Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 15, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
216121 5.4 警告 Background Check protool - Android 用 Background Check protool アプリケーションにおけるサーバになりすまされる脆弱性 CWE-310
暗号の問題
CVE-2014-5580 2014-09-18 16:57 2014-09-3 Show GitHub Exploit DB Packet Storm
216122 5.4 警告 Thomas Fun Apps. - Android 用 brokenscreencrank アプリケーションにおけるサーバになりすまされる脆弱性 CWE-310
暗号の問題
CVE-2014-5587 2014-09-18 16:57 2014-09-3 Show GitHub Exploit DB Packet Storm
216123 5.4 警告 BeenVerified.com - Android 用 Background Check BeenVerified アプリケーションにおけるサーバになりすまされる脆弱性 CWE-310
暗号の問題
CVE-2014-5584 2014-09-18 16:57 2014-09-3 Show GitHub Exploit DB Packet Storm
216124 5.4 警告 Black Belt Studio - Android 用 Most Popular Ringtones アプリケーションにおけるサーバになりすまされる脆弱性 CWE-310
暗号の問題
CVE-2014-5583 2014-09-18 16:57 2014-09-3 Show GitHub Exploit DB Packet Storm
216125 5.4 警告 Caesar - Android 用 mirror photo & shape アプリケーションにおけるサーバになりすまされる脆弱性 CWE-310
暗号の問題
CVE-2014-5581 2014-09-18 16:57 2014-09-3 Show GitHub Exploit DB Packet Storm
216126 5.4 警告 The Big Byte - Android 用 Ingress Intel Helper アプリケーションにおけるサーバになりすまされる脆弱性 CWE-310
暗号の問題
CVE-2014-5582 2014-09-18 16:57 2014-09-3 Show GitHub Exploit DB Packet Storm
216127 5.4 警告 Ask.fm - Android 用 Ask.fm - Social Q&A Network アプリケーションにおけるサーバになりすまされる脆弱性 CWE-310
暗号の問題
CVE-2014-5574 2014-09-18 16:57 2014-09-3 Show GitHub Exploit DB Packet Storm
216128 5.4 警告 Azeus Systems Limited - Android 用 Anywhere Pad-Meet, Collaborate アプリケーションにおけるサーバになりすまされる脆弱性 CWE-310
暗号の問題
CVE-2014-5579 2014-09-18 16:57 2014-09-3 Show GitHub Exploit DB Packet Storm
216129 5.4 警告 Avus Capital - Android 用 Trading 212 FOREX アプリケーションにおけるサーバになりすまされる脆弱性 CWE-310
暗号の問題
CVE-2014-5578 2014-09-18 16:57 2014-09-3 Show GitHub Exploit DB Packet Storm
216130 5.4 警告 BeautyntheRep - Android 用 AVON Buy & Sell アプリケーションにおけるサーバになりすまされる脆弱性 CWE-310
暗号の問題
CVE-2014-5577 2014-09-18 16:57 2014-09-3 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 15, 2026, 4:28 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
293841 - david_alkire drag_\&_drop_gallery Unrestricted file upload vulnerability in upload.php in the Drag & Drop Gallery module 6.x-1.5 and earlier for Drupal allows remote attackers to execute arbitrary PHP code by uploading a file with an… NVD-CWE-Other
CVE-2012-4472 2024-11-21 10:42 2012-12-1 Show GitHub Exploit DB Packet Storm
293842 - dominique_clause search_autocomplete The Search Autocomplete module 7.x-2.x before 7.x-2.4 for Drupal does not properly restrict access to the module admin page, which allows remote attackers to disable an autocompletion or change the p… CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-4471 2024-11-21 10:42 2012-12-1 Show GitHub Exploit DB Packet Storm
293843 - philip_ludlam listhandler The Listhandler module 6.x-1.x before 6.x-1.1 for Drupal does not properly check permissions when importing emails, which allows remote comment authors to bypass access restrictions and possibly have… CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-4470 2024-11-21 10:42 2012-12-1 Show GitHub Exploit DB Packet Storm
293844 - simon_rycroft hashcash Cross-site scripting (XSS) vulnerability in the Hashcash module 6.x-2.x before 6.x-2.6 and 7.x-2.x before 7.x-2.2 for Drupal, when "Log failed hashcash" is enabled, allows remote attackers to inject … CWE-79
Cross-site Scripting
CVE-2012-4469 2024-11-21 10:42 2012-12-1 Show GitHub Exploit DB Packet Storm
293845 - privatemsg_project privatemsg Cross-site scripting (XSS) vulnerability in the Privatemsg module 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via a user name in a private message. CWE-79
Cross-site Scripting
CVE-2012-4468 2024-11-21 10:42 2012-12-1 Show GitHub Exploit DB Packet Storm
293846 - google android drivers/gpu/msm/kgsl.c in the Qualcomm Innovation Center (QuIC) Graphics KGSL kernel-mode driver for Android 2.3 through 4.2 allows attackers to cause a denial of service (NULL pointer dereference) v… CWE-20
 Improper Input Validation 
CVE-2012-4222 2024-11-21 10:42 2012-11-30 Show GitHub Exploit DB Packet Storm
293847 - google android Integer overflow in diagchar_core.c in the Qualcomm Innovation Center (QuIC) Diagnostics (aka DIAG) kernel-mode driver for Android 2.3 through 4.2 allows attackers to execute arbitrary code or cause … CWE-189
Numeric Errors
CVE-2012-4221 2024-11-21 10:42 2012-11-30 Show GitHub Exploit DB Packet Storm
293848 - google android diagchar_core.c in the Qualcomm Innovation Center (QuIC) Diagnostics (aka DIAG) kernel-mode driver for Android 2.3 through 4.2 allows attackers to execute arbitrary code or cause a denial of service … NVD-CWE-noinfo
CVE-2012-4220 2024-11-21 10:42 2012-11-30 Show GitHub Exploit DB Packet Storm
293849 - xen xen The graphical console in Xen 4.0, 4.1 and 4.2 allows local OS guest administrators to obtain sensitive host resource information via the qemu monitor. NOTE: this might be a duplicate of CVE-2007-099… CWE-200
Information Exposure
CVE-2012-4411 2024-11-21 10:42 2012-11-24 Show GitHub Exploit DB Packet Storm
293850 - mcrypt mcrypt Multiple format string vulnerabilities in mcrypt 2.6.8 and earlier might allow user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via vectors invol… CWE-134
Use of Externally-Controlled Format String
CVE-2012-4426 2024-11-21 10:42 2012-11-22 Show GitHub Exploit DB Packet Storm