Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 28, 2026, 2:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
217031 10 危険 ソフォス - Sophos Cyberoam アプライアンスの CyberoamOS の Guest Login Portal における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2014-5503 2014-10-9 18:19 2014-09-15 Show GitHub Exploit DB Packet Storm
217032 9 危険 ソフォス - Sophos Cyberoam アプライアンスの CyberoamOS における任意のコマンドを挿入される脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2014-5502 2014-10-9 18:18 2014-09-15 Show GitHub Exploit DB Packet Storm
217033 9.3 危険 ソフォス - Sophos Cyberoam アプライアンスの CyberoamOS の診断サービスにおけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2014-5501 2014-10-9 18:18 2014-09-15 Show GitHub Exploit DB Packet Storm
217034 7.5 危険 PhpCompta - PHPCompta/NOALYSS の backup.php における任意のコマンドを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2014-6389 2014-10-9 17:54 2014-10-1 Show GitHub Exploit DB Packet Storm
217035 6.8 警告 Charles Cazabon - getmail の IMAP-over-SSL の実装において IMAP サーバになりすまされる脆弱性 CWE-310
暗号の問題
CVE-2014-7273 2014-10-9 17:48 2014-10-7 Show GitHub Exploit DB Packet Storm
217036 7.5 危険 アルバネットワークス株式会社 - Aruba コントローラ上で稼動する ArubaOS の管理インタフェースにおける認証を回避される脆弱性 CWE-noinfo
情報不足
CVE-2014-7299 2014-10-9 17:44 2014-10-7 Show GitHub Exploit DB Packet Storm
217037 4.3 警告 Debian - apt-cacher-ng の job.cc におけるクロスサイトスクリプティングの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2014-4510 2014-10-9 17:38 2014-06-21 Show GitHub Exploit DB Packet Storm
217038 3.5 注意 MediaWiki - MediaWiki の Special:Preferences および Special:UserLogin のページにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-7295 2014-10-9 17:29 2014-09-11 Show GitHub Exploit DB Packet Storm
217039 3.6 注意 David Golden - Perl 用 Capture::Tiny モジュールにおける任意のファイルに書き込まれる脆弱性 CWE-59
リンク解釈の問題
CVE-2014-1875 2014-10-9 16:51 2014-02-6 Show GitHub Exploit DB Packet Storm
217040 7.5 危険 Google - Google Chrome で使用される Google V8 におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2014-7967 2014-10-9 16:19 2014-10-7 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 28, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
297061 - pro-face pro-server_ex
wingp_pc_runtime
Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, allows remote attackers to cause a denial of service (out-of-bounds read operation) via … CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2012-3792 2024-11-21 10:41 2012-06-26 Show GitHub Exploit DB Packet Storm
297062 - cms-center simple_web_content_management_system Multiple SQL injection vulnerabilities in Simple Web Content Management System 1.1 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) item_delete.php, (2) item_statu… CWE-89
SQL Injection
CVE-2012-3791 2024-11-21 10:41 2012-06-22 Show GitHub Exploit DB Packet Storm
297063 - adiscon loganalyzer Cross-site scripting (XSS) vulnerability in index.php in Adiscon LogAnalyzer before 3.4.4 and 3.5.x before 3.5.5 allows remote attackers to inject arbitrary web script or HTML via the highlight param… CWE-79
Cross-site Scripting
CVE-2012-3790 2024-11-21 10:41 2012-06-21 Show GitHub Exploit DB Packet Storm
297064 - wordpress plugin_newsletter_plugin Directory traversal vulnerability in preview.php in the Plugin Newsletter plugin 1.5 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the data parameter. CWE-22
Path Traversal
CVE-2012-3588 2024-11-21 10:41 2012-06-20 Show GitHub Exploit DB Packet Storm
297065 - debian advanced_package_tool APT 0.7.x before 0.7.25 and 0.8.x before 0.8.16, when using the apt-key net-update to import keyrings, relies on GnuPG argument order and does not check GPG subkeys, which might allow remote attacker… CWE-20
 Improper Input Validation 
CVE-2012-3587 2024-11-21 10:41 2012-06-20 Show GitHub Exploit DB Packet Storm
297066 - digium asterisk chan_skinny.c in the Skinny (aka SCCP) channel driver in Asterisk Open Source 10.x before 10.5.1 allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon cr… NVD-CWE-Other
CVE-2012-3553 2024-11-21 10:41 2012-06-20 Show GitHub Exploit DB Packet Storm
297067 - wordpress fcchat_widget Unrestricted file upload vulnerability in html/Upload.php in the FCChat Widget plugin 2.2.13.1 and earlier for WordPress allows remote attackers to execute arbitrary code by uploading a file with a f… CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-3578 2024-11-21 10:41 2012-06-17 Show GitHub Exploit DB Packet Storm
297068 - nmedia member_conversation Unrestricted file upload vulnerability in doupload.php in the Nmedia Member Conversation plugin before 1.4 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an … CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-3577 2024-11-21 10:41 2012-06-17 Show GitHub Exploit DB Packet Storm
297069 - jquindlen wpstorecart Unrestricted file upload vulnerability in php/upload.php in the wpStoreCart plugin before 2.5.30 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable… CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-3576 2024-11-21 10:41 2012-06-16 Show GitHub Exploit DB Packet Storm
297070 - rbx_gallery rbx_gallery Unrestricted file upload vulnerability in uploader.php in the RBX Gallery plugin 2.1 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, … CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-3575 2024-11-21 10:41 2012-06-16 Show GitHub Exploit DB Packet Storm