t… CWE-200
Information Exposure
CVE-2013-4368 2024-11-21 10:55 2013-10-18 Show GitHub Exploit DB Packet Storm
295815 - apache
debian
opensuse
suse
mod_fcgid
debian_linux
opensuse
linux_enterprise_software_development_kit
cloud
Heap-based buffer overflow in the fcgid_header_bucket_read function in fcgid_bucket.c in the mod_fcgid module before 2.3.9 for the Apache HTTP Server allows remote attackers to have an unspecified im… CWE-787
 Out-of-bounds Write
CVE-2013-4365 2024-11-21 10:55 2013-10-18 Show GitHub Exploit DB Packet Storm
295816 - rubygems
ruby-lang
rubygems
ruby
Algorithmic complexity vulnerability in Gem::Version::ANCHORED_VERSION_PATTERN in lib/rubygems/version.rb in RubyGems before 1.8.23.2, 1.8.24 through 1.8.26, 2.0.x before 2.0.10, and 2.1.x before 2.1… CWE-310
Cryptographic Issues
CVE-2013-4363 2024-11-21 10:55 2013-10-18 Show GitHub Exploit DB Packet Storm
295817 - redhat
rubygems
ruby-lang
enterprise_linux
rubygems
ruby
Algorithmic complexity vulnerability in Gem::Version::VERSION_PATTERN in lib/rubygems/version.rb in RubyGems before 1.8.23.1, 1.8.24 through 1.8.25, 2.0.x before 2.0.8, and 2.1.x before 2.1.0, as use… CWE-310
Cryptographic Issues
CVE-2013-4287 2024-11-21 10:55 2013-10-18 Show GitHub Exploit DB Packet Storm
295818 - rubyonrails
opensuse
debian
rails
opensuse
debian_linux
Multiple format string vulnerabilities in log_subscriber.rb files in the log subscriber component in Action Mailer in Ruby on Rails 3.x before 3.2.15 allow remote attackers to cause a denial of servi… CWE-134
Use of Externally-Controlled Format String
CVE-2013-4389 2024-11-21 10:55 2013-10-17 Show GitHub Exploit DB Packet Storm
295819 - videolan vlc_media_player Buffer overflow in the mp4a packetizer (modules/packetizer/mpeg4audio.c) in VideoLAN VLC Media Player before 2.0.8 allows remote attackers to cause a denial of service (crash) and possibly execute ar… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2013-4388 2024-11-21 10:55 2013-10-12 Show GitHub Exploit DB Packet Storm
295820 - qemu qemu Use-after-free vulnerability in the virtio-pci implementation in Qemu 1.4.0 through 1.6.0 allows local users to cause a denial of service (daemon crash) by "hot-unplugging" a virtio device. CWE-399
 Resource Management Errors
CVE-2013-4377 2024-11-21 10:55 2013-10-12 Show GitHub Exploit DB Packet Storm