Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 12, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
219151 7.5 危険 アドビシステムズ
Apache Software Foundation
- Apache Cordova および Adobe PhoneGap におけるイベントベースのブリッジのデバイスリソース制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-1881 2014-03-4 19:32 2014-01-24 Show GitHub Exploit DB Packet Storm
219152 7.5 危険 アドビシステムズ
Apache Software Foundation
- Apache Cordova および Adobe PhoneGap におけるホワイトリスト保護メカニズムを回避される脆弱性 CWE-20
不適切な入力確認
CVE-2012-6637 2014-03-4 19:07 2012-04-30 Show GitHub Exploit DB Packet Storm
219153 5 警告 PNG Development Group - libpng におけるサービス運用妨害 (DoS) の脆弱性 CWE-189
CWE-Other
CVE-2014-0333 2014-03-4 18:16 2014-02-25 Show GitHub Exploit DB Packet Storm
219154 6.8 警告 Google - Android API における Java オブジェクトの任意のメソッドを実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-6636 2014-03-4 17:49 2014-02-7 Show GitHub Exploit DB Packet Storm
219155 4.3 警告 MediaWiki - MediaWiki の includes/api/ApiFormatBase.php の formatHTML 関数におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-2244 2014-03-4 17:06 2014-02-28 Show GitHub Exploit DB Packet Storm
219156 5.8 警告 MediaWiki - MediaWiki の includes/User.php におけるアクセス権を取得される脆弱性 CWE-362
競合状態
CVE-2014-2243 2014-03-4 17:06 2014-02-28 Show GitHub Exploit DB Packet Storm
219157 4.3 警告 MediaWiki - MediaWiki の includes/upload/UploadBase.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-2242 2014-03-4 17:06 2014-02-28 Show GitHub Exploit DB Packet Storm
219158 4.3 警告 シスコシステムズ - Cisco Unified Communications Domain Manager の Business Voice Services Manager のページにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-2104 2014-03-4 17:00 2014-02-28 Show GitHub Exploit DB Packet Storm
219159 7.9 危険 ブルーコートシステムズ - Blue Coat ProxySG に脆弱性 CWE-264
CWE-Other
CVE-2014-2033 2014-03-4 16:58 2014-02-28 Show GitHub Exploit DB Packet Storm
219160 9.3 危険 SAS - Base SAS のクライアントアプリケーションにおけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2014-2262 2014-03-4 16:38 2014-01-17 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 13, 2026, 5:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
293291 - moodle moodle Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authenticated users to bypass intended capability restrictions and perform certain topic changes by leveraging course-editing capabiliti… CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-4401 2024-11-21 10:42 2012-09-19 Show GitHub Exploit DB Packet Storm
293292 - moodle moodle repository/repository_ajax.php in Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authenticated users to bypass intended upload-size restrictions via a -1 value in the maxbytes field. CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-4400 2024-11-21 10:42 2012-09-19 Show GitHub Exploit DB Packet Storm
293293 - freedesktop
gtk
spice-gtk
libgio
libgio, when used in setuid or other privileged programs in spice-gtk and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYSTEM_BUS_ADDRESS env… CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-4425 2024-11-21 10:42 2012-09-19 Show GitHub Exploit DB Packet Storm
293294 - openstack keystone OpenStack Keystone 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles. CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-4413 2024-11-21 10:42 2012-09-19 Show GitHub Exploit DB Packet Storm
293295 - ghostscript
argyllcms
color
ghostscript
cms
icclib
Multiple integer underflows in the icmLut_allocate function in International Color Consortium (ICC) Format library (icclib), as used in Ghostscript 9.06 and Argyll Color Management System, allow remo… CWE-189
Numeric Errors
CVE-2012-4405 2024-11-21 10:42 2012-09-19 Show GitHub Exploit DB Packet Storm
293296 - mike_carr flogr Multiple cross-site scripting (XSS) vulnerabilities in index.php in Flogr 2.5.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO or (2) an arbitrary par… CWE-79
Cross-site Scripting
CVE-2012-4336 2024-11-21 10:42 2012-09-16 Show GitHub Exploit DB Packet Storm
293297 - google mod_pagespeed Cross-site scripting (XSS) vulnerability in the mod_pagespeed module 0.10.19.1 through 0.10.22.4 for the Apache HTTP Server allows remote attackers to inject arbitrary web script or HTML via unspecif… CWE-79
Cross-site Scripting
CVE-2012-4360 2024-11-21 10:42 2012-09-15 Show GitHub Exploit DB Packet Storm
293298 - google mod_pagespeed The mod_pagespeed module before 0.10.22.6 for the Apache HTTP Server does not properly verify its host name, which allows remote attackers to trigger HTTP requests to arbitrary hosts via unspecified … CWE-20
 Improper Input Validation 
CVE-2012-4001 2024-11-21 10:42 2012-09-15 Show GitHub Exploit DB Packet Storm
293299 - cybozu kunai_browser_for_remote_service The WebView class in the Cybozu KUNAI Browser for Remote Service application beta for Android allows remote attackers to execute arbitrary JavaScript code, and obtain sensitive information, via a cra… CWE-200
Information Exposure
CVE-2012-4013 2024-11-21 10:42 2012-09-15 Show GitHub Exploit DB Packet Storm
293300 - wordpress wordpress wp-admin/plugins.php in WordPress before 3.4.2, when the multisite feature is enabled, does not check for network-administrator privileges before performing a network-wide activation of an installed … CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-4422 2024-11-21 10:42 2012-09-15 Show GitHub Exploit DB Packet Storm