Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 6, 2026, noon

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
218561 10 危険 AlienVault - AlienVault OSSIM の av-centerd SOAP サービスにおける任意のコマンドを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2014-5210 2014-08-22 11:37 2014-05-5 Show GitHub Exploit DB Packet Storm
218562 7.5 危険 AlienVault - AlienVault OSSIM の ossim-framework サービスにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2014-5159 2014-08-22 11:36 2014-03-31 Show GitHub Exploit DB Packet Storm
218563 10 危険 AlienVault - AlienVault OSSIM の ossim-framework サービスにおける任意のコマンドを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2014-5158 2014-08-22 11:36 2014-03-31 Show GitHub Exploit DB Packet Storm
218564 7.5 危険 Ruby on Rails project - Ruby on Rails の Active Record における強力なパラメータ保護メカニズムを回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-3514 2014-08-22 11:35 2014-08-18 Show GitHub Exploit DB Packet Storm
218565 4 警告 シスコシステムズ - Cisco WebEx MeetMeNow Server の PHP スクリプトにおけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2014-3340 2014-08-22 11:35 2014-08-20 Show GitHub Exploit DB Packet Storm
218566 4.3 警告 シスコシステムズ - Cisco ASR 5000 シリーズのソフトウェアの Packet Data Network Gateway の セッションマネージャコンポーネントにおけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2014-3331 2014-08-22 11:34 2014-08-19 Show GitHub Exploit DB Packet Storm
218567 6.5 警告 DELL EMC (旧 EMC Corporation) - EMC RSA Archer GRC Platform における権限を取得される脆弱性 CWE-noinfo
情報不足
CVE-2014-2517 2014-08-21 18:59 2014-08-19 Show GitHub Exploit DB Packet Storm
218568 5.4 警告 DELL EMC (旧 EMC Corporation) - EMC RSA Archer GRC Platform における任意のコードのダウンロードを誘発される脆弱性 CWE-noinfo
情報不足
CVE-2014-2505 2014-08-21 18:58 2014-08-19 Show GitHub Exploit DB Packet Storm
218569 6.8 警告 DELL EMC (旧 EMC Corporation) - EMC RSA Archer GRC Platform におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2014-0641 2014-08-21 18:57 2014-08-19 Show GitHub Exploit DB Packet Storm
218570 4 警告 DELL EMC (旧 EMC Corporation) - EMC RSA Archer GRC Platform におけるリソースへのアクセス制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-0640 2014-08-21 18:55 2014-08-19 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 6, 2026, 4:18 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
290711 5.5 MEDIUM
Local
check_mk_project check_mk Check_MK through 1.2.5i2p1 allows local users to read arbitrary files via a symlink attack to a file in /var/lib/check_mk_agent/job. CWE-59
Link Following
CVE-2014-0243 2024-11-21 11:01 2018-07-20 Show GitHub Exploit DB Packet Storm
290712 8.8 HIGH
Network
uclouvain
opensuse
openjpeg
opensuse
Heap-based buffer overflow in the JPEG2000 image tile decoder in OpenJPEG before 1.5.2 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impa… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2014-0158 2024-11-21 11:01 2018-04-11 Show GitHub Exploit DB Packet Storm
290713 5.4 MEDIUM
Network
emberjs ember.js Ember.js 1.0.x before 1.0.1, 1.1.x before 1.1.3, 1.2.x before 1.2.1, 1.3.x before 1.3.1, and 1.4.x before 1.4.0-beta.2 allows remote attackers to conduct cross-site scripting (XSS) attacks by leverag… CWE-79
Cross-site Scripting
CVE-2014-0014 2024-11-21 11:01 2018-02-16 Show GitHub Exploit DB Packet Storm
290714 5.4 MEDIUM
Network
emberjs ember.js Ember.js 1.0.x before 1.0.1, 1.1.x before 1.1.3, 1.2.x before 1.2.1, 1.3.x before 1.3.1, and 1.4.x before 1.4.0-beta.2 allows remote attackers to conduct cross-site scripting (XSS) attacks by leverag… CWE-79
Cross-site Scripting
CVE-2014-0013 2024-11-21 11:01 2018-02-16 Show GitHub Exploit DB Packet Storm
290715 8.8 HIGH
Network
redhat cloudforms_management_engine The check_privileges method in vmdb/app/controllers/application_controller.rb in ManageIQ, as used in Red Hat CloudForms Management Engine (CFME), allows remote authenticated users to bypass authoriz… CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-0087 2024-11-21 11:01 2018-01-12 Show GitHub Exploit DB Packet Storm
290716 9.8 CRITICAL
Network
hawt
redhat
hawtio
jboss_fuse
The admin terminal in Hawt.io does not require authentication, which allows remote attackers to execute arbitrary commands via the k parameter. CWE-287
Improper Authentication
CVE-2014-0121 2024-11-21 11:01 2017-12-30 Show GitHub Exploit DB Packet Storm
290717 8.8 HIGH
Network
hawt
redhat
hawtio
jboss_fuse
Cross-site request forgery (CSRF) vulnerability in the admin terminal in Hawt.io allows remote attackers to hijack the authentication of arbitrary users for requests that run commands on the Karaf se… CWE-352
 Origin Validation Error
CVE-2014-0120 2024-11-21 11:01 2017-12-30 Show GitHub Exploit DB Packet Storm
290718 5.5 MEDIUM
Local
apache karaf Apache Karaf before 4.0.10 enables a shutdown port on the loopback interface, which allows local users to cause a denial of service (shutdown) by sending a shutdown command to all listening high port… CWE-20
 Improper Input Validation 
CVE-2014-0219 2024-11-21 11:01 2017-11-16 Show GitHub Exploit DB Packet Storm
290719 9.8 CRITICAL
Network
apache cordova_in-app-browser
cordova
The CDVInAppBrowser class in the Apache Cordova In-App-Browser standalone plugin (org.apache.cordova.inappbrowser) before 0.3.2 for iOS and the In-App-Browser plugin for iOS from Cordova 2.6.0 throug… CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-0073 2024-11-21 11:01 2017-10-31 Show GitHub Exploit DB Packet Storm
290720 7.5 HIGH
Network
apache cordova_file_transfer
cordova
ios/CDVFileTransfer.m in the Apache Cordova File-Transfer standalone plugin (org.apache.cordova.file-transfer) before 0.4.2 for iOS and the File-Transfer plugin for iOS from Cordova 2.4.0 through 2.9… CWE-20
 Improper Input Validation 
CVE-2014-0072 2024-11-21 11:01 2017-10-31 Show GitHub Exploit DB Packet Storm