Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 15, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
217481 4.3 警告 Ipswitch, Inc. - Ipswitch IMail Server の Web クライアントインターフェースにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-3878 2014-06-6 16:30 2014-06-4 Show GitHub Exploit DB Packet Storm
217482 7.5 危険 Stephen Adkins - Perl 用の App::Context モジュールにおける任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2012-6141 2014-06-6 16:19 2012-12-6 Show GitHub Exploit DB Packet Storm
217483 3.5 注意 Jo Hasenau - TYPO3 用 Grid Elements エクステンションのレイアウトウィザードにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-3949 2014-06-6 15:14 2014-05-27 Show GitHub Exploit DB Packet Storm
217484 4.3 警告 Alex Kellner - TYPO3 用 powermail エクステンションの backend モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-3948 2014-06-6 15:13 2014-05-22 Show GitHub Exploit DB Packet Storm
217485 7.5 危険 Ingy dot Net - Perl 用 Spoon モジュールの Session::Cookie における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2012-6143 2014-06-6 14:51 2012-12-6 Show GitHub Exploit DB Packet Storm
217486 7.5 危険 Jochen Wiedmann - Perl 用 HTML::EP モジュールの Session::Cookie における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2012-6142 2014-06-6 14:50 2012-12-6 Show GitHub Exploit DB Packet Storm
217487 4 警告 ownCloud - ownCloud Server における任意のプレビュー画像にアクセスされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-3963 2014-06-6 14:11 2014-01-22 Show GitHub Exploit DB Packet Storm
217488 4 警告 ownCloud - ownCloud Server における他のユーザのファイル名を読まれる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-3838 2014-06-6 14:11 2014-04-29 Show GitHub Exploit DB Packet Storm
217489 4 警告 ownCloud - ownCloud Server の document アプリケーションにおける共有ファイルを列挙される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-3837 2014-06-6 14:10 2014-04-29 Show GitHub Exploit DB Packet Storm
217490 6.8 警告 ownCloud - ownCloud Server におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2014-3836 2014-06-6 14:10 2014-04-29 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 15, 2026, 4:28 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
291641 - owncloud owncloud Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 4.0.12 and 4.5.x before 4.5.7 allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) site_… CWE-79
Cross-site Scripting
CVE-2013-0297 2024-11-21 10:47 2014-03-15 Show GitHub Exploit DB Packet Storm
291642 - apache tomcat Apache Tomcat 7.x uses world-readable permissions for the log directory and its files, which might allow local users to obtain sensitive information by reading a file. NOTE: One Tomcat distributor ha… CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-0346 2024-11-21 10:47 2014-02-15 Show GitHub Exploit DB Packet Storm
291643 - elgg elgg Cross-site scripting (XSS) vulnerability in the Twitter widget in Elgg before 1.7.17 and 1.8.x before 1.8.13 allows remote attackers to inject arbitrary web script or HTML via the params[twitter_user… CWE-79
Cross-site Scripting
CVE-2013-0234 2024-11-21 10:47 2014-02-3 Show GitHub Exploit DB Packet Storm
291644 - apache ofbiz Multiple cross-site scripting (XSS) vulnerabilities in widget/screen/ModelScreenWidget.java in Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.05, 11.04.01, and possibly 09.04.x all… CWE-79
Cross-site Scripting
CVE-2013-0177 2024-11-21 10:47 2014-01-31 Show GitHub Exploit DB Packet Storm
291645 - ibm java Unspecified vulnerability in IBM Java SDK 7 before SR4-FP1, 6 before SR13-FP1, 5.0 before SR16-FP1, and 1.4.2 before SR13-FP16 has unknown impact and attack vectors related to Class Libraries. NVD-CWE-noinfo
CVE-2013-0485 2024-11-21 10:47 2014-01-22 Show GitHub Exploit DB Packet Storm
291646 - libexpat_project
python
apple
libexpat
python
ipados
iphone_os
macos
watchos
tvos
expat 2.1.0 and earlier does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function, which allows remote attackers to cause a denial of serv… CWE-611
XXE
CVE-2013-0340 2024-11-21 10:47 2014-01-22 Show GitHub Exploit DB Packet Storm
291647 - xmlsoft
canonical
debian
suse
libxml2
ubuntu_linux
debian_linux
linux_enterprise_server
libxml2 through 2.9.1 does not properly handle external entities expansion unless an application developer uses the xmlSAX2ResolveEntity or xmlSetExternalEntityLoader function, which allows remote at… CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-0339 2024-11-21 10:47 2014-01-22 Show GitHub Exploit DB Packet Storm
291648 - drupal drupal Cross-site scripting (XSS) vulnerability in Drupal 6.x before 6.28 and 7.x before 7.19, when running with older versions of jQuery that are vulnerable to CVE-2011-4969, allows remote attackers to inj… CWE-79
Cross-site Scripting
CVE-2013-0244 2024-11-21 10:47 2014-01-20 Show GitHub Exploit DB Packet Storm
291649 - memcached memcached The process_bin_delete function in memcached.c in memcached 1.4.4 and other versions before 1.4.17, when running in verbose mode, allows remote attackers to cause a denial of service (segmentation fa… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2013-0179 2024-11-21 10:47 2014-01-14 Show GitHub Exploit DB Packet Storm
291650 - open_source_development_team
fedoraproject
opensuse
gentoo
acme
sthttpd
fedora
opensuse
linux
thttpd
thttpd.c in sthttpd before 2.26.4-r2 and thttpd 2.25b use world-readable permissions for /var/log/thttpd.log, which allows local users to obtain sensitive information by reading the file. CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-0348 2024-11-21 10:47 2013-12-14 Show GitHub Exploit DB Packet Storm