Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
219291 4.3 警告 Apache Software Foundation - Apache Santuario XML Security for C++ の XML デジタル署名機能における署名を再利用される脆弱性 CWE-310
暗号の問題
CVE-2013-2153 2013-08-22 18:44 2013-07-17 Show GitHub Exploit DB Packet Storm
219292 5 警告 Puppet - Puppet Enterprise におけるデータベースパスワードを取得される脆弱性 CWE-255
証明書・パスワード管理
CVE-2013-4967 2013-08-22 18:24 2013-08-15 Show GitHub Exploit DB Packet Storm
219293 4.9 警告 Puppet - Puppet Enterprise における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2013-4959 2013-08-22 18:16 2013-08-15 Show GitHub Exploit DB Packet Storm
219294 6.9 警告 Puppet - Puppet Enterprise における権限を取得される脆弱性 CWE-287
不適切な認証
CVE-2013-4958 2013-08-22 18:16 2013-08-15 Show GitHub Exploit DB Packet Storm
219295 5.8 警告 Puppet - Puppet Enterprise のログインページにおけるオープンリダイレクトの脆弱性 CWE-20
不適切な入力確認
CVE-2013-4955 2013-08-22 18:08 2013-08-15 Show GitHub Exploit DB Packet Storm
219296 5.8 警告 Puppet - Puppet Enterprise におけるセッションをハイジャックされる脆弱性 CWE-20
不適切な入力確認
CVE-2013-4762 2013-08-22 18:06 2013-08-15 Show GitHub Exploit DB Packet Storm
219297 7.5 危険 OpenStack
Novell
- OpenStack Swift における XML インジェクションの脆弱性 CWE-94
コード・インジェクション
CVE-2013-2161 2013-08-22 17:47 2013-05-24 Show GitHub Exploit DB Packet Storm
219298 4.3 警告 OpenStack - OpenStack Keystone における認証を回避される脆弱性 CWE-287
不適切な認証
CVE-2013-2157 2013-08-22 17:44 2013-06-27 Show GitHub Exploit DB Packet Storm
219299 4.3 警告 Stanislas Rolland - TYPO3 用 Static Info Tables エクステンションにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-5323 2013-08-22 15:29 2013-02-19 Show GitHub Exploit DB Packet Storm
219300 7.5 危険 Jan Bednarik - TYPO3 用 CoolURI エクステンションにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2013-5322 2013-08-22 15:28 2013-02-19 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 26, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
277691 - microsoft outlook_express
windows_mail
Heap-based buffer overflow in Microsoft Outlook Express 6 and earlier, and Windows Mail for Vista, allows remote Network News Transfer Protocol (NNTP) servers to execute arbitrary code via long NNTP … CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2007-3897 2019-10-10 07:53 2007-10-10 Show GitHub Exploit DB Packet Storm
277692 - postgresql
tcl
debian
canonical
postgresql
tcl\/tk
debian_linux
ubuntu_linux
The regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows context-dependent attackers to cause a … CWE-399
 Resource Management Errors
CVE-2007-4772 2019-10-10 07:53 2008-01-10 Show GitHub Exploit DB Packet Storm
277693 - mozilla firefox
seamonkey
thunderbird
Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonkey before 1.1.5 allows remote attackers to execute arbitrary commands via a (1) mailto, (2) nntp, (3) news, or (4) snews URI wit… CWE-20
 Improper Input Validation 
CVE-2007-4841 2019-10-10 07:53 2007-09-13 Show GitHub Exploit DB Packet Storm
277694 - mozilla
canonical
firefox
seamonkey
thunderbird
ubuntu_linux
The JavaScript engine in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, and SeaMonkey before 1.0.8 allows remote attackers to cause a denial of service (crash) a… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2007-0777 2019-10-10 07:52 2007-02-27 Show GitHub Exploit DB Packet Storm
277695 - mozilla
canonical
firefox
seamonkey
thunderbird
ubuntu_linux
Successful exploitation in Thunderbird requires that JavaScript be enabled in mail which is not the default setting. CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2007-0777 2019-10-10 07:52 2007-02-27 Show GitHub Exploit DB Packet Storm
277696 - mozilla
canonical
debian
firefox
seamonkey
ubuntu_linux
debian_linux
The page cache feature in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 can generate hash collisions that cause page data to be appended to the wrong page cache, … CWE-200
Information Exposure
CVE-2007-0778 2019-10-10 07:52 2007-02-27 Show GitHub Exploit DB Packet Storm
277697 - mozilla
canonical
firefox
seamonkey
ubuntu_linux
browser.js in Mozilla Firefox 1.5.x before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 uses the requesting URI to identify child windows, which allows remote attackers to conduct cros… CWE-79
Cross-site Scripting
CVE-2007-0780 2019-10-10 07:52 2007-02-27 Show GitHub Exploit DB Packet Storm
277698 - php
canonical
php
ubuntu_linux
The zend_hash_init function in PHP 5 before 5.2.1 and PHP 4 before 4.4.5, when running on a 64-bit platform, allows context-dependent attackers to cause a denial of service (infinite loop) by unseria… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2007-0988 2019-10-10 07:52 2007-02-21 Show GitHub Exploit DB Packet Storm
277699 - php
canonical
php
ubuntu_linux
Availability also affected by time out alarm for the script, which helps prevent infinite loops. CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2007-0988 2019-10-10 07:52 2007-02-21 Show GitHub Exploit DB Packet Storm
277700 - mozilla
debian
firefox
seamonkey
debian_linux
A regression error in Mozilla Firefox 2.x before 2.0.0.2 and 1.x before 1.5.0.10, and SeaMonkey 1.1 before 1.1.1 and 1.0 before 1.0.8, allows remote attackers to execute arbitrary JavaScript as the u… CWE-94
Code Injection
CVE-2007-0994 2019-10-10 07:52 2007-03-6 Show GitHub Exploit DB Packet Storm