Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 4, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
218991 4.3 警告 Blogstand Banner plugin project - WordPress 用 Blogstand Banner プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-4848 2014-07-11 14:39 2014-06-28 Show GitHub Exploit DB Packet Storm
218992 4.3 警告 Buffercode - WordPress 用 Random Banner プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-4847 2014-07-11 14:38 2014-06-28 Show GitHub Exploit DB Packet Storm
218993 4.3 警告 Matcha Labs - WordPress 用 Meta Slider プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-4846 2014-07-11 14:37 2014-06-27 Show GitHub Exploit DB Packet Storm
218994 4.3 警告 Chris Taylor - WordPress 用 BannerMan プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-4845 2014-07-11 14:37 2014-06-27 Show GitHub Exploit DB Packet Storm
218995 4 警告 シスコシステムズ - Cisco Unified Communications Manager の Dialed Number Analyzer コンポーネントにおけるディレクトリトラバーサルの脆弱性 CWE-20
不適切な入力確認
CVE-2014-3318 2014-07-11 14:08 2014-07-10 Show GitHub Exploit DB Packet Storm
218996 4 警告 シスコシステムズ - Cisco Unified Communications Manager の Dialed Number Analyzer コンポーネントにおけるアップロードの制限を回避される脆弱性 CWE-20
不適切な入力確認
CVE-2014-3316 2014-07-11 14:07 2014-07-10 Show GitHub Exploit DB Packet Storm
218997 4.3 警告 シスコシステムズ - Cisco Unified Communications Manager の Dialed Number Analyzer コンポーネントにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-3315 2014-07-11 14:06 2014-07-10 Show GitHub Exploit DB Packet Storm
218998 5.1 警告 シスコシステムズ - Cisco WebEx Meetings Server および WebEx Meeting Center の WebEx Meetings クライアントにおけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2014-3311 2014-07-11 14:06 2014-07-10 Show GitHub Exploit DB Packet Storm
218999 4.3 警告 シスコシステムズ - Cisco WebEx Meetings Server および WebEx Meeting Center の WebEx Meetings クライアントにおける任意のファイルを読まれる脆弱性 CWE-20
不適切な入力確認
CVE-2014-3310 2014-07-11 14:05 2014-07-10 Show GitHub Exploit DB Packet Storm
219000 4.3 警告 osTicket - osTicket におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-4744 2014-07-11 12:29 2014-06-20 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 4, 2026, 4:17 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
290841 - ibm global_security_kit
tivoli_directory_server
security_directory_server
IBM GSKit 7.x before 7.0.4.48 and 8.x before 8.0.50.16, as used in IBM Security Directory Server (ISDS) and Tivoli Directory Server (TDS), allows remote attackers to cause a denial of service (applic… CWE-20
 Improper Input Validation 
CVE-2013-6747 2024-11-21 10:59 2014-01-28 Show GitHub Exploit DB Packet Storm
290842 - libreswan libreswan Libreswan 3.7 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon restart) via IKEv2 packets that lack expected payloads. NVD-CWE-Other
CVE-2013-6467 2024-11-21 10:59 2014-01-27 Show GitHub Exploit DB Packet Storm
290843 - xelerance openswan Openswan 2.6.39 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon restart) via IKEv2 packets that lack expected payloads. NVD-CWE-Other
CVE-2013-6466 2024-11-21 10:59 2014-01-27 Show GitHub Exploit DB Packet Storm
290844 - pivotal_software
vmware
spring_framework The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolution, which allows remote attackers to read arbitra… CWE-352
CWE-611
 Origin Validation Error
XXE
CVE-2013-6429 2024-11-21 10:59 2014-01-27 Show GitHub Exploit DB Packet Storm
290845 - apple
canonical
cups
ubuntu_linux
lppasswd in CUPS before 1.7.1, when running with setuid privileges, allows local users to read portions of arbitrary files via a modified HOME environment variable and a symlink attack involving .cup… CWE-59
Link Following
CVE-2013-6891 2024-11-21 10:59 2014-01-26 Show GitHub Exploit DB Packet Storm
290846 - yahoo toolbar Cross-site scripting (XSS) vulnerability in clickstream.js in Y! Toolbar plugin for FireFox 3.1.0.20130813024103 for Mac, and 2.5.9.2013418100420 for Windows, allows remote attackers to inject arbitr… CWE-79
Cross-site Scripting
CVE-2013-6853 2024-11-21 10:59 2014-01-26 Show GitHub Exploit DB Packet Storm
290847 - redhat libvirt Multiple race conditions in the (1) virDomainBlockStats, (2) virDomainGetBlockInf, (3) qemuDomainBlockJobImpl, and (4) virDomainGetBlockIoTune functions in libvirt before 1.2.1 do not properly verify… CWE-362
Race Condition
CVE-2013-6458 2024-11-21 10:59 2014-01-25 Show GitHub Exploit DB Packet Storm
290848 - redhat libvirt The libxlDomainGetNumaParameters function in the libxl driver (libxl/libxl_driver.c) in libvirt before 1.2.1 does not properly initialize the nodemap, which allows local users to cause a denial of se… CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-6457 2024-11-21 10:59 2014-01-25 Show GitHub Exploit DB Packet Storm
290849 - redhat enterprise_virtualization_manager The remote-viewer in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.3, when using a native SPICE client invocation method, initially makes insecure connections to the SPICE server, which… CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-6434 2024-11-21 10:59 2014-01-25 Show GitHub Exploit DB Packet Storm
290850 - live555
videolan
streaming_media
vlc_media_player
The parseRTSPRequestString function in Live Networks Live555 Streaming Media 2013.11.26, as used in VideoLAN VLC Media Player, allows remote attackers to cause a denial of service (crash) and possibl… CWE-189
Numeric Errors
CVE-2013-6934 2024-11-21 10:59 2014-01-24 Show GitHub Exploit DB Packet Storm