Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 28, 2026, 4:09 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
216141 2.1 注意 ClamAV - ClamAV の clamscan におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2013-6497 2014-12-2 10:52 2013-11-4 Show GitHub Exploit DB Packet Storm
216142 6.8 警告 lwIP プロジェクト
Contiki プロジェクト
- uIP と lwIP の DNS リゾルバにキャッシュポイズニングの脆弱性 CWE-Other
CWE-Other
CVE-2014-4883 2014-12-1 18:06 2014-11-3 Show GitHub Exploit DB Packet Storm
216143 6.8 警告 Xavoc Technocrats Pvt. Ltd. - Xavoc Technocrats xEpan CMS におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2014-8429 2014-12-1 18:04 2014-10-22 Show GitHub Exploit DB Packet Storm
216144 4.3 警告 レッドハット - FreeIPA の Web UI におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-7850 2014-12-1 17:37 2014-11-18 Show GitHub Exploit DB Packet Storm
216145 9.3 危険 Enalean - Enalean Tuleap における任意のコマンドを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2014-7178 2014-12-1 17:33 2014-09-18 Show GitHub Exploit DB Packet Storm
216146 5 警告 MatrikonOPC - DNP3 用 MatrikonOPC OPC Server におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2014-5426 2014-12-1 17:24 2014-10-22 Show GitHub Exploit DB Packet Storm
216147 6.8 警告 OpenVPN Technologies - OpenVPN Access Server のデスクトップクライアントの XML-RPC API におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2014-9104 2014-12-1 17:22 2014-07-1 Show GitHub Exploit DB Packet Storm
216148 6.8 警告 Oxwall
skalfa
- Oxwall および SkaDate Lite におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2014-9101 2014-12-1 17:21 2014-07-28 Show GitHub Exploit DB Packet Storm
216149 10 危険 ARRIS Group - ARRIS VAP2500 の管理ポータルにおける任意のコマンドを実行される脆弱性 CWE-Other
その他
CVE-2014-8423 2014-12-1 17:02 2014-11-25 Show GitHub Exploit DB Packet Storm
216150 7.8 危険 ARRIS Group - ARRIS VAP2500 における認証を回避される脆弱性 CWE-287
不適切な認証
CVE-2014-8424 2014-12-1 17:01 2014-11-25 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 28, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
293241 - spreecommerce spree Spree Commerce 1.0.x through 1.3.2 allows remote authenticated administrators to instantiate arbitrary Ruby objects and execute arbitrary commands via the (1) payment_method parameter to core/app/con… CWE-20
 Improper Input Validation 
CVE-2013-1656 2024-11-21 10:50 2013-03-9 Show GitHub Exploit DB Packet Storm
293242 - linux linux_kernel The _xfs_buf_find function in fs/xfs/xfs_buf.c in the Linux kernel before 3.7.6 does not validate block numbers, which allows local users to cause a denial of service (NULL pointer dereference and sy… CWE-20
 Improper Input Validation 
CVE-2013-1819 2024-11-21 10:50 2013-03-7 Show GitHub Exploit DB Packet Storm
293243 - php php The SOAP parser in PHP before 5.3.23 and 5.4.x before 5.4.13 allows remote attackers to read arbitrary files via a SOAP WSDL file containing an XML external entity declaration in conjunction with an … CWE-200
Information Exposure
CVE-2013-1643 2024-11-21 10:50 2013-03-6 Show GitHub Exploit DB Packet Storm
293244 - php php ext/soap/soap.c in PHP before 5.3.22 and 5.4.x before 5.4.13 does not validate the relationship between the soap.wsdl_cache_dir directive and the open_basedir directive, which allows remote attackers… CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-1635 2024-11-21 10:50 2013-03-6 Show GitHub Exploit DB Packet Storm
293245 - todd_miller
apple
sudo
mac_os_x
sudo 1.6.0 through 1.7.10p6 and sudo 1.8.0 through 1.8.6p6 allows local users or physically proximate attackers to bypass intended time restrictions and retain privileges without re-authenticating by… CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-1775 2024-11-21 10:50 2013-03-6 Show GitHub Exploit DB Packet Storm
293246 - linux
redhat
linux_kernel
enterprise_linux
enterprise_mrg
The chase_port function in drivers/usb/serial/io_ti.c in the Linux kernel before 3.7.4 allows local users to cause a denial of service (NULL pointer dereference and system crash) via an attempted /de… CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-1774 2024-11-21 10:50 2013-03-1 Show GitHub Exploit DB Packet Storm
293247 - linux
redhat
linux_kernel
enterprise_linux
enterprise_mrg
Buffer overflow in the VFAT filesystem implementation in the Linux kernel before 3.3 allows local users to gain privileges or cause a denial of service (system crash) via a VFAT write operation on a … CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2013-1773 2024-11-21 10:50 2013-03-1 Show GitHub Exploit DB Packet Storm
293248 - linux linux_kernel The log_prefix function in kernel/printk.c in the Linux kernel 3.x before 3.4.33 does not properly remove a prefix string from a syslog header, which allows local users to cause a denial of service (… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2013-1772 2024-11-21 10:50 2013-03-1 Show GitHub Exploit DB Packet Storm
293249 - linux linux_kernel Use-after-free vulnerability in the shmem_remount_fs function in mm/shmem.c in the Linux kernel before 3.7.10 allows local users to gain privileges or cause a denial of service (system crash) by remo… CWE-399
 Resource Management Errors
CVE-2013-1767 2024-11-21 10:50 2013-03-1 Show GitHub Exploit DB Packet Storm
293250 - linux linux_kernel Array index error in the __sock_diag_rcv_msg function in net/core/sock_diag.c in the Linux kernel before 3.7.10 allows local users to gain privileges via a large family value in a Netlink message. CWE-20
 Improper Input Validation 
CVE-2013-1763 2024-11-21 10:50 2013-03-1 Show GitHub Exploit DB Packet Storm