Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 28, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
218981 3.5 注意 Jo Hasenau - TYPO3 用 Grid Elements エクステンションのレイアウトウィザードにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-3949 2014-06-6 15:14 2014-05-27 Show GitHub Exploit DB Packet Storm
218982 4.3 警告 Alex Kellner - TYPO3 用 powermail エクステンションの backend モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-3948 2014-06-6 15:13 2014-05-22 Show GitHub Exploit DB Packet Storm
218983 7.5 危険 Ingy dot Net - Perl 用 Spoon モジュールの Session::Cookie における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2012-6143 2014-06-6 14:51 2012-12-6 Show GitHub Exploit DB Packet Storm
218984 7.5 危険 Jochen Wiedmann - Perl 用 HTML::EP モジュールの Session::Cookie における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2012-6142 2014-06-6 14:50 2012-12-6 Show GitHub Exploit DB Packet Storm
218985 4 警告 ownCloud - ownCloud Server における任意のプレビュー画像にアクセスされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-3963 2014-06-6 14:11 2014-01-22 Show GitHub Exploit DB Packet Storm
218986 4 警告 ownCloud - ownCloud Server における他のユーザのファイル名を読まれる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-3838 2014-06-6 14:11 2014-04-29 Show GitHub Exploit DB Packet Storm
218987 4 警告 ownCloud - ownCloud Server の document アプリケーションにおける共有ファイルを列挙される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-3837 2014-06-6 14:10 2014-04-29 Show GitHub Exploit DB Packet Storm
218988 6.8 警告 ownCloud - ownCloud Server におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2014-3836 2014-06-6 14:10 2014-04-29 Show GitHub Exploit DB Packet Storm
218989 7.5 危険 ownCloud - ownCloud Server における LDAP インジェクション攻撃を実行される脆弱性 CWE-94
コード・インジェクション
CVE-2014-2051 2014-06-6 14:09 2014-03-3 Show GitHub Exploit DB Packet Storm
218990 4 警告 ownCloud - ownCloud Server における任意のカレンダーを読まれる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-0304 2014-06-6 14:08 2013-02-20 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 28, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
291151 - jpchacha chasys_draw_ies Stack-based buffer overflow in the ReadFile function in flt_BMP.dll in Chasys Draw IES before 4.11.02 allows remote attackers to execute arbitrary code via crafted biPlanes and biBitCount fields in a… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2013-3928 2024-11-21 10:54 2014-03-12 Show GitHub Exploit DB Packet Storm
291152 - novell zenworks_configuration_management Directory traversal vulnerability in the PreBoot service in Novell ZENworks Configuration Management (ZCM) 11.2 allows remote attackers to read arbitrary files via a .. (dot dot) in a preboot update … CWE-22
Path Traversal
CVE-2013-3706 2024-11-21 10:54 2014-03-6 Show GitHub Exploit DB Packet Storm
291153 - ibm websphere_mq Directory traversal vulnerability in WMQ Telemetry in IBM WebSphere MQ 7.5 before 7.5.0.3 allows remote attackers to read arbitrary files via a crafted URI. CWE-22
Path Traversal
CVE-2013-4054 2024-11-21 10:54 2014-03-2 Show GitHub Exploit DB Packet Storm
291154 - suse studio_onsite
studio_extension_for_system_z
SUSE Studio Onsite 1.3.x before 1.3.6 and SUSE Studio Extension for System z 1.3 uses "static" secret tokens, which has unspecified impact and vectors. CWE-310
Cryptographic Issues
CVE-2013-3712 2024-11-21 10:54 2014-02-27 Show GitHub Exploit DB Packet Storm
291155 - ibm sametime The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to conduct clickjacking attacks via unspecified vectors. CWE-20
 Improper Input Validation 
CVE-2013-3988 2024-11-21 10:54 2014-02-14 Show GitHub Exploit DB Packet Storm
291156 - ibm sametime The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 does not validate URLs in Cookie headers before using them in redirects, which has unspecified impact and remote attac… CWE-20
 Improper Input Validation 
CVE-2013-3983 2024-11-21 10:54 2014-02-14 Show GitHub Exploit DB Packet Storm
291157 - ibm sametime The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 does not send the appropriate HTTP response headers to prevent unwanted caching by a web browser, which allows remote … CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-3978 2024-11-21 10:54 2014-02-14 Show GitHub Exploit DB Packet Storm
291158 - maxxmarketing joomshopping Cross-site scripting (XSS) vulnerability in the JoomShopping (com_joomshopping) component before 4.3.1 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the user_name par… CWE-79
Cross-site Scripting
CVE-2013-3933 2024-11-21 10:54 2014-02-12 Show GitHub Exploit DB Packet Storm
291159 - xaraya xaraya Multiple cross-site scripting (XSS) vulnerabilities in Xaraya 2.4.0-b1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) id, (2) interface, (3) name, or (4) tabmod… CWE-79
Cross-site Scripting
CVE-2013-3639 2024-11-21 10:54 2014-02-6 Show GitHub Exploit DB Packet Storm
291160 - ibm spss_collaboration_and_deployment_services The server in IBM SPSS Collaboration and Deployment Services 4.x before 4.2.1.3 IF3, 5.x before 5.0 FP3, and 6.x before 6.0 IF1 allows remote attackers to read arbitrary files via an unspecified HTTP… CWE-200
Information Exposure
CVE-2013-4043 2024-11-21 10:54 2014-02-2 Show GitHub Exploit DB Packet Storm