Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":April 30, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
217701 6.8 警告 FFmpeg - FFmpeg の libavcodec/msrle.c の msrle_decode_frame 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-189
数値処理の問題
CVE-2014-2099 2014-03-4 15:55 2014-02-17 Show GitHub Exploit DB Packet Storm
217702 6.8 警告 FFmpeg - FFmpeg の libavcodec/wmalosslessdec.c におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2014-2098 2014-03-4 15:55 2014-02-7 Show GitHub Exploit DB Packet Storm
217703 6.8 警告 FFmpeg - FFmpeg の libavcodec/takdec.c の tak_decode_frame 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2014-2097 2014-03-4 15:54 2014-02-1 Show GitHub Exploit DB Packet Storm
217704 4.3 警告 MODX - MODX Revolution の manager/templates/default/header.tpl におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-2080 2014-03-4 15:45 2014-01-21 Show GitHub Exploit DB Packet Storm
217705 3.5 注意 CloudBees - CloudBees Jenkins の java/hudson/model/Cause.java におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-2067 2014-03-4 15:37 2014-02-14 Show GitHub Exploit DB Packet Storm
217706 4 警告 CloudBees - CloudBees Jenkins の CLI ジョブ作成におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2014-2059 2014-03-4 15:37 2014-02-14 Show GitHub Exploit DB Packet Storm
217707 4.3 警告 BuddyPress.org - WordPress 用 BuddyPress プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-1888 2014-03-4 15:13 2014-02-5 Show GitHub Exploit DB Packet Storm
217708 4.3 警告 OTRS プロジェクト - Open Ticket Request System におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-1695 2014-03-4 15:08 2014-02-25 Show GitHub Exploit DB Packet Storm
217709 4.3 警告 Open Web Analytics - Open Web Analytics のログインページにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-1456 2014-03-4 15:04 2014-02-1 Show GitHub Exploit DB Packet Storm
217710 7.5 危険 SimpleHRM - SimpleHRM の flexycms/modules/user/user_manager.php のログインページにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2013-2498 2014-03-4 14:58 2013-04-12 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 1, 2026, 4:54 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
295221 - jerome_schneider ameos_dragndropupload Unspecified vulnerability in the Drag Drop Mass Upload (ameos_dragndropupload) extension 2.0.2 and earlier for TYPO3 allows remote attackers to upload arbitrary files via unknown vectors. NVD-CWE-noinfo
CVE-2011-3980 2024-11-21 10:31 2011-10-4 Show GitHub Exploit DB Packet Storm
295222 - zikula zikula_application_framework Cross-site scripting (XSS) vulnerability in ztemp/view_compiled/Theme/theme_admin_setasdefault.php in the theme module in Zikula Application Framework 1.3.0 build 3168, 1.2.7, and probably other vers… CWE-79
Cross-site Scripting
CVE-2011-3979 2024-11-21 10:31 2011-10-4 Show GitHub Exploit DB Packet Storm
295223 - lightneasy lightneasy Multiple cross-site scripting (XSS) vulnerabilities in LightNEasy.php in LightNEasy 3.2.4 allow remote authenticated users to inject arbitrary web script or HTML via the (1) commentemail, (2) comment… CWE-79
Cross-site Scripting
CVE-2011-3978 2024-11-21 10:31 2011-10-4 Show GitHub Exploit DB Packet Storm
295224 - nomachine nx_server
nx_node
Unspecified vulnerability in nxconfigure.sh in NoMachine NX Node 3.x before 3.5.0-4 and NX Server 3.x before 3.5.0-5 allows local users to read arbitrary files via unknown vectors. NVD-CWE-noinfo
CVE-2011-3977 2024-11-21 10:31 2011-10-4 Show GitHub Exploit DB Packet Storm
295225 - ammsoft scriptftp Stack-based buffer overflow in AmmSoft ScriptFTP 3.3 allows remote FTP servers to execute arbitrary code via a long filename in a response to a LIST command, as demonstrated using (1) GETLIST or (2) … CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2011-3976 2024-11-21 10:31 2011-10-4 Show GitHub Exploit DB Packet Storm
295226 - google
htc
android
evo_3d
evo_4g
thunderbolt
A certain HTC update for Android 2.3.4 build GRJ22, when the Sense interface is used on the HTC EVO 3D, EVO 4G, ThunderBolt, and unspecified other devices, provides the HtcLoggers.apk application, wh… CWE-200
Information Exposure
CVE-2011-3975 2024-11-21 10:31 2011-10-4 Show GitHub Exploit DB Packet Storm
295227 - ffmpeg ffmpeg Integer signedness error in the decode_residual_inter function in cavsdec.c in libavcodec in FFmpeg before 0.7.4 and 0.8.x before 0.8.3 allows remote attackers to cause a denial of service (incorrect… CWE-189
Numeric Errors
CVE-2011-3974 2024-11-21 10:31 2011-10-3 Show GitHub Exploit DB Packet Storm
295228 - ffmpeg ffmpeg cavsdec.c in libavcodec in FFmpeg before 0.7.4 and 0.8.x before 0.8.3 allows remote attackers to cause a denial of service (incorrect write operation and application crash) via an invalid bitstream i… CWE-399
 Resource Management Errors
CVE-2011-3973 2024-11-21 10:31 2011-10-3 Show GitHub Exploit DB Packet Storm
295229 - mozilla firefox
seamonkey
Mozilla Firefox before 7.0 and SeaMonkey before 2.4 do not properly restrict availability of motion data events, which makes it easier for remote attackers to read keystrokes by leveraging JavaScript… CWE-264
Permissions, Privileges, and Access Controls
CVE-2011-3866 2024-11-21 10:31 2011-09-29 Show GitHub Exploit DB Packet Storm
295230 - ulyssesonline black-letterhead Cross-site scripting (XSS) vulnerability in the Black-LetterHead theme before 1.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php. CWE-79
Cross-site Scripting
CVE-2011-3865 2024-11-21 10:31 2011-09-28 Show GitHub Exploit DB Packet Storm