Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 24, 2026, noon

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
216261 4.3 警告 AITpro - WordPress 用 BulletProof Security プラグインの admin/htaccess/bpsunlock.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-7958 2014-11-7 15:27 2014-11-5 Show GitHub Exploit DB Packet Storm
216262 4.3 警告 Wordfence.com - WordPress 用 Wordfence Security プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-4664 2014-11-7 15:27 2014-06-30 Show GitHub Exploit DB Packet Storm
216263 3.5 注意 Compfight - WordPress 用 Compfight プラグインの compfight-search.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-8622 2014-11-7 15:27 2014-07-3 Show GitHub Exploit DB Packet Storm
216264 7.5 危険 CA Technologies - CA Cloud Service Management における任意のファイルを読まれる脆弱性 CWE-nocwe
CWE以外
CVE-2014-8474 2014-11-7 15:22 2014-11-3 Show GitHub Exploit DB Packet Storm
216265 6.8 警告 CA Technologies - CA Cloud Service Management におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2014-8473 2014-11-7 15:21 2014-11-3 Show GitHub Exploit DB Packet Storm
216266 6.8 警告 CA Technologies - CA Cloud Service Management におけるアクセス制限を回避される脆弱性 CWE-287
不適切な認証
CVE-2014-8472 2014-11-7 15:20 2014-11-3 Show GitHub Exploit DB Packet Storm
216267 4.3 警告 CA Technologies - CA Cloud Service Management における反射攻撃を実行される脆弱性 CWE-noinfo
情報不足
CVE-2014-8471 2014-11-7 15:20 2014-11-3 Show GitHub Exploit DB Packet Storm
216268 4.3 警告 LaboCNIL - French National Commission on Informatics and Liberty CookieViz の json.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-8352 2014-11-7 14:56 2014-11-4 Show GitHub Exploit DB Packet Storm
216269 7.5 危険 LaboCNIL - French National Commission on Informatics and Liberty CookieViz の info.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2014-8351 2014-11-7 14:55 2014-11-4 Show GitHub Exploit DB Packet Storm
216270 4.3 警告 Forma Lms project - Forma Lms におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-5257 2014-11-7 14:53 2014-11-4 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 24, 2026, 4:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
292411 - ffmpeg ffmpeg Array index error in the qdm2_decode_super_block function in libavcodec/qdm2.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted QDM2 data, which triggers an out-… CWE-20
 Improper Input Validation 
CVE-2013-0846 2024-11-21 10:48 2013-12-8 Show GitHub Exploit DB Packet Storm
292412 - ffmpeg ffmpeg libavcodec/alsdec.c in FFmpeg before 1.0.4 allows remote attackers to have an unspecified impact via a crafted block length, which triggers an out-of-bounds write. CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2013-0845 2024-11-21 10:48 2013-12-8 Show GitHub Exploit DB Packet Storm
292413 - ffmpeg ffmpeg Off-by-one error in the adpcm_decode_frame function in libavcodec/adpcm.c in FFmpeg before 1.0.4 allows remote attackers to have an unspecified impact via crafted DK4 data, which triggers an out-of-b… CWE-189
Numeric Errors
CVE-2013-0844 2024-11-21 10:48 2013-12-8 Show GitHub Exploit DB Packet Storm
292414 - opensuse opensuse The SUSE horde5 package before 5.0.2-2.4.1 sets incorrect ownership for certain configuration files and directories including /etc/apache2/vhosts.d, which allows local wwwrun users to gain privileges… CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-1090 2024-11-21 10:48 2013-12-7 Show GitHub Exploit DB Packet Storm
292415 - canonical ubuntu_linux
maas
maas-import-pxe-files in MAAS before 13.10 does not verify the integrity of downloaded files, which allows remote attackers to modify these files via a man-in-the-middle (MITM) attack. CWE-310
Cryptographic Issues
CVE-2013-1058 2024-11-21 10:48 2013-11-24 Show GitHub Exploit DB Packet Storm
292416 - ffmpeg ffmpeg The field_end function in libavcodec/h264.c in FFmpeg before 1.1.2 allows remote attackers to have an unspecified impact via crafted H.264 data, related to an SPS and slice mismatch and an out-of-bou… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2013-0869 2024-11-21 10:48 2013-11-24 Show GitHub Exploit DB Packet Storm
292417 - ffmpeg ffmpeg libavcodec/huffyuvdec.c in FFmpeg before 1.1.2 allows remote attackers to have an unspecified impact via crafted Huffyuv data, related to an out-of-bounds write and (1) unchecked return codes from th… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2013-0868 2024-11-21 10:48 2013-11-24 Show GitHub Exploit DB Packet Storm
292418 - ffmpeg ffmpeg The decode_slice_header function in libavcodec/h264.c in FFmpeg before 1.1.2 does not properly check when the pixel format changes, which allows remote attackers to have unspecified impact via crafte… CWE-20
 Improper Input Validation 
CVE-2013-0867 2024-11-21 10:48 2013-11-24 Show GitHub Exploit DB Packet Storm
292419 - ffmpeg ffmpeg The aac_decode_init function in libavcodec/aacdec.c in FFmpeg before 1.0.4 and 1.1.x before 1.1.2 allows remote attackers to have an unspecified impact via a large number of channels in an AAC file, … CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2013-0866 2024-11-21 10:48 2013-11-24 Show GitHub Exploit DB Packet Storm
292420 - ffmpeg ffmpeg The vqa_decode_chunk function in libavcodec/vqavideo.c in FFmpeg before 1.0.4 and 1.1.x before 1.1.2 allows remote attackers to have an unspecified impact via a large (1) cbp0 or (2) cbpz chunk in We… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2013-0865 2024-11-21 10:48 2013-11-24 Show GitHub Exploit DB Packet Storm