Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 30, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
216961 4.3 警告 Exponent CMS project - Exponent CMS におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-6635 2014-10-29 15:45 2014-09-20 Show GitHub Exploit DB Packet Storm
216962 7.5 危険 XRMS CRM Project - XRMS CRM における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2014-5520 2014-10-29 15:41 2014-08-27 Show GitHub Exploit DB Packet Storm
216963 7.5 危険 F5 Networks - F5 BIG-IP Analytics における脆弱性 CWE-310
暗号の問題
CVE-2013-7408 2014-10-29 15:40 2013-04-9 Show GitHub Exploit DB Packet Storm
216964 5 警告 DeepRoot Linux - DeepOfix の SMTP サーバにおける認証を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-6796 2014-10-29 15:39 2013-11-6 Show GitHub Exploit DB Packet Storm
216965 7.5 危険 Zoho Corporation - ZOHO ManageEngine EventLog Analyzer の agentUpload サーブレットにおけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2014-6037 2014-10-29 15:39 2014-08-31 Show GitHub Exploit DB Packet Storm
216966 4.4 警告 Vinay Sajip - python-gnupg の shell_quote 関数における脆弱性 CWE-20
不適切な入力確認
CVE-2014-1929 2014-10-29 15:28 2014-06-4 Show GitHub Exploit DB Packet Storm
216967 4.6 警告 Vinay Sajip - python-gnupg の shell_quote 関数における任意のコードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2014-1928 2014-10-29 15:28 2014-02-5 Show GitHub Exploit DB Packet Storm
216968 7.5 危険 Vinay Sajip - python-gnupg の shell_quote 関数における任意のコードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2014-1927 2014-10-29 15:27 2014-02-5 Show GitHub Exploit DB Packet Storm
216969 2.1 注意 IBM - IBM API Management における重要な暗号文情報を取得される脆弱性 CWE-noinfo
情報不足
CVE-2014-6133 2014-10-29 14:29 2014-10-21 Show GitHub Exploit DB Packet Storm
216970 5 警告 IBM - IBM Sterling B2B Integrator のパスワード変更機能における管理者のアクセス権を取得される脆弱性 CWE-255
証明書・パスワード管理
CVE-2014-6099 2014-10-29 14:25 2014-10-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 30, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
291111 - redmine redmine_git_hosting_plugin git_http_controller.rb in the redmine_git_hosting plugin for Redmine allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the service parameter to info/refs, related … CWE-77
Command Injection
CVE-2013-4663 2024-11-21 10:56 2014-12-28 Show GitHub Exploit DB Packet Storm
291112 - umbraco umbraco_cms The update function in umbraco.webservices/templates/templateService.cs in the TemplateService component in Umbraco CMS before 6.0.4 does not require authentication, which allows remote attackers to … CWE-287
Improper Authentication
CVE-2013-4793 2024-11-21 10:56 2014-12-28 Show GitHub Exploit DB Packet Storm
291113 - eucalyptus eucalyptus The cloud controller (aka CLC) component in Eucalyptus 3.3.x and 3.4.x before 3.4.2, when the dns.recursive.enabled setting is used, allows remote attackers to cause a denial of service (traffic ampl… CWE-19
 Data Processing Errors
CVE-2013-4769 2024-11-21 10:56 2014-12-27 Show GitHub Exploit DB Packet Storm
291114 - owl intranet_knowledgebase Multiple cross-site scripting (XSS) vulnerabilities in Owl Intranet Knowledgebase 1.10 allow remote authenticated users to inject arbitrary web script or HTML via (1) the Search field to browse.php o… CWE-79
Cross-site Scripting
CVE-2013-4754 2024-11-21 10:56 2014-12-27 Show GitHub Exploit DB Packet Storm
291115 - claroline claroline Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.11.9 and earlier allow remote authenticated users to inject arbitrary web script or HTML via (1) the Search field in an inbox action… CWE-79
Cross-site Scripting
CVE-2013-4753 2024-11-21 10:56 2014-12-27 Show GitHub Exploit DB Packet Storm
291116 - h3c
hp
secbladefw
secpath1000fe
f1000-e_vpn_firewall
s5820_secblade_vpn_firewall_module
s7500e_secblade_vpn_firewall_module
s9500e_secblade_vpn_firewall_module
sr66_gigabit_firewall_module…
Unspecified vulnerability in HP and H3C VPN Firewall Module products SECPATH1000FE before 5.20.R3177 and SECBLADEFW before 5.20.R3177 allows remote attackers to cause a denial of service via unknown … NVD-CWE-noinfo
CVE-2013-4840 2024-11-21 10:56 2014-07-29 Show GitHub Exploit DB Packet Storm
291117 9.8 CRITICAL
Network
symantec web_gateway SNMPConfig.php in the management console in Symantec Web Gateway (SWG) before 5.2.1 allows remote attackers to execute arbitrary commands via unspecified vectors. NVD-CWE-noinfo
CVE-2013-5017 2024-11-21 10:56 2014-06-19 Show GitHub Exploit DB Packet Storm
291118 - ddsn cm3_acora_content_management_system DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, allows remote attackers to obtain sensitive information via a .. (dot dot) in the "l" parameter… CWE-200
Information Exposure
CVE-2013-4728 2024-11-21 10:56 2014-06-6 Show GitHub Exploit DB Packet Storm
291119 - ddsn cm3_acora_content_management_system DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, allows remote attackers to obtain sensitive information via a request to Admin/top.aspx. CWE-200
Information Exposure
CVE-2013-4727 2024-11-21 10:56 2014-06-6 Show GitHub Exploit DB Packet Storm
291120 - ddsn cm3_acora_content_management_system DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, does not set the secure flag for an unspecified cookie in an https session, which makes it easi… CWE-200
Information Exposure
CVE-2013-4725 2024-11-21 10:56 2014-06-6 Show GitHub Exploit DB Packet Storm