Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 18, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
216761 4.3 警告 Mikko Saari - WordPress 用 Relevanssi プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-9443 2015-01-8 13:47 2014-12-16 Show GitHub Exploit DB Packet Storm
216762 6.5 警告 Reality66 - WordPress 用 Cart66 Lite プラグインの models/Cart66Ajax.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2014-9442 2015-01-8 13:46 2014-12-22 Show GitHub Exploit DB Packet Storm
216763 6.8 警告 Lightbox Photo Gallery project - WordPress 用 Lightbox Photo Gallery プラグインにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2014-9441 2015-01-8 13:46 2014-12-12 Show GitHub Exploit DB Packet Storm
216764 6.8 警告 Sliding Social Icons project - WordPress 用 Sliding Social Icons プラグインにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2014-9437 2015-01-8 13:46 2014-12-12 Show GitHub Exploit DB Packet Storm
216765 6.8 警告 e107.org - e107 の e107_admin/users.php の AdminObserver 関数におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2014-9459 2015-01-8 12:20 2014-12-28 Show GitHub Exploit DB Packet Storm
216766 10 危険 Hex-Rays - Hex-Rays IDA の GDB debugger モジュールにおけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2014-9458 2015-01-8 12:13 2014-12-24 Show GitHub Exploit DB Packet Storm
216767 6.5 警告 PMB Services SAS. - PMB の classes/mono_display.class.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2014-9457 2015-01-8 12:03 2014-12-25 Show GitHub Exploit DB Packet Storm
216768 5.8 警告 NYU - Ex Libris Patron Directory Services 用 NYU OpenSSO Integration のログインページにおけるオープンリダイレクトの脆弱性 CWE-Other
その他
CVE-2014-7294 2015-01-8 11:53 2014-12-29 Show GitHub Exploit DB Packet Storm
216769 4.3 警告 NYU - Ex Libris Patron Directory Services 用 NYU OpenSSO Integration のログインページにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-7293 2015-01-8 11:53 2014-12-29 Show GitHub Exploit DB Packet Storm
216770 4.3 警告 IPCop - IPCop の cgi-bin/ipinfo.cgi におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-7417 2015-01-7 19:48 2013-04-25 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 18, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
290711 - ibm curam_social_program_management Multiple CRLF injection vulnerabilities in the Universal Access component in IBM Curam Social Program Management (SPM) 6.0.5.5, when WebSphere Application Server is not used, allow remote authenticat… NVD-CWE-Other
CVE-2014-3069 2024-11-21 11:07 2014-08-12 Show GitHub Exploit DB Packet Storm
290712 - ibm tivoli_business_service_manager Cross-site scripting (XSS) vulnerability in IBM Tivoli Business Service Manager 4.2.0 before 4.2.0.0 IF12 and 4.2.1 before 4.2.1.3 IF9 allows remote authenticated users to inject arbitrary web script… CWE-79
Cross-site Scripting
CVE-2014-3031 2024-11-21 11:07 2014-08-12 Show GitHub Exploit DB Packet Storm
290713 - cisco nx-os
nexus_9000
Cisco NX-OS 6.1(2)I2(1) on Nexus 9000 switches does not properly process packet-drop policy checks for logged packets, which allows remote attackers to bypass intended access restrictions via a flood… CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-3330 2024-11-21 11:07 2014-08-12 Show GitHub Exploit DB Packet Storm
290714 - cisco ios_xe
ios
The EnergyWise module in Cisco IOS 12.2, 15.0, 15.1, 15.2, and 15.4 and IOS XE 3.2.xXO, 3.3.xSG, 3.4.xSG, and 3.5.xE before 3.5.3E allows remote attackers to cause a denial of service (device reload)… CWE-20
 Improper Input Validation 
CVE-2014-3327 2024-11-21 11:07 2014-08-12 Show GitHub Exploit DB Packet Storm
290715 - ibm business_process_manager IBM Business Process Manager (BPM) 8.5 through 8.5.5 allows remote attackers to obtain potentially sensitive information by visiting an unspecified JSP diagnostic page. CWE-200
Information Exposure
CVE-2014-3076 2024-11-21 11:07 2014-08-12 Show GitHub Exploit DB Packet Storm
290716 - cisco unity_connection SQL injection vulnerability in the web framework in Cisco Unity Connection 9.1(2) and earlier allows remote authenticated users to execute arbitrary SQL commands via a crafted request, aka Bug ID CSC… CWE-89
SQL Injection
CVE-2014-3336 2024-11-21 11:07 2014-08-12 Show GitHub Exploit DB Packet Storm
290717 - cisco unity_connection The server in Cisco Unity Connection 9.1(1) and 9.1(2) allows remote authenticated users to obtain privileged access by conducting an "HTTP Intercept" attack and leveraging the ability to read files … CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-3333 2024-11-21 11:07 2014-08-12 Show GitHub Exploit DB Packet Storm
290718 - cisco unified_communications_manager Cisco Unified Communications Manager (CM) 8.6(.2) and earlier has an incorrect CLI restrictions setting, which allows remote authenticated users to establish undetected concurrent logins via unspecif… NVD-CWE-noinfo
CVE-2014-3332 2024-11-21 11:07 2014-08-12 Show GitHub Exploit DB Packet Storm
290719 - cisco webex_meetings_server user.php in Cisco WebEx Meetings Server 1.5(.1.131) and earlier does not properly implement the token timer for authenticated encryption, which allows remote attackers to obtain sensitive information… CWE-310
Cryptographic Issues
CVE-2014-3302 2024-11-21 11:07 2014-08-1 Show GitHub Exploit DB Packet Storm
290720 - ibm infosphere_master_data_management_server_for_product_information_management
infosphere_master_data_management
The GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.0 through 11.0 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 does n… CWE-20
 Improper Input Validation 
CVE-2014-3009 2024-11-21 11:07 2014-08-1 Show GitHub Exploit DB Packet Storm