Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 12, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
217241 4 警告 シスコシステムズ - Cisco Unified Communications Domain Manager の VOSS の Web フレームワークにおける重要な番号変換情報を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-3282 2014-06-2 14:24 2014-05-28 Show GitHub Exploit DB Packet Storm
217242 5 警告 シスコシステムズ - Cisco Unified Communications Domain Manager の VOSS の Web フレームワークにおけるアカウント名を列挙される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-3279 2014-06-2 14:22 2014-05-28 Show GitHub Exploit DB Packet Storm
217243 4 警告 シスコシステムズ - Cisco Unified Communications Domain Manager の VOSS における重要なユーザおよびグループ情報を取得される脆弱性 CWE-287
不適切な認証
CVE-2014-3277 2014-06-2 14:21 2014-05-28 Show GitHub Exploit DB Packet Storm
217244 4.3 警告 Apache Software Foundation - Apache HBase における双方向認証を無効にされる脆弱性 CWE-287
不適切な認証
CVE-2013-2193 2014-06-2 14:14 2013-07-4 Show GitHub Exploit DB Packet Storm
217245 5 警告 レッドハット - FreeIPA のデフォルトの LDAP ACI におけるクロスレルムの Kerberos Trust 鍵を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-0199 2014-06-2 14:05 2013-01-23 Show GitHub Exploit DB Packet Storm
217246 6.5 警告 Sharetronix - Sharetronix における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2014-3415 2014-06-2 11:48 2014-05-28 Show GitHub Exploit DB Packet Storm
217247 6.8 警告 Sharetronix - Sharetronix におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2014-3414 2014-06-2 11:47 2014-05-28 Show GitHub Exploit DB Packet Storm
217248 4.3 警告 SOSreport project - SOSreport における重要な情報を取得される脆弱性 CWE-255
証明書・パスワード管理
CVE-2014-0246 2014-06-2 11:33 2014-05-27 Show GitHub Exploit DB Packet Storm
217249 6.8 警告 IBM - IBM Notes で使用される Autonomy KeyView IDOL の .mdb パーサにおけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2012-6349 2014-05-30 18:19 2013-03-21 Show GitHub Exploit DB Packet Storm
217250 7.5 危険 日本電気
IBM
アップル
Mozilla Foundation
Google
フェンリル株式会社
レッドハット
- libpng における整数オーバーフローの脆弱性 CWE-189
数値処理の問題
CVE-2011-3026 2014-05-30 18:11 2012-02-15 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 13, 2026, 5:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
291831 - nero mediahome Nero MediaHome 4.5.8.0 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an HTTP header without a name. NVD-CWE-Other
CVE-2012-5877 2024-11-21 10:45 2014-05-30 Show GitHub Exploit DB Packet Storm
291832 - nero mediahome Multiple off-by-one errors in NMMediaServerService.dll in Nero MediaHome 4.5.8.0 and earlier allow remote attackers to cause a denial of service (crash) via a long string in the (1) request line or (… CWE-189
Numeric Errors
CVE-2012-5876 2024-11-21 10:45 2014-05-30 Show GitHub Exploit DB Packet Storm
291833 - paul_mattes x3270 x3270 before 3.3.12ga12 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-midd… CWE-310
Cryptographic Issues
CVE-2012-5662 2024-11-21 10:45 2014-05-27 Show GitHub Exploit DB Packet Storm
291834 - apache couchdb Apache CouchDB before 1.0.4, 1.1.x before 1.1.2, and 1.2.x before 1.2.1 allows remote attackers to execute arbitrary code via a JSONP callback, related to Adobe Flash. CWE-94
Code Injection
CVE-2012-5649 2024-11-21 10:45 2014-05-23 Show GitHub Exploit DB Packet Storm
291835 - typo3 typo3 The Backend History Module in TYPO3 4.5.x before 4.5.21, 4.6.x before 4.6.14, and 4.7.x before 4.7.6 does not properly restrict access, which allows remote authenticated editors to read the history o… CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-6146 2024-11-21 10:45 2014-05-20 Show GitHub Exploit DB Packet Storm
291836 - cisco ios_xe
asr_1001
asr_1002
asr_1002-x
asr_1002_fixed_router
asr_1004
asr_1006
asr_1013
asr_1023_router
Cisco ASR 1000 devices with software before 3.8S, when BDI routing is enabled, allow remote attackers to cause a denial of service (device reload) via crafted (1) broadcast or (2) multicast ICMP pack… CWE-20
 Improper Input Validation 
CVE-2012-5723 2024-11-21 10:45 2014-04-24 Show GitHub Exploit DB Packet Storm
291837 - roundup-tracker roundup Cross-site scripting (XSS) vulnerability in cgi/client.py in Roundup before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via the @action parameter to support/issue1. CWE-79
Cross-site Scripting
CVE-2012-6131 2024-11-21 10:45 2014-04-12 Show GitHub Exploit DB Packet Storm
291838 - roundup-tracker roundup Cross-site scripting (XSS) vulnerability in the history display in Roundup before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via a username, related to generating a link. CWE-79
Cross-site Scripting
CVE-2012-6130 2024-11-21 10:45 2014-04-12 Show GitHub Exploit DB Packet Storm
291839 - roundup-tracker roundup Cross-site scripting (XSS) vulnerability in Roundup before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via the otk parameter. CWE-79
Cross-site Scripting
CVE-2012-6132 2024-11-21 10:45 2014-04-11 Show GitHub Exploit DB Packet Storm
291840 - theforeman foreman Multiple SQL injection vulnerabilities in Foreman before 1.0.2 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) app/models/hostext/search.rb or (2) app/model… CWE-89
SQL Injection
CVE-2012-5648 2024-11-21 10:45 2014-04-4 Show GitHub Exploit DB Packet Storm