Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 24, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
218701 5.1 警告 マイクロソフト - 複数の Microsoft Windows 製品の Remote Desktop Protocol の実装における重要な情報を取得される脆弱性 CWE-310
暗号の問題
CVE-2014-0296 2014-06-12 17:49 2014-06-10 Show GitHub Exploit DB Packet Storm
218702 6.8 警告 マイクロソフト - Internet Explorer 8 CMarkup における解放済みメモリ使用の脆弱性 CWE-399
CWE-Other
CVE-2014-1770 2014-06-12 17:44 2014-05-21 Show GitHub Exploit DB Packet Storm
218703 9.3 危険 マイクロソフト - Microsoft Word 2007 および Office 互換機能パックにおける任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2014-2778 2014-06-12 17:30 2014-06-10 Show GitHub Exploit DB Packet Storm
218704 4.3 警告 マイクロソフト - Microsoft XML コアサービスにおけるクライアントシステム上のフルパス名およびフルパス名に埋め込まれたローカルユーザ名を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-1816 2014-06-12 17:25 2014-06-10 Show GitHub Exploit DB Packet Storm
218705 5 警告 マイクロソフト - 複数の Microsoft Windows 製品の TCP の実装におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2014-1811 2014-06-12 17:22 2014-06-10 Show GitHub Exploit DB Packet Storm
218706 4.3 警告 マイクロソフト - Microsoft Lync Server 2010 および 2013 の Web コンポーネントサーバにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-1823 2014-06-12 17:18 2014-06-10 Show GitHub Exploit DB Packet Storm
218707 9.3 危険 マイクロソフト - 複数の Microsoft 製品の GDI+ における任意のコードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2014-1818 2014-06-12 17:09 2014-06-10 Show GitHub Exploit DB Packet Storm
218708 9.3 危険 マイクロソフト - 複数の Microsoft 製品の Uniscribe の usp10.dll における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2014-1817 2014-06-12 17:08 2014-06-10 Show GitHub Exploit DB Packet Storm
218709 7.5 危険 マイクロソフト
アドビシステムズ
Google
- Adobe Flash Player および Adobe AIR における任意のコードを実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-0536 2014-06-12 16:01 2014-06-10 Show GitHub Exploit DB Packet Storm
218710 7.5 危険 マイクロソフト
アドビシステムズ
Google
- Adobe Flash Player および Adobe AIR におけるアクセス制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-0535 2014-06-12 16:01 2014-06-10 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 24, 2026, 4:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
296771 - yaniv_aran-shamir gigya Cross-site scripting (XSS) vulnerability in the Gigya - Social optimization module 6.x before 6.x-3.2 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. CWE-79
Cross-site Scripting
CVE-2012-2117 2024-11-21 10:38 2012-09-1 Show GitHub Exploit DB Packet Storm
296772 - commerceguys commerce_reorder Cross-site request forgery (CSRF) vulnerability in the Commerce Reorder module before 7.x-1.1 for Drupal allows remote attackers to hijack the authentication of arbitrary users for requests that add … CWE-352
 Origin Validation Error
CVE-2012-2116 2024-11-21 10:38 2012-09-1 Show GitHub Exploit DB Packet Storm
296773 - etalabs musl Stack-based buffer overflow in fprintf in musl before 0.8.8 and earlier allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string to… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2012-2114 2024-11-21 10:38 2012-09-1 Show GitHub Exploit DB Packet Storm
296774 - fusiondrupalthemes fusion Cross-site scripting (XSS) vulnerability in the fusion_core_preprocess_page function in fusion_core/template.php in the Fusion module before 6.x-1.13 for Drupal allows remote attackers to inject arbi… CWE-79
Cross-site Scripting
CVE-2012-2083 2024-11-21 10:38 2012-09-1 Show GitHub Exploit DB Packet Storm
296775 - asterisk
sangoma
open_source
asterisk
certified_asterisk
digiumphones
business_edition
Incomplete blacklist vulnerability in main/manager.c in Asterisk Open Source 1.8.x before 1.8.15.1 and 10.x before 10.7.1, Certified Asterisk 1.8.11 before 1.8.11-cert6, Asterisk Digiumphones 10.x.x-… NVD-CWE-Other
CVE-2012-2186 2024-11-21 10:38 2012-08-31 Show GitHub Exploit DB Packet Storm
296776 - emc cloud_tiering_appliance_virtual_edition
cloud_tiering_appliance
EMC Cloud Tiering Appliance (aka CTA, formerly FMA) 9.0 and earlier, and Cloud Tiering Appliance Virtual Edition (CTA/VE) 9.0 and earlier, allows remote attackers to obtain GUI administrative access … CWE-287
Improper Authentication
CVE-2012-2285 2024-11-21 10:38 2012-08-30 Show GitHub Exploit DB Packet Storm
296777 - mozilla firefox
thunderbird
seamonkey
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey before 2.12 allow remote attackers to cause a denial of service (memo… NVD-CWE-noinfo
CVE-2012-1971 2024-11-21 10:38 2012-08-29 Show GitHub Exploit DB Packet Storm
296778 - mozilla
suse
opensuse
redhat
canonical
firefox
seamonkey
thunderbird
thunderbird_esr
linux_enterprise_desktop
opensuse
linux_enterprise_server
linux_enterprise_software_development_kit
enterprise_linux_server
en…
Use-after-free vulnerability in the nsHTMLSelectElement::SubmitNamesValues function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x befor… CWE-416
 Use After Free
CVE-2012-1976 2024-11-21 10:38 2012-08-29 Show GitHub Exploit DB Packet Storm
296779 - mozilla
suse
opensuse
redhat
canonical
debian
firefox
seamonkey
thunderbird
thunderbird_esr
linux_enterprise_desktop
opensuse
linux_enterprise_server
linux_enterprise_software_development_kit
enterprise_linux_server
en…
Use-after-free vulnerability in the PresShell::CompleteMove function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and S… CWE-416
 Use After Free
CVE-2012-1975 2024-11-21 10:38 2012-08-29 Show GitHub Exploit DB Packet Storm
296780 - mozilla firefox
thunderbird
seamonkey
Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey before 2.12 do not prevent use of the Object.defineProperty method to shadow the location object (aka window.location), which makes… CWE-79
Cross-site Scripting
CVE-2012-1956 2024-11-21 10:38 2012-08-29 Show GitHub Exploit DB Packet Storm