Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 15, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
216441 7.5 危険 php-sqrl project - php-sqrl の sqrl_verify.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2014-5458 2014-08-27 16:34 2014-08-17 Show GitHub Exploit DB Packet Storm
216442 4.9 警告 IBM - IBM Emptoris Sourcing Portfolio および Emptoris Spend Analysis におけるフィッシング攻撃を実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-4790 2014-08-27 16:25 2014-08-12 Show GitHub Exploit DB Packet Storm
216443 6 警告 IBM - 複数の IBM Emptoris 製品におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2014-3040 2014-08-27 16:24 2014-08-12 Show GitHub Exploit DB Packet Storm
216444 3.5 注意 IBM - IBM Emptoris Sourcing Portfolio におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-3033 2014-08-27 16:24 2014-08-12 Show GitHub Exploit DB Packet Storm
216445 2.6 注意 サン・マイクロシステムズ
Linux
IBM
ヒューレット・パッカード
- 複数の OS 上で稼動する IBM Tivoli Storage Manager for Space Management のバックアップ/アーカイブ・クライアントにおけるアクセス制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-6335 2014-08-27 16:23 2013-10-31 Show GitHub Exploit DB Packet Storm
216446 6.9 警告 OpenVPN Technologies - OpenVPN に同梱された PrivateTunnel の ptservice サービスにおける権限を取得される脆弱性 CWE-Other
その他
CVE-2014-5455 2014-08-27 15:57 2014-07-11 Show GitHub Exploit DB Packet Storm
216447 6 警告 SAS - SAS Visual Analytics のイメージアップロードモジュールにおける任意のコードを実行される脆弱性 CWE-Other
その他
CVE-2014-5454 2014-08-27 15:26 2014-08-13 Show GitHub Exploit DB Packet Storm
216448 2.1 注意 Social Stats project - Drupal 用 Social Stats モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-5456 2014-08-27 14:59 2014-08-19 Show GitHub Exploit DB Packet Storm
216449 7.2 危険 Ubisoft - Ubisoft Uplay PC における権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-5453 2014-08-27 14:22 2014-07-3 Show GitHub Exploit DB Packet Storm
216450 6.8 警告 innovaphone AG - innovaphone PBX におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2014-5335 2014-08-27 13:58 2014-08-21 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 15, 2026, 4:28 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
295841 - squid-cache squid Squid 3.1.9 allows remote attackers to bypass the access configuration for the CONNECT method by providing an arbitrary allowed hostname in the Host HTTP header. NOTE: this issue might not be reprod… CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-2213 2024-11-21 10:38 2012-04-28 Show GitHub Exploit DB Packet Storm
295842 - mcafee web_gateway McAfee Web Gateway 7.0 allows remote attackers to bypass the access configuration for the CONNECT method by providing an arbitrary allowed hostname in the Host HTTP header. NOTE: this issue might no… CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-2212 2024-11-21 10:38 2012-04-28 Show GitHub Exploit DB Packet Storm
295843 - openssl openssl Multiple integer signedness errors in crypto/buffer/buffer.c in OpenSSL 0.9.8v allow remote attackers to conduct buffer overflow attacks, and cause a denial of service (memory corruption) or possibly… CWE-189
Numeric Errors
CVE-2012-2131 2024-11-21 10:38 2012-04-25 Show GitHub Exploit DB Packet Storm
295844 - teampass teampass Cross-site scripting (XSS) vulnerability in sources/users.queries.php in TeamPass before 2.1.6 allows remote authenticated users to inject arbitrary web script or HTML via the login parameter in an a… CWE-79
Cross-site Scripting
CVE-2012-2234 2024-11-21 10:38 2012-04-22 Show GitHub Exploit DB Packet Storm
295845 - owncloud owncloud Open redirect vulnerability in index.php (aka the Login Page) in ownCloud before 3.0.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the r… CWE-20
 Improper Input Validation 
CVE-2012-2270 2024-11-21 10:38 2012-04-20 Show GitHub Exploit DB Packet Storm
295846 - owncloud owncloud Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 3.0.3 allow remote attackers to inject arbitrary web script or HTML via (1) an arbitrary field to apps/contacts/ajax/addcard.php… CWE-79
Cross-site Scripting
CVE-2012-2269 2024-11-21 10:38 2012-04-20 Show GitHub Exploit DB Packet Storm
295847 - ryan_walberg php_gift_registry SQL injection vulnerability in users.php in PHP Gift Registry 1.5.5 allows remote authenticated users to execute arbitrary SQL commands via the userid parameter in an edit action. CWE-89
SQL Injection
CVE-2012-2236 2024-11-21 10:38 2012-04-20 Show GitHub Exploit DB Packet Storm
295848 - comodo comodo_internet_security Comodo Internet Security before 5.10.228257.2253 on Windows 7 x64 allows local users to cause a denial of service (system crash) via a crafted 32-bit Portable Executable (PE) file with a kernel Image… CWE-94
Code Injection
CVE-2012-2273 2024-11-21 10:38 2012-04-20 Show GitHub Exploit DB Packet Storm
295849 - openssl
redhat
openssl The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in OpenSSL before 0.9.8v, 1.0.0 before 1.0.0i, and 1.0.1 before 1.0.1a does not properly interpret integer data, which allows remote attackers… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2012-2110 2024-11-21 10:38 2012-04-20 Show GitHub Exploit DB Packet Storm
295850 - hp system_management_homepage Unspecified vulnerability in HP System Management Homepage (SMH) before 7.0 allows local users to modify data or obtain sensitive information via unknown vectors. NVD-CWE-noinfo
CVE-2012-1993 2024-11-21 10:38 2012-04-18 Show GitHub Exploit DB Packet Storm