Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 10, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
217311 5 警告 SAP - SAP NetWeaver の Software Lifecycle Manager の Java Server Page における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2014-3129 2014-05-2 15:18 2014-04-28 Show GitHub Exploit DB Packet Storm
217312 3.5 注意 Eugene Pankov - Eugene Pankov Ajenti の plugins/main/content/js/ajenti.coffee におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-2260 2014-05-2 15:15 2014-01-16 Show GitHub Exploit DB Packet Storm
217313 7.2 危険 Super Project - Super の super.c における権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-0470 2014-05-2 15:10 2014-04-28 Show GitHub Exploit DB Packet Storm
217314 9 危険 フォーティネット - FortiGuard FortiAuthenticator における権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-6990 2014-05-2 15:07 2013-12-15 Show GitHub Exploit DB Packet Storm
217315 6.5 警告 ブルーコートシステムズ - Blue Coat Content Analysis System のコマンドラインインターフェースにおける任意のコマンドを実行される脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2014-2565 2014-05-2 15:05 2014-04-4 Show GitHub Exploit DB Packet Storm
217316 5 警告 レッドハット - Red Hat Enterprise MRG で使用される Cumin における重要な情報を取得される脆弱性 CWE-310
暗号の問題
CVE-2013-6445 2014-05-2 14:55 2013-11-4 Show GitHub Exploit DB Packet Storm
217317 9.3 危険 Debian
Canonical
- dpkg の解凍機能におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2014-0471 2014-05-2 14:54 2014-04-28 Show GitHub Exploit DB Packet Storm
217318 5 警告 TIBCO Software - 複数の TIBCO 製品における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2014-2545 2014-05-2 14:52 2014-04-29 Show GitHub Exploit DB Packet Storm
217319 7.5 危険 Igor Sysoev - nginx の ngx_http_spdy_module モジュールの SPDY の実装における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2014-0088 2014-05-2 14:42 2014-03-4 Show GitHub Exploit DB Packet Storm
217320 4.3 警告 MediaWiki - MediaWiki の includes/actions/InfoAction.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-2853 2014-05-2 12:01 2014-03-29 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 10, 2026, 4:58 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
291981 - inclind custom_pub Cross-site scripting (XSS) vulnerability in the Custom Publishing Options module 6.x-1.x before 6.x-1.4 for Drupal allows remote authenticated users with the "administer nodes" permission to inject a… CWE-79
Cross-site Scripting
CVE-2012-4496 2024-11-21 10:43 2012-11-1 Show GitHub Exploit DB Packet Storm
291982 - mime_mail_module_project mimemail The Mime Mail module 6.x-1.x before 6.x-1.1 for Drupal does not properly restrict access to files outside Drupal's publish files directory, which allows remote authenticated users to send arbitrary f… CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-4495 2024-11-21 10:43 2012-11-1 Show GitHub Exploit DB Packet Storm
291983 - niif shibb_auth The Shibboleth authentication module 7.x-4.0 for Drupal does not properly check the active status of users, which allows remote blocked users to access bypass intended access restrictions and possibl… CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-4494 2024-11-21 10:43 2012-11-1 Show GitHub Exploit DB Packet Storm
291984 - isaac_sukin shorten Multiple cross-site scripting (XSS) vulnerabilities in the Shorten URLs module 6.x-1.x before 6.x-1.13 and 7.x-1.x before 7.x-1.2 for Drupal allow remote authenticated users with certain permissions … CWE-79
Cross-site Scripting
CVE-2012-4492 2024-11-21 10:43 2012-11-1 Show GitHub Exploit DB Packet Storm
291985 - tomatocart tomatocart TomatoCart 1.1.7, when the PayPal Express Checkout module is enabled in sandbox mode, allows remote authenticated users to bypass intended payment requirements by modifying a certain redirection URL. CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-4934 2024-11-21 10:43 2012-10-31 Show GitHub Exploit DB Packet Storm
291986 - emc avamar EMC Avamar Client for VMware 6.1 stores the cleartext server root password on the proxy client, which might allow remote attackers to obtain sensitive information by leveraging "network access" to th… CWE-255
Credentials Management
CVE-2012-4610 2024-11-21 10:43 2012-10-31 Show GitHub Exploit DB Packet Storm
291987 - laurent_destailleur awstats Unspecified vulnerability in awredir.pl in AWStats before 7.1 has unknown impact and attack vectors. CWE-79
Cross-site Scripting
CVE-2012-4547 2024-11-21 10:43 2012-10-31 Show GitHub Exploit DB Packet Storm
291988 - cisco adaptive_security_appliance_software
5500_series_adaptive_security_appliance
7600_router
catalyst_6500
catalyst_6503-e
catalyst_6504-e
catalyst_6506-e
catalyst_6509-e
catalyst…
The DCERPC inspection engine on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with software 8.3 before 8.3(2… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2012-4663 2024-11-21 10:43 2012-10-30 Show GitHub Exploit DB Packet Storm
291989 - wftpserver wing_ftp_server Wing FTP Server before 4.1.1 allows remote authenticated users to cause a denial of service (daemon crash) via two zip commands. CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2012-4729 2024-11-21 10:43 2012-10-26 Show GitHub Exploit DB Packet Storm
291990 - apache
citrix
cloudstack Citrix Cloud.com CloudStack, and Apache CloudStack pre-release, allows remote attackers to make arbitrary API calls by leveraging the system user account, as demonstrated by API calls to delete VMs. CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-4501 2024-11-21 10:43 2012-10-26 Show GitHub Exploit DB Packet Storm