Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 9, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
217591 3.5 注意 オラクル - Oracle Supply Chain Products Suite の Oracle Agile PLM Framework における Security に関する脆弱性 CWE-noinfo
情報不足
CVE-2014-2467 2014-04-18 10:13 2014-04-15 Show GitHub Exploit DB Packet Storm
217592 2.1 注意 オラクル - Oracle Supply Chain Products Suite の Oracle Agile PLM Framework における Security に関する脆弱性 CWE-noinfo
情報不足
CVE-2014-2466 2014-04-18 10:12 2014-04-15 Show GitHub Exploit DB Packet Storm
217593 4.3 警告 オラクル - Oracle Supply Chain Products Suite の Oracle Agile PLM Framework における Security に関する脆弱性 CWE-noinfo
情報不足
CVE-2014-2465 2014-04-18 10:12 2014-04-15 Show GitHub Exploit DB Packet Storm
217594 3.5 注意 オラクル - Oracle Supply Chain Products Suite の Oracle Agile PLM Framework における Security に関する脆弱性 CWE-noinfo
情報不足
CVE-2014-2464 2014-04-18 10:12 2014-04-15 Show GitHub Exploit DB Packet Storm
217595 5 警告 オラクル - Oracle Supply Chain Products Suite の Oracle Transportation Management における Security に関する脆弱性 CWE-noinfo
情報不足
CVE-2014-2461 2014-04-18 10:11 2014-04-15 Show GitHub Exploit DB Packet Storm
217596 4 警告 オラクル - Oracle Supply Chain Products Suite の Oracle Transportation Management における CSV Management に関する脆弱性 CWE-noinfo
情報不足
CVE-2014-2460 2014-04-18 10:10 2014-04-15 Show GitHub Exploit DB Packet Storm
217597 3.7 注意 オラクル - Oracle Supply Chain Products Suite の Oracle Transportation Management における Security に関する脆弱性性 CWE-noinfo
情報不足
CVE-2014-2459 2014-04-18 10:10 2014-04-15 Show GitHub Exploit DB Packet Storm
217598 4.3 警告 オラクル - Oracle Supply Chain Products Suite の Oracle Agile Product Lifecycle における Install に関する脆弱性 CWE-noinfo
情報不足
CVE-2014-2458 2014-04-18 10:09 2014-04-15 Show GitHub Exploit DB Packet Storm
217599 4.3 警告 オラクル - Oracle Supply Chain Products Suite の Oracle Agile Product Lifecycle における Install に関する脆弱性 CWE-noinfo
情報不足
CVE-2014-2457 2014-04-18 10:09 2014-04-15 Show GitHub Exploit DB Packet Storm
217600 3.5 注意 オラクル - Oracle Supply Chain Products Suite の Oracle Agile PLM Framework における Security に関する脆弱性 CWE-noinfo
情報不足
CVE-2014-2445 2014-04-18 10:08 2014-04-15 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 9, 2026, 5:07 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
296301 - tomatosoft free_mp3_player TomatoSoft Free Mp3 Player 1.0 allows remote attackers to cause a denial of service (application crash) via a long string in an MP3 file, possibly a buffer overflow. CWE-20
 Improper Input Validation 
CVE-2011-5043 2024-11-21 10:33 2011-12-31 Show GitHub Exploit DB Packet Storm
296302 - gphemsley sasha Cross-site scripting (XSS) vulnerability in inc/lib/lib.base.php in SASHA 0.2.0 allows remote attackers to inject arbitrary web script or HTML via the instructors parameter. NOTE: the original discl… CWE-79
Cross-site Scripting
CVE-2011-5042 2024-11-21 10:33 2011-12-31 Show GitHub Exploit DB Packet Storm
296303 - pulsecms pulse_cms Multiple cross-site scripting (XSS) vulnerabilities in Pulse Pro CMS 1.7.2 allow remote attackers to inject arbitrary web script or HTML via the (1) d parameter in a blocks action and (2) post_id par… CWE-79
Cross-site Scripting
CVE-2011-5041 2024-11-21 10:33 2011-12-31 Show GitHub Exploit DB Packet Storm
296304 - infoproject biznis_heroj Multiple cross-site scripting (XSS) vulnerabilities in Infoproject Biznis Heroj allow remote attackers to inject arbitrary web script or HTML via the config parameter to (1) nalozi_naslov.php and (2)… CWE-79
Cross-site Scripting
CVE-2011-5040 2024-11-21 10:33 2011-12-31 Show GitHub Exploit DB Packet Storm
296305 - infoproject biznis_heroj Multiple SQL injection vulnerabilities in Infoproject Biznis Heroj allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters to login.php, (3) the filt… CWE-89
SQL Injection
CVE-2011-5039 2024-11-21 10:33 2011-12-31 Show GitHub Exploit DB Packet Storm
296306 - hitcode hitappoint SQL injection vulnerability in hitCode hitAppoint 4.5.17 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the username parameter to index.php. NOTE: the provenance … CWE-89
SQL Injection
CVE-2011-5038 2024-11-21 10:33 2011-12-31 Show GitHub Exploit DB Packet Storm
296307 - google v8 Google V8 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption)… CWE-20
 Improper Input Validation 
CVE-2011-5037 2024-11-21 10:33 2011-12-30 Show GitHub Exploit DB Packet Storm
296308 - rack_project rack Rack before 1.1.3, 1.2.x before 1.2.5, and 1.3.x before 1.3.6 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote atta… CWE-310
Cryptographic Issues
CVE-2011-5036 2024-11-21 10:33 2011-12-30 Show GitHub Exploit DB Packet Storm
296309 - oracle glassfish_server Oracle Glassfish 2.1.1, 3.0.1, and 3.1.1, as used in Communications Server 2.0, Sun Java System Application Server 8.1 and 8.2, and possibly other products, computes hash values for form parameters w… CWE-20
 Improper Input Validation 
CVE-2011-5035 2024-11-21 10:33 2011-12-30 Show GitHub Exploit DB Packet Storm
296310 - apache geronimo Apache Geronimo 2.2.1 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of s… CWE-20
 Improper Input Validation 
CVE-2011-5034 2024-11-21 10:33 2011-12-30 Show GitHub Exploit DB Packet Storm