Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 11, 2026, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
216781 5 警告 Apache Software Foundation - Apache MyFaces Core の MyFaces JavaServer Faces におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2011-4367 2014-06-23 15:26 2011-11-4 Show GitHub Exploit DB Packet Storm
216782 7.8 危険 Belkin International - Belkin N150 におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2014-2962 2014-06-23 13:52 2014-06-18 Show GitHub Exploit DB Packet Storm
216783 5.5 警告 F5 Networks - F5 ARX Data Manager に SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2014-2949 2014-06-23 13:52 2014-06-17 Show GitHub Exploit DB Packet Storm
216784 4 警告 東日本旅客鉄道株式会社 - Android 版アプリ「JR東日本アプリ」における SSL サーバ証明書の検証不備の脆弱性 CWE-Other
その他
CVE-2014-2001 2014-06-23 13:51 2014-06-18 Show GitHub Exploit DB Packet Storm
216785 2.6 注意 エヌ・ティ・ティ・コミュニケーションズ株式会社 - Android 版アプリ「050 plus」における情報管理不備の脆弱性 CWE-200
情報漏えい
CVE-2014-2000 2014-06-23 13:51 2014-06-17 Show GitHub Exploit DB Packet Storm
216786 4.3 警告 Real Time Logic - BarracudaDrive におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-4335 2014-06-23 13:47 2014-06-17 Show GitHub Exploit DB Packet Storm
216787 5 警告 Canonical - Ubuntu 用 OpenStack Nova および Openstack Cinder パッケージにおける権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-1068 2014-06-23 13:46 2013-01-11 Show GitHub Exploit DB Packet Storm
216788 9.3 危険 アドビシステムズ - Adobe Photoshop CS5 の U3D.8BI library プラグインにおけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2012-2052 2014-06-23 13:46 2012-05-8 Show GitHub Exploit DB Packet Storm
216789 6.8 警告 ARRIS Group - ARRIS SBG901 SURFboard Wireless Cable Modem の goform/RgDdns におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2014-3778 2014-06-23 12:11 2014-06-17 Show GitHub Exploit DB Packet Storm
216790 6.8 警告 BoonEx - Dolphin の administration/profiles.php におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2014-4333 2014-06-23 12:07 2014-06-17 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 12, 2026, 5:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
293521 - hp operations_orchestration Unspecified vulnerability in HP Operations Orchestration 9.0 before 9.03 allows remote attackers to execute arbitrary code via unknown vectors. NVD-CWE-noinfo
CVE-2012-3258 2024-11-21 10:40 2012-09-19 Show GitHub Exploit DB Packet Storm
293522 - siemens simatic_pcs7
wincc
WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allows remote attackers to discover a username and password via crafted parameters to unspecified method… CWE-200
Information Exposure
CVE-2012-3034 2024-11-21 10:40 2012-09-18 Show GitHub Exploit DB Packet Storm
293523 - siemens simatic_pcs7
wincc
SQL injection vulnerability in WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allows remote attackers to execute arbitrary SQL commands via a crafted S… CWE-89
SQL Injection
CVE-2012-3032 2024-11-21 10:40 2012-09-18 Show GitHub Exploit DB Packet Storm
293524 - siemens simatic_pcs7
wincc
Multiple cross-site scripting (XSS) vulnerabilities in WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allow remote attackers to inject arbitrary web sc… CWE-79
Cross-site Scripting
CVE-2012-3031 2024-11-21 10:40 2012-09-18 Show GitHub Exploit DB Packet Storm
293525 - siemens simatic_pcs7
wincc
WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, stores sensitive information under the web root with insufficient access control, which allows remote at… CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-3030 2024-11-21 10:40 2012-09-18 Show GitHub Exploit DB Packet Storm
293526 - siemens simatic_pcs7
wincc
Cross-site request forgery (CSRF) vulnerability in WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allows remote attackers to hijack the authentication … CWE-352
 Origin Validation Error
CVE-2012-3028 2024-11-21 10:40 2012-09-18 Show GitHub Exploit DB Packet Storm
293527 - cososys endpoint_protector_appliace_4 The CoSoSys Endpoint Protector 4 appliance establishes an EPProot password based entirely on the appliance serial number, which makes it easier for remote attackers to obtain access via a brute-force… CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-2994 2024-11-21 10:40 2012-09-18 Show GitHub Exploit DB Packet Storm
293528 5.9 MEDIUM
Network
microsoft windows_phone_7_firmware Microsoft Windows Phone 7 does not verify the domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL server for the (1) … CWE-295
Improper Certificate Validation 
CVE-2012-2993 2024-11-21 10:40 2012-09-18 Show GitHub Exploit DB Packet Storm
293529 - trendmicro interscan_messaging_security_suite Cross-site request forgery (CSRF) vulnerability in saveAccountSubTab.imss in Trend Micro InterScan Messaging Security Suite 7.1-Build_Win32_1394 allows remote attackers to hijack the authentication o… CWE-352
 Origin Validation Error
CVE-2012-2996 2024-11-21 10:40 2012-09-17 Show GitHub Exploit DB Packet Storm
293530 - trendmicro interscan_messaging_security_suite Multiple cross-site scripting (XSS) vulnerabilities in Trend Micro InterScan Messaging Security Suite 7.1-Build_Win32_1394 allow remote attackers to inject arbitrary web script or HTML via (1) the wr… CWE-79
Cross-site Scripting
CVE-2012-2995 2024-11-21 10:40 2012-09-17 Show GitHub Exploit DB Packet Storm