Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 9, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
218711 6.8 警告 FFmpeg - FFmpeg の libavcodec/msrle.c の msrle_decode_frame 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-189
数値処理の問題
CVE-2014-2099 2014-03-4 15:55 2014-02-17 Show GitHub Exploit DB Packet Storm
218712 6.8 警告 FFmpeg - FFmpeg の libavcodec/wmalosslessdec.c におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2014-2098 2014-03-4 15:55 2014-02-7 Show GitHub Exploit DB Packet Storm
218713 6.8 警告 FFmpeg - FFmpeg の libavcodec/takdec.c の tak_decode_frame 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2014-2097 2014-03-4 15:54 2014-02-1 Show GitHub Exploit DB Packet Storm
218714 4.3 警告 MODX - MODX Revolution の manager/templates/default/header.tpl におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-2080 2014-03-4 15:45 2014-01-21 Show GitHub Exploit DB Packet Storm
218715 3.5 注意 CloudBees - CloudBees Jenkins の java/hudson/model/Cause.java におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-2067 2014-03-4 15:37 2014-02-14 Show GitHub Exploit DB Packet Storm
218716 4 警告 CloudBees - CloudBees Jenkins の CLI ジョブ作成におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2014-2059 2014-03-4 15:37 2014-02-14 Show GitHub Exploit DB Packet Storm
218717 4.3 警告 BuddyPress.org - WordPress 用 BuddyPress プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-1888 2014-03-4 15:13 2014-02-5 Show GitHub Exploit DB Packet Storm
218718 4.3 警告 OTRS プロジェクト - Open Ticket Request System におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-1695 2014-03-4 15:08 2014-02-25 Show GitHub Exploit DB Packet Storm
218719 4.3 警告 Open Web Analytics - Open Web Analytics のログインページにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-1456 2014-03-4 15:04 2014-02-1 Show GitHub Exploit DB Packet Storm
218720 7.5 危険 SimpleHRM - SimpleHRM の flexycms/modules/user/user_manager.php のログインページにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2013-2498 2014-03-4 14:58 2013-04-12 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 9, 2026, 5:07 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
295741 - wireshark
redhat
wireshark
enterprise_linux
Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 does not properly perform certain string conversions, which allows remote attackers to cause a denial of service (NULL pointer dereference and app… NVD-CWE-Other
CVE-2012-0042 2024-11-21 10:34 2012-04-11 Show GitHub Exploit DB Packet Storm
295742 - wireshark
redhat
wireshark
enterprise_linux
The dissect_packet function in epan/packet.c in Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) via a long packet in a ca… CWE-20
 Improper Input Validation 
CVE-2012-0041 2024-11-21 10:34 2012-04-11 Show GitHub Exploit DB Packet Storm
295743 - microsoft office
works_6-9_file_converter
works
Heap-based buffer overflow in the Office Works File Converter in Microsoft Office 2007 SP2, Works 9, and Works 6-9 File Converter allows remote attackers to execute arbitrary code via a crafted Works… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2012-0177 2024-11-21 10:34 2012-04-11 Show GitHub Exploit DB Packet Storm
295744 - microsoft internet_explorer Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "VML Style Remote Code E… CWE-94
Code Injection
CVE-2012-0172 2024-11-21 10:34 2012-04-11 Show GitHub Exploit DB Packet Storm
295745 - microsoft internet_explorer Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "SelectAll Remote Code E… CWE-94
Code Injection
CVE-2012-0171 2024-11-21 10:34 2012-04-11 Show GitHub Exploit DB Packet Storm
295746 - microsoft internet_explorer Microsoft Internet Explorer 6 and 7 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "OnReadyStateChange Remote C… CWE-94
Code Injection
CVE-2012-0170 2024-11-21 10:34 2012-04-11 Show GitHub Exploit DB Packet Storm
295747 - microsoft internet_explorer Microsoft Internet Explorer 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "JScript9 Remote Code Execution Vu… CWE-94
Code Injection
CVE-2012-0169 2024-11-21 10:34 2012-04-11 Show GitHub Exploit DB Packet Storm
295748 - microsoft internet_explorer Microsoft Internet Explorer 6 through 9 allows user-assisted remote attackers to execute arbitrary code via a crafted HTML document that is not properly handled during a "Print table of links" print … CWE-94
Code Injection
CVE-2012-0168 2024-11-21 10:34 2012-04-11 Show GitHub Exploit DB Packet Storm
295749 - microsoft .net_framework Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly validate function parameters, which allows remote attackers to execute arbitrary code via (1) a crafted XA… CWE-20
 Improper Input Validation 
CVE-2012-0163 2024-11-21 10:34 2012-04-11 Show GitHub Exploit DB Packet Storm
295750 - microsoft forefront_unified_access_gateway Microsoft Forefront Unified Access Gateway (UAG) 2010 SP1 and SP1 Update 1 does not properly configure the default web site, which allows remote attackers to obtain sensitive information via a crafte… CWE-16
Configuration
CVE-2012-0147 2024-11-21 10:34 2012-04-11 Show GitHub Exploit DB Packet Storm