Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 10, 2026, noon

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
217181 5 警告 The Foreman - Foreman における重要な情報を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-0192 2014-05-12 17:02 2014-04-24 Show GitHub Exploit DB Packet Storm
217182 6.8 警告 The Foreman - Foreman における Web セッションをハイジャックされる脆弱性 CWE-287
不適切な認証
CVE-2014-0090 2014-05-12 17:00 2014-02-26 Show GitHub Exploit DB Packet Storm
217183 4.3 警告 Slashes and Dots Sdn Bhd - Offiria におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-2689 2014-05-12 16:57 2014-05-7 Show GitHub Exploit DB Packet Storm
217184 3.3 注意 Novell
Travis Shirk
- Python 用 eyeD3 の tag.py における任意のファイルを変更される脆弱性 CWE-59
リンク解釈の問題
CVE-2014-1934 2014-05-12 16:34 2014-05-7 Show GitHub Exploit DB Packet Storm
217185 4.3 警告 Cristian Gafton - Pam 用 pam_userdb モジュールにおけるパスワードを推測される脆弱性 CWE-310
暗号の問題
CVE-2013-7041 2014-05-12 16:34 2013-12-4 Show GitHub Exploit DB Packet Storm
217186 4.9 警告 GNU Project - GNU Rush における任意のファイルを読まれる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-6889 2014-05-12 16:23 2013-12-29 Show GitHub Exploit DB Packet Storm
217187 2.1 注意 CloudBees - Jenkins 用 Subversion Plugin におけるパスワードおよび SSH 秘密鍵を取得される脆弱性 CWE-255
証明書・パスワード管理
CVE-2013-6372 2014-05-12 16:11 2013-11-20 Show GitHub Exploit DB Packet Storm
217188 4.9 警告 Fabrice Bellard
Canonical
- QEMU の hw/net/vmxnet3.c におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2013-4544 2014-05-12 15:51 2013-06-12 Show GitHub Exploit DB Packet Storm
217189 5.5 警告 Fedora Project
Zabbix
- Zabbix の Frontend における任意のユーザのメディアを変更される脆弱性 CWE-noinfo
情報不足
CVE-2014-1685 2014-05-12 12:23 2014-02-6 Show GitHub Exploit DB Packet Storm
217190 4 警告 Fedora Project
Zabbix
- Zabbix の API における任意のユーザになりすまされる脆弱性 CWE-287
不適切な認証
CVE-2014-1682 2014-05-12 12:19 2014-02-13 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 10, 2026, 4:58 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
292201 - microcart_project microcart Multiple cross-site scripting (XSS) vulnerabilities in Microcart 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO or (2) query string to _admin/index.php or (3)… CWE-79
Cross-site Scripting
CVE-2012-4241 2024-11-21 10:42 2014-08-13 Show GitHub Exploit DB Packet Storm
292202 - tinymce tinymce The bbcode plugin in TinyMCE 3.5.8 does not properly enforce the TinyMCE security policy for the (1) encoding directive and (2) valid_elements attribute, which allows attackers to conduct cross-site … CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-4230 2024-11-21 10:42 2014-04-25 Show GitHub Exploit DB Packet Storm
292203 - cisco nx-os Directory traversal vulnerability in filesys in Cisco NX-OS 6.1(2) and earlier allows local users to access arbitrary files via crafted command-line arguments during a delete action, aka Bug IDs CSCt… CWE-22
Path Traversal
CVE-2012-4135 2024-11-21 10:42 2013-12-21 Show GitHub Exploit DB Packet Storm
292204 - cisco nx-os Directory traversal vulnerability in tar in Cisco NX-OS allows local users to access arbitrary files via crafted command-line arguments, aka Bug IDs CSCty07157, CSCty07159, CSCty07162, and CSCty07164. CWE-22
Path Traversal
CVE-2012-4131 2024-11-21 10:42 2013-12-21 Show GitHub Exploit DB Packet Storm
292205 - cisco unified_computing_system The fabric-interconnect component in Cisco Unified Computing System (UCS) does not encrypt KVM virtual-media data, which allows man-in-the-middle attackers to obtain sensitive information by sniffing… CWE-310
Cryptographic Issues
CVE-2012-4115 2024-11-21 10:42 2013-10-21 Show GitHub Exploit DB Packet Storm
292206 - cisco unified_computing_system The fabric-interconnect component in Cisco Unified Computing System (UCS) does not properly verify X.509 certificates, which allows man-in-the-middle attackers to watch SSL KVM video-channel traffic … CWE-20
 Improper Input Validation 
CVE-2012-4117 2024-11-21 10:42 2013-10-19 Show GitHub Exploit DB Packet Storm
292207 - cisco unified_computing_system The fabric-interconnect component in Cisco Unified Computing System (UCS) does not encrypt KVM media traffic, which allows remote attackers to obtain sensitive information, and consequently complete … CWE-200
Information Exposure
CVE-2012-4116 2024-11-21 10:42 2013-10-19 Show GitHub Exploit DB Packet Storm
292208 - cisco unified_computing_system The fabric-interconnect KVM module in Cisco Unified Computing System (UCS) does not encrypt video data, which allows man-in-the-middle attackers to watch KVM display content by sniffing the network o… CWE-310
Cryptographic Issues
CVE-2012-4114 2024-11-21 10:42 2013-10-19 Show GitHub Exploit DB Packet Storm
292209 - cisco unified_computing_system The fabric-interconnect component in Cisco Unified Computing System (UCS) allows local users to gain privileges and read arbitrary files via crafted command parameters within the command-line interfa… CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-4113 2024-11-21 10:42 2013-10-19 Show GitHub Exploit DB Packet Storm
292210 - cisco unified_computing_system The Baseboard Management Controller (BMC) in Cisco Unified Computing System (UCS) allows local users to gain privileges and execute arbitrary commands via crafted command parameters within the comman… CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-4112 2024-11-21 10:42 2013-10-19 Show GitHub Exploit DB Packet Storm