Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 2, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
216251 4.3 警告 The phpMyAdmin Project - phpMyAdmin におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-8958 2014-12-2 14:24 2014-11-20 Show GitHub Exploit DB Packet Storm
216252 2.1 注意 ESET - 複数の ESET 製品で使用される ESET Personal Firewall NDIS フィルタのカーネルモードドライバにおける重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2014-4974 2014-12-2 12:10 2014-10-22 Show GitHub Exploit DB Packet Storm
216253 5 警告 infoware GmbH - Infoware MapSuite の MapAPI における絶対パストラバーサルの脆弱性 CWE-Other
その他
CVE-2014-2232 2014-12-2 11:39 2014-03-24 Show GitHub Exploit DB Packet Storm
216254 2.1 注意 ClamAV - ClamAV の clamscan におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2013-6497 2014-12-2 10:52 2013-11-4 Show GitHub Exploit DB Packet Storm
216255 6.8 警告 lwIP プロジェクト
Contiki プロジェクト
- uIP と lwIP の DNS リゾルバにキャッシュポイズニングの脆弱性 CWE-Other
CWE-Other
CVE-2014-4883 2014-12-1 18:06 2014-11-3 Show GitHub Exploit DB Packet Storm
216256 6.8 警告 Xavoc Technocrats Pvt. Ltd. - Xavoc Technocrats xEpan CMS におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2014-8429 2014-12-1 18:04 2014-10-22 Show GitHub Exploit DB Packet Storm
216257 4.3 警告 レッドハット - FreeIPA の Web UI におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-7850 2014-12-1 17:37 2014-11-18 Show GitHub Exploit DB Packet Storm
216258 9.3 危険 Enalean - Enalean Tuleap における任意のコマンドを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2014-7178 2014-12-1 17:33 2014-09-18 Show GitHub Exploit DB Packet Storm
216259 5 警告 MatrikonOPC - DNP3 用 MatrikonOPC OPC Server におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2014-5426 2014-12-1 17:24 2014-10-22 Show GitHub Exploit DB Packet Storm
216260 6.8 警告 OpenVPN Technologies - OpenVPN Access Server のデスクトップクライアントの XML-RPC API におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2014-9104 2014-12-1 17:22 2014-07-1 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 2, 2026, 4:18 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
291901 - hitmyserver hms_testimonials Multiple cross-site request forgery (CSRF) vulnerabilities in the HMS Testimonials plugin before 2.0.11 for WordPress allow remote attackers to hijack the authentication of administrators for request… CWE-352
 Origin Validation Error
CVE-2013-4240 2024-11-21 10:55 2014-04-3 Show GitHub Exploit DB Packet Storm
291902 - samba
canonical
samba
ubuntu_linux
Samba 3.x before 3.6.23, 4.0.x before 4.0.16, and 4.1.x before 4.1.6 does not enforce the password-guessing protection mechanism for all interfaces, which makes it easier for remote attackers to obta… CWE-255
Credentials Management
CVE-2013-4496 2024-11-21 10:55 2014-03-14 Show GitHub Exploit DB Packet Storm
291903 - vicidial vicidial Multiple SQL injection vulnerabilities in the agent interface (agc/) in VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier allow (1) remote attackers to execute arbitrary SQ… CWE-89
SQL Injection
CVE-2013-4467 2024-11-21 10:55 2014-03-12 Show GitHub Exploit DB Packet Storm
291904 - php xhprof Cross-site scripting (XSS) vulnerability in XHProf before 0.9.4 allows remote attackers to inject arbitrary web script or HTML via the run parameter. CWE-79
Cross-site Scripting
CVE-2013-4433 2024-11-21 10:55 2014-03-12 Show GitHub Exploit DB Packet Storm
291905 - schneems wicked Directory traversal vulnerability in controller/concerns/render_redirect.rb in the Wicked gem before 1.0.1 for Ruby allows remote attackers to read arbitrary files via a %2E%2E%2F (encoded dot dot sl… CWE-22
Path Traversal
CVE-2013-4413 2024-11-21 10:55 2014-03-12 Show GitHub Exploit DB Packet Storm
291906 - plone plone mail_password.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote authenticated users to bypass the prohibition on password changes via the forgotten password emai… CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-4198 2024-11-21 10:55 2014-03-12 Show GitHub Exploit DB Packet Storm
291907 - plone plone (1) cb_decode.py and (2) linkintegrity.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allow remote authenticated users to cause a denial of service (resource consumption) v… CWE-20
 Improper Input Validation 
CVE-2013-4199 2024-11-21 10:55 2014-03-12 Show GitHub Exploit DB Packet Storm
291908 - plone plone member_portrait.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote authenticated users to modify or delete portraits of other users via unspecified vectors. CWE-20
 Improper Input Validation 
CVE-2013-4197 2024-11-21 10:55 2014-03-12 Show GitHub Exploit DB Packet Storm
291909 - plone plone Multiple open redirect vulnerabilities in (1) marmoset_patch.py, (2) publish.py, and (3) principiaredirect.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allow remote attac… CWE-20
 Improper Input Validation 
CVE-2013-4195 2024-11-21 10:55 2014-03-12 Show GitHub Exploit DB Packet Storm
291910 - plone plone The object manager implementation (objectmanager.py) in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 does not properly restrict access to internal methods, which allows remote … CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-4196 2024-11-21 10:55 2014-03-12 Show GitHub Exploit DB Packet Storm