Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 20, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
217291 4.3 警告 Mozilla Foundation - Bugzilla の jsonrpc.cgi の WebService/Server/JSONRPC.pm の JSONP エンドポイント内の response 関数におけるクロスサイトリクエストフォージェリ攻撃を実行される脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2014-1546 2014-08-15 15:33 2014-07-24 Show GitHub Exploit DB Packet Storm
217292 4.3 警告 Piwigo - Piwigo におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-1980 2014-08-15 13:35 2014-08-8 Show GitHub Exploit DB Packet Storm
217293 3.5 注意 Compfight - WordPress 用 Compfight プラグインの compfight-search.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-5202 2014-08-15 12:36 2014-07-3 Show GitHub Exploit DB Packet Storm
217294 6.5 警告 シスコシステムズ - Cisco Unified Communications Manager および Cisco Unified Presence Server の管理 Web インターフェースにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2014-3339 2014-08-15 12:04 2014-08-12 Show GitHub Exploit DB Packet Storm
217295 8.5 危険 シスコシステムズ - Cisco Unified Communications Manager の CTIManager モジュールにおける権限を取得される脆弱性 CWE-20
不適切な入力確認
CVE-2014-3338 2014-08-15 12:04 2014-08-11 Show GitHub Exploit DB Packet Storm
217296 6.8 警告 シスコシステムズ - Cisco Unified Communications Manager の SIP の実装におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2014-3337 2014-08-15 12:03 2014-08-11 Show GitHub Exploit DB Packet Storm
217297 4.4 警告 Puppet - Puppet Enterprise および Mcollective で使用される MCollective aes_security プラグインにおける許可されていない Mcollective 接続を確立される脆弱性 CWE-362
競合状態
CVE-2014-3251 2014-08-15 10:54 2014-07-15 Show GitHub Exploit DB Packet Storm
217298 7.5 危険 Google - Google Chrome におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2014-3167 2014-08-15 10:47 2014-08-12 Show GitHub Exploit DB Packet Storm
217299 7.5 危険 Google - Google Chrome で使用される Blink の Web Sockets の実装におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2014-3165 2014-08-15 10:46 2014-08-12 Show GitHub Exploit DB Packet Storm
217300 6.8 警告 マイクロソフト - Microsoft Windows Media Center の MCPlayer.dll における任意のコードを実行される脆弱性 CWE-399
リソース管理の問題
CVE-2014-4060 2014-08-15 10:33 2014-08-12 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 20, 2026, 4:14 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
291381 - moodle moodle Moodle 2.x through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 does not properly manage privileges for WebDAV repositories, which allows remote authenticated users to read,… CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-1836 2024-11-21 10:50 2013-03-26 Show GitHub Exploit DB Packet Storm
291382 - moodle moodle Moodle 2.x through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 allows remote authenticated administrators to obtain sensitive information from the external repositories of … CWE-200
Information Exposure
CVE-2013-1835 2024-11-21 10:50 2013-03-26 Show GitHub Exploit DB Packet Storm
291383 - moodle moodle notes/edit.php in Moodle 1.9.x through 1.9.19, 2.x through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 allows remote authenticated users to reassign notes via a modified (1… CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-1834 2024-11-21 10:50 2013-03-26 Show GitHub Exploit DB Packet Storm
291384 - moodle moodle Multiple cross-site scripting (XSS) vulnerabilities in the File Picker module in Moodle 2.x through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 allow remote authenticated u… CWE-79
Cross-site Scripting
CVE-2013-1833 2024-11-21 10:50 2013-03-26 Show GitHub Exploit DB Packet Storm
291385 - moodle moodle repository/webdav/lib.php in Moodle 2.x through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 includes the WebDAV password in the configuration form, which allows remote auth… CWE-200
Information Exposure
CVE-2013-1832 2024-11-21 10:50 2013-03-26 Show GitHub Exploit DB Packet Storm
291386 - moodle moodle lib/setuplib.php in Moodle through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals… CWE-200
Information Exposure
CVE-2013-1831 2024-11-21 10:50 2013-03-26 Show GitHub Exploit DB Packet Storm
291387 - fedoraproject
moodle
fedora
moodle
user/view.php in Moodle through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 does not enforce the forceloginforprofiles setting, which allows remote attackers to obtain sens… CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-1830 2024-11-21 10:50 2013-03-26 Show GitHub Exploit DB Packet Storm
291388 - moodle moodle calendar/managesubscriptions.php in Moodle 2.4.x before 2.4.2 does not consider capability requirements before displaying calendar subscriptions, which allows remote authenticated users to obtain pot… CWE-200
Information Exposure
CVE-2013-1829 2024-11-21 10:50 2013-03-26 Show GitHub Exploit DB Packet Storm
291389 - openstack
canonical
folsom
ubuntu_linux
OpenStack Keystone Folsom (2012.2) does not properly perform revocation checks for Keystone PKI tokens when done through a server, which allows remote attackers to bypass intended access restrictions… CWE-287
Improper Authentication
CVE-2013-1865 2024-11-21 10:50 2013-03-23 Show GitHub Exploit DB Packet Storm
291390 - openstack glance The v1 API in OpenStack Glance Essex (2012.1), Folsom (2012.2), and Grizzly, when using the single-tenant Swift or S3 store, reports the location field, which allows remote authenticated users to obt… CWE-200
Information Exposure
CVE-2013-1840 2024-11-21 10:50 2013-03-23 Show GitHub Exploit DB Packet Storm