Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 20, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
216131 3.5 注意 FOG Project - FOG におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-3111 2014-10-28 10:58 2014-04-29 Show GitHub Exploit DB Packet Storm
216132 6.5 警告 InterWorx - InterWorx Web Control Panel の xhr.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2014-2531 2014-10-28 10:47 2014-03-17 Show GitHub Exploit DB Packet Storm
216133 4.3 警告 Splunk - Splunk におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-8380 2014-10-28 10:39 2014-05-27 Show GitHub Exploit DB Packet Storm
216134 4.3 警告 WebAsyst - Webasyst Shop-Script におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-8377 2014-10-28 10:11 2014-08-12 Show GitHub Exploit DB Packet Storm
216135 4.3 警告 Tenable, Inc. - Tenable Nessus 用 Web UI におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-7280 2014-10-28 09:58 2014-06-13 Show GitHub Exploit DB Packet Storm
216136 7.5 危険 Zoho Corporation - ZOHO ManageEngine Desktop Central におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2014-5006 2014-10-28 09:50 2014-08-31 Show GitHub Exploit DB Packet Storm
216137 7.5 危険 Zoho Corporation - ZOHO ManageEngine Desktop Central におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2014-5005 2014-10-28 09:49 2014-08-31 Show GitHub Exploit DB Packet Storm
216138 6.8 警告 MRBS - Drupal 用 MRBS モジュールにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2013-7407 2014-10-27 19:30 2013-07-17 Show GitHub Exploit DB Packet Storm
216139 7.5 危険 MRBS - Drupal 用 MRBS モジュールにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2013-7406 2014-10-27 19:30 2013-07-17 Show GitHub Exploit DB Packet Storm
216140 5 警告 Websupporter - WordPress 用 WP AmASIN - The Amazon Affiliate Shop プラグインの reviews.php における絶対パストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2014-4577 2014-10-27 18:55 2014-03-5 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 21, 2026, 4:10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
295141 - cisco ios
unified_communications_manager
ios_xe
The SIP implementation in Cisco Unified Communications Manager (CUCM) 6.x and 7.x before 7.1(5b)su5, 8.x before 8.5(1)su4, and 8.6 before 8.6(2a)su1; Cisco IOS 12.2 through 12.4 and 15.0 through 15.2… CWE-20
 Improper Input Validation 
CVE-2012-3949 2024-11-21 10:41 2012-09-27 Show GitHub Exploit DB Packet Storm
295142 - apple iphone_os WebKit, as used in Apple iOS before 6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. CWE-119
CWE-399
Incorrect Access of Indexable Resource ('Range Error') 
 Resource Management Errors
CVE-2012-3747 2024-11-21 10:41 2012-09-21 Show GitHub Exploit DB Packet Storm
295143 - apple iphone_os UIWebView in UIKit in Apple iOS before 6 does not properly use the Data Protection feature, which allows context-dependent attackers to obtain cleartext file content by leveraging direct access to a … CWE-310
Cryptographic Issues
CVE-2012-3746 2024-11-21 10:41 2012-09-21 Show GitHub Exploit DB Packet Storm
295144 - apple iphone_os Off-by-one error in Telephony in Apple iOS before 6 allows remote attackers to cause a denial of service (buffer overflow and connectivity outage) via a crafted user-data header in an SMS message. CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2012-3745 2024-11-21 10:41 2012-09-21 Show GitHub Exploit DB Packet Storm
295145 - apple iphone_os Telephony in Apple iOS before 6 uses an SMS message's return address as the displayed sender address, which allows remote attackers to spoof text communication via a message in which the return addre… NVD-CWE-Other
CVE-2012-3744 2024-11-21 10:41 2012-09-21 Show GitHub Exploit DB Packet Storm
295146 - apple iphone_os The System Logs implementation in Apple iOS before 6 does not restrict /var/log access by sandboxed apps, which allows remote attackers to obtain sensitive information via a crafted app that reads lo… CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-3743 2024-11-21 10:41 2012-09-21 Show GitHub Exploit DB Packet Storm
295147 - apple iphone_os Safari in Apple iOS before 6 does not properly restrict use of an unspecified Unicode character that looks similar to the https lock indicator, which allows remote attackers to spoof https connection… CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-3742 2024-11-21 10:41 2012-09-21 Show GitHub Exploit DB Packet Storm
295148 - apple iphone_os The Restrictions (aka Parental Controls) implementation in Apple iOS before 6 does not properly handle purchase attempts after a Disable Restrictions action, which allows local users to bypass an int… CWE-287
Improper Authentication
CVE-2012-3741 2024-11-21 10:41 2012-09-21 Show GitHub Exploit DB Packet Storm
295149 - apple iphone_os The Passcode Lock implementation in Apple iOS before 6 does not properly manage the lock state, which allows physically proximate attackers to bypass an intended passcode requirement via unspecified … CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-3740 2024-11-21 10:41 2012-09-21 Show GitHub Exploit DB Packet Storm
295150 - apple iphone_os The Passcode Lock implementation in Apple iOS before 6 allows physically proximate attackers to bypass an intended passcode requirement via vectors involving use of the camera. CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-3739 2024-11-21 10:41 2012-09-21 Show GitHub Exploit DB Packet Storm