Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 6, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
218581 6.8 警告 SpringSource - Spring Framework の Spring MVC における任意のファイルを読まれる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-7315 2014-01-27 15:39 2013-08-22 Show GitHub Exploit DB Packet Storm
218582 10 危険 アドビシステムズ - Adobe Digital Editions における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2014-0494 2014-01-27 15:11 2014-01-22 Show GitHub Exploit DB Packet Storm
218583 6.8 警告 シスコシステムズ - Cisco Video Surveillance Operations Manager における重要な情報を取得される脆弱性 CWE-287
不適切な認証
CVE-2014-0674 2014-01-27 14:48 2014-01-24 Show GitHub Exploit DB Packet Storm
218584 7.5 危険 レッドハット - Red Hat Certificate System および Dogtag Certificate System の Token Processing System におけるフォーマットストリングの脆弱性 CWE-134
書式文字列の問題
CVE-2013-1886 2014-01-27 14:48 2013-05-22 Show GitHub Exploit DB Packet Storm
218585 4.3 警告 レッドハット - Red Hat Certificate System および Dogtag Certificate System の Token Processing System におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-1885 2014-01-27 14:47 2013-05-22 Show GitHub Exploit DB Packet Storm
218586 6.8 警告 日本電気 - 複数の NEC 製のルータの OSPF の実装におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2013-7314 2014-01-27 14:39 2013-08-1 Show GitHub Exploit DB Packet Storm
218587 5.4 警告 Enterasys Networks - Enterasys のスイッチおよびルータの OSPF の実装におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2013-7312 2014-01-27 14:33 2013-08-1 Show GitHub Exploit DB Packet Storm
218588 5.4 警告 ヤマハ - Yamaha ルータの OSPF の実装におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2013-7310 2014-01-27 14:21 2013-08-1 Show GitHub Exploit DB Packet Storm
218589 5.4 警告 D-Link Systems, Inc. - D-Link DES-3810-28 スイッチのファームウェアの OSPF の実装におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2013-7308 2014-01-27 14:13 2013-08-1 Show GitHub Exploit DB Packet Storm
218590 5.4 警告 ブロケード コミュニケーションズ システムズ株式会社 - Brocade Vyatta vRouter のソフトウェアの OSPF の実装におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2013-7307 2014-01-27 14:09 2013-08-1 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 6, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
292551 - john_franklin advertisement Cross-site scripting (XSS) vulnerability in the Advertisement module 6.x-2.x before 6.x-2.3 for Drupal, when debug mode is enabled, allows remote attackers to inject arbitrary web script or HTML via … CWE-79
Cross-site Scripting
CVE-2012-2703 2024-11-21 10:39 2012-06-27 Show GitHub Exploit DB Packet Storm
292552 - tony_freixas ubercart_product_keys The Ubercart Product Keys module 6.x-1.x before 6.x-1.1 for Drupal does not properly check access for product keys, which allows remote attackers to read all unassigned product keys via certain condi… CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-2702 2024-11-21 10:39 2012-06-27 Show GitHub Exploit DB Packet Storm
292553 - rubyonrails ruby_on_rails
rails
The Active Record component in Ruby on Rails before 3.0.14, 3.1.x before 3.1.6, and 3.2.x before 3.2.6 does not properly implement the passing of request data to a where method in an ActiveRecord cla… CWE-89
SQL Injection
CVE-2012-2695 2024-11-21 10:39 2012-06-22 Show GitHub Exploit DB Packet Storm
292554 - rubyonrails ruby_on_rails
rails
actionpack/lib/action_dispatch/http/request.rb in Ruby on Rails before 3.0.14, 3.1.x before 3.1.6, and 3.2.x before 3.2.6 does not properly consider differences in parameter handling between the Acti… CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-2694 2024-11-21 10:39 2012-06-22 Show GitHub Exploit DB Packet Storm
292555 - rubyonrails ruby_on_rails
rails
The Active Record component in Ruby on Rails 3.0.x before 3.0.13, 3.1.x before 3.1.5, and 3.2.x before 3.2.4 does not properly implement the passing of request data to a where method in an ActiveReco… CWE-89
SQL Injection
CVE-2012-2661 2024-11-21 10:39 2012-06-22 Show GitHub Exploit DB Packet Storm
292556 - rubyonrails ruby_on_rails
rails
actionpack/lib/action_dispatch/http/request.rb in Ruby on Rails before 3.0.13, 3.1.x before 3.1.5, and 3.2.x before 3.2.4 does not properly consider differences in parameter handling between the Acti… CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-2660 2024-11-21 10:39 2012-06-22 Show GitHub Exploit DB Packet Storm
292557 - drupal-id counter_module SQL injection vulnerability in the Counter module for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors related to "recording visits." CWE-89
SQL Injection
CVE-2012-2718 2024-11-21 10:39 2012-06-22 Show GitHub Exploit DB Packet Storm
292558 - david_stosik comment_moderation Cross-site request forgery (CSRF) vulnerability in the Comment Moderation module 6.x-1.x before 6.x-1.1 for Drupal allows remote attackers to hijack the authentication of administrators for requests … CWE-352
 Origin Validation Error
CVE-2012-2716 2024-11-21 10:39 2012-06-22 Show GitHub Exploit DB Packet Storm
292559 - openstack compute
essex
diablo
The (1) EC2 and (2) OS APIs in OpenStack Compute (Nova) Folsom (2012.2), Essex (2012.1), and Diablo (2011.3) do not properly check the protocol when security groups are created and the network protoc… CWE-20
 Improper Input Validation 
CVE-2012-2654 2024-11-21 10:39 2012-06-22 Show GitHub Exploit DB Packet Storm
292560 - w1.fi hostapd hostapd 0.7.3, and possibly other versions before 1.0, uses 0644 permissions for /etc/hostapd/hostapd.conf, which might allow local users to obtain sensitive information such as credentials. CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-2389 2024-11-21 10:39 2012-06-22 Show GitHub Exploit DB Packet Storm