Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 6, 2026, 2 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
217121 6.5 警告 Postfix Admin Project - Postfix Admin の functions.inc.php の gen_show_status 関数における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2014-2655 2014-04-4 14:27 2014-02-19 Show GitHub Exploit DB Packet Storm
217122 4.3 警告 Splunk - Splunk の Splunk Web におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-2578 2014-04-4 12:15 2014-03-24 Show GitHub Exploit DB Packet Storm
217123 3.5 注意 OTRS プロジェクト - Open Ticket Request System におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-2553 2014-04-4 12:03 2014-04-1 Show GitHub Exploit DB Packet Storm
217124 6.8 警告 HitMyServer - WordPress 用 HMS Testimonials プラグインにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2013-4240 2014-04-4 11:19 2013-08-8 Show GitHub Exploit DB Packet Storm
217125 3.5 注意 IBM - IBM WebSphere Portal の IBM Connections 統合におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-0901 2014-04-3 18:29 2014-03-31 Show GitHub Exploit DB Packet Storm
217126 4.3 警告 IBM - IBM WebSphere Portal の WCM UI におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-0828 2014-04-3 18:29 2014-03-31 Show GitHub Exploit DB Packet Storm
217127 4.3 警告 シスコシステムズ - Cisco Security Manager の Web フレームワークにおける CRLF インジェクションの脆弱性 CWE-20
不適切な入力確認
CVE-2014-2138 2014-04-3 18:22 2014-04-1 Show GitHub Exploit DB Packet Storm
217128 4.3 警告 シスコシステムズ - Cisco Web セキュリティ アプライアンスの Web フレームワークにおける CRLF インジェクションの脆弱性 CWE-20
不適切な入力確認
CVE-2014-2137 2014-04-3 18:18 2014-04-1 Show GitHub Exploit DB Packet Storm
217129 4.3 警告 シスコシステムズ - Cisco Unity Connection の Web Inbox におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-2125 2014-04-3 18:17 2014-04-1 Show GitHub Exploit DB Packet Storm
217130 5 警告 Posh portal project - POSH の portal/scr_authentif.php の Remember Me 機能における重要な情報を取得される脆弱性 CWE-255
証明書・パスワード管理
CVE-2014-2212 2014-04-3 18:14 2014-02-20 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 6, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
292731 - wikidforum wikidforum Multiple cross-site scripting (XSS) vulnerabilities in Wikidforum 2.10 allow remote attackers to inject arbitrary web script or HTML via the (1) search field, or the (2) Author or (3) select_sort par… CWE-79
Cross-site Scripting
CVE-2012-2099 2024-11-21 10:38 2013-01-24 Show GitHub Exploit DB Packet Storm
292732 - sitecom wlm-2501 Multiple cross-site request forgery (CSRF) vulnerabilities in Sitecom WLM-2501 allow remote attackers to hijack the authentication of administrators for requests that modify settings for (1) Mac Filt… CWE-352
 Origin Validation Error
CVE-2012-1922 2024-11-21 10:38 2013-01-24 Show GitHub Exploit DB Packet Storm
292733 - linux linux_kernel The rds_ib_xmit function in net/rds/ib_send.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel 3.7.4 and earlier allows local users to cause a denial of service (BUG… NVD-CWE-noinfo
CVE-2012-2372 2024-11-21 10:38 2013-01-23 Show GitHub Exploit DB Packet Storm
292734 - linux
canonical
linux_kernel
ubuntu_linux
Buffer overflow in virt/kvm/irq_comm.c in the KVM subsystem in the Linux kernel before 3.2.24 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via vectors r… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2012-2137 2024-11-21 10:38 2013-01-23 Show GitHub Exploit DB Packet Storm
292735 - linux linux_kernel Buffer overflow in the macvtap device driver in the Linux kernel before 3.4.5, when running in certain configurations, allows privileged KVM guest users to cause a denial of service (crash) via a lon… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2012-2119 2024-11-21 10:38 2013-01-23 Show GitHub Exploit DB Packet Storm
292736 - emc avamar
avamar_plugin
EMC Avamar Client 4.x, 5.x, and 6.x on HP-UX and Mac OS X, and the EMC Avamar plugin 4.x, 5.x, and 6.x for Oracle, uses world-writable permissions for cache directories, which allows local users to g… CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-2291 2024-11-21 10:38 2013-01-22 Show GitHub Exploit DB Packet Storm
292737 - redhat
squirrelmail
enterprise_linux
squirrelmail
functions/imap_general.php in SquirrelMail, as used in Red Hat Enterprise Linux (RHEL) 4 and 5, does not properly handle 8-bit characters in passwords, which allows remote attackers to cause a denial… CWE-399
 Resource Management Errors
CVE-2012-2124 2024-11-21 10:38 2013-01-18 Show GitHub Exploit DB Packet Storm
292738 - pizzashack rssh Incomplete blacklist vulnerability in rssh before 2.3.4, when the rsync protocol is enabled, allows local users to bypass intended restricted shell access via the --rsh command line option. NVD-CWE-Other
CVE-2012-2252 2024-11-21 10:38 2013-01-11 Show GitHub Exploit DB Packet Storm
292739 - pizzashack rssh rssh 2.3.2, as used by Debian, Fedora, and others, when the rsync protocol is enabled, allows local users to bypass intended restricted shell access via a (1) "-e" or (2) "--" command line option. CWE-20
 Improper Input Validation 
CVE-2012-2251 2024-11-21 10:38 2013-01-11 Show GitHub Exploit DB Packet Storm
292740 - apache cxf Apache CXF 2.4.5 through 2.4.7, 2.5.1 through 2.5.3, and 2.6.x before 2.6.1, does not properly enforce child policies of a WS-SecurityPolicy 1.1 SupportingToken policy on the client side, which allow… CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-2378 2024-11-21 10:38 2013-01-5 Show GitHub Exploit DB Packet Storm