Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 10, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
217001 6.8 警告 OpenText - OpenText Exceed OnDemand における重要な情報を取得される脆弱性 CWE-287
不適切な認証
CVE-2013-6806 2014-05-20 17:55 2013-12-16 Show GitHub Exploit DB Packet Storm
217002 5 警告 OpenText - OpenText Exceed OnDemand における資格情報を取得される脆弱性 CWE-310
暗号の問題
CVE-2013-6805 2014-05-20 17:52 2013-12-16 Show GitHub Exploit DB Packet Storm
217003 6.5 警告 GitLab.org - GitLab で使用される Ruby 用 Grit gem における任意のコマンドを実行される脆弱性 CWE-Other
その他
CVE-2013-4489 2014-05-20 17:24 2013-11-4 Show GitHub Exploit DB Packet Storm
217004 5 警告 UnrealIRCd - UnrealIRCd におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2013-7384 2014-05-20 17:09 2013-11-23 Show GitHub Exploit DB Packet Storm
217005 5 警告 UnrealIRCd - UnrealIRCd におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2013-6413 2014-05-20 17:08 2013-11-23 Show GitHub Exploit DB Packet Storm
217006 6.5 警告 Joachim Noreiko - Drupal 用 Flag モジュールの includes/flag.export.inc の flag_import_form_validate 関数における任意の PHP コードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2014-3453 2014-05-20 16:38 2014-05-12 Show GitHub Exploit DB Packet Storm
217007 2.1 注意 Florian Weber - Drupal 用 Spaces モジュールの Spaces OG サブモジュールにおける重要な情報を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-4498 2014-05-20 16:37 2013-10-23 Show GitHub Exploit DB Packet Storm
217008 5 警告 katbailey - Drupal 用 Quick Tabs モジュールにおける重要な情報を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-4406 2014-05-20 16:36 2013-10-2 Show GitHub Exploit DB Packet Storm
217009 8.5 危険 Skybox Security - Skybox View Appliances with ISO における重要な情報を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-2084 2014-05-20 15:57 2014-05-12 Show GitHub Exploit DB Packet Storm
217010 5 警告 VICIDIAL Group - VICIDIAL ダイヤラーにおけるアクセス権を取得される脆弱性 CWE-255
証明書・パスワード管理
CVE-2013-7382 2014-05-20 15:02 2013-10-23 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 10, 2026, 4:58 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
292371 - mozilla
redhat
canonical
firefox
thunderbird_esr
thunderbird
seamonkey
enterprise_linux_server
enterprise_linux_workstation
ubuntu_linux
enterprise_linux_desktop
enterprise_linux_eus
Use-after-free vulnerability in the nsSMILAnimationController::DoSample function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 1… CWE-416
 Use After Free
CVE-2012-4181 2024-11-21 10:42 2012-10-11 Show GitHub Exploit DB Packet Storm
292372 - mozilla
redhat
canonical
suse
debian
firefox
thunderbird_esr
thunderbird
seamonkey
enterprise_linux_server
enterprise_linux_workstation
ubuntu_linux
enterprise_linux_desktop
enterprise_linux_eus
linux_enterpri…
Use-after-free vulnerability in the nsTextEditRules::WillInsert function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, a… CWE-416
 Use After Free
CVE-2012-4182 2024-11-21 10:42 2012-10-11 Show GitHub Exploit DB Packet Storm
292373 - mozilla
redhat
canonical
suse
debian
firefox
thunderbird_esr
thunderbird
seamonkey
enterprise_linux_server
enterprise_linux_workstation
ubuntu_linux
enterprise_linux_desktop
enterprise_linux_eus
linux_enterpri…
Heap-based buffer overflow in the nsHTMLEditor::IsPrevCharInNodeWhitespace function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x befor… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2012-4180 2024-11-21 10:42 2012-10-11 Show GitHub Exploit DB Packet Storm
292374 - mozilla
redhat
canonical
suse
debian
firefox
thunderbird_esr
thunderbird
seamonkey
enterprise_linux_server
enterprise_linux_workstation
ubuntu_linux
enterprise_linux_desktop
enterprise_linux_eus
linux_enterpri…
Use-after-free vulnerability in the nsHTMLCSSUtils::CreateCSSPropertyTxn function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before … CWE-416
 Use After Free
CVE-2012-4179 2024-11-21 10:42 2012-10-11 Show GitHub Exploit DB Packet Storm
292375 - dracut_project
fedoraproject
redhat
dracut
fedora
enterprise_linux_desktop
enterprise_linux_server
enterprise_linux_workstation
dracut.sh in dracut, as used in Red Hat Enterprise Linux 6, Fedora 16 and 17, and possibly other products, creates initramfs images with world-readable permissions, which might allow local users to o… CWE-276
Incorrect Default Permissions 
CVE-2012-4453 2024-11-21 10:42 2012-10-10 Show GitHub Exploit DB Packet Storm
292376 - apache axis2 Apache Axis2 allows remote attackers to forge messages and bypass authentication via an "XML Signature wrapping attack." CWE-287
Improper Authentication
CVE-2012-4418 2024-11-21 10:42 2012-10-10 Show GitHub Exploit DB Packet Storm
292377 7.5 HIGH
Network
cakefoundation cakephp The Xml class in CakePHP 2.1.x before 2.1.5 and 2.2.x before 2.2.1 allows remote attackers to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE)… CWE-611
XXE
CVE-2012-4399 2024-11-21 10:42 2012-10-10 Show GitHub Exploit DB Packet Storm
292378 - glpi-project glpi Multiple cross-site scripting (XSS) vulnerabilities in GLPI-PROJECT GLPI before 0.83.3 allow remote attackers to inject arbitrary web script or HTML via unknown vectors. CWE-79
Cross-site Scripting
CVE-2012-4003 2024-11-21 10:42 2012-10-10 Show GitHub Exploit DB Packet Storm
292379 - glpi-project glpi Cross-site request forgery (CSRF) vulnerability in GLPI-PROJECT GLPI before 0.83.3 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. CWE-352
 Origin Validation Error
CVE-2012-4002 2024-11-21 10:42 2012-10-10 Show GitHub Exploit DB Packet Storm
292380 - oracle mysql MySQL 5.0.88, and possibly other versions and platforms, allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX … CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-4452 2024-11-21 10:42 2012-10-10 Show GitHub Exploit DB Packet Storm