Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 2, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
219451 7.1 危険 IBM - IBM Lotus Protector for Mail Security の Admin Web UI における任意のコマンドを実行される脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2014-0887 2014-05-30 15:51 2014-03-24 Show GitHub Exploit DB Packet Storm
219452 7.1 危険 IBM - IBM Lotus Protector for Mail Security の Admin Web UI におけるアクセス制限を回避される脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2014-0886 2014-05-30 15:29 2014-03-24 Show GitHub Exploit DB Packet Storm
219453 6.8 警告 IBM - IBM Lotus Protector for Mail Security の Admin Web UI におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2014-0885 2014-05-30 15:22 2014-03-24 Show GitHub Exploit DB Packet Storm
219454 3.5 注意 IBM - IBM Lotus Protector for Mail Security の Admin Web UI におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-0884 2014-05-30 15:09 2014-03-24 Show GitHub Exploit DB Packet Storm
219455 5 警告 Google Doc Embedder - WordPress 用 Google Doc Embedder プラグインにおけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2012-4915 2014-05-30 10:51 2012-09-14 Show GitHub Exploit DB Packet Storm
219456 4.3 警告 IBM - IBM WebSphere Portal における任意のファイルを読まれる脆弱性 CWE-200
情報漏えい
CVE-2013-5454 2014-05-30 10:38 2013-11-11 Show GitHub Exploit DB Packet Storm
219457 4.3 警告 IBM - IBM Domino の iNotes の MIME 電子メール機能におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-3990 2014-05-29 18:30 2013-07-31 Show GitHub Exploit DB Packet Storm
219458 4.3 警告 IBM - IBM Domino の iNotes の MIME 電子メール機能におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-3032 2014-05-29 18:30 2013-07-31 Show GitHub Exploit DB Packet Storm
219459 9.3 危険 IBM - IBM Domino の iNotes の DWA9W ActiveX コントロールにおける整数オーバーフローの脆弱性 CWE-189
数値処理の問題
CVE-2013-3027 2014-05-29 18:29 2013-07-31 Show GitHub Exploit DB Packet Storm
219460 9.3 危険 IBM - IBM Lotus Quickr for Domino におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2013-3026 2014-05-29 18:28 2013-06-7 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 2, 2026, 4:18 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
296521 - paypal merchant_sdk The PayPal merchant SDK does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-midd… CWE-20
 Improper Input Validation 
CVE-2012-5787 2024-11-21 10:45 2012-11-5 Show GitHub Exploit DB Packet Storm
296522 - apache cxf The wsdl_first_https sample code in distribution/src/main/release/samples/wsdl_first_https/src/main/ in Apache CXF before 2.7.0 does not verify that the server hostname matches a domain name in the s… CWE-20
 Improper Input Validation 
CVE-2012-5786 2024-11-21 10:45 2012-11-5 Show GitHub Exploit DB Packet Storm
296523 - apache axis2 Apache Axis2/Java 1.6.2 and earlier does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man… CWE-20
 Improper Input Validation 
CVE-2012-5785 2024-11-21 10:45 2012-11-5 Show GitHub Exploit DB Packet Storm
296524 - apache
paypal
axis
mass_pay
transactional_information_soap
payments_pro
activemq
Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service implementation in Apache ActiveMQ, and other products, do… CWE-20
 Improper Input Validation 
CVE-2012-5784 2024-11-21 10:45 2012-11-5 Show GitHub Exploit DB Packet Storm
296525 - apache
canonical
httpclient
ubuntu_linux
Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain name in the subject's … CWE-295
Improper Certificate Validation 
CVE-2012-5783 2024-11-21 10:45 2012-11-5 Show GitHub Exploit DB Packet Storm
296526 - amazon flexible_payments_service Amazon Flexible Payments Service (FPS) PHP Library does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, w… CWE-20
 Improper Input Validation 
CVE-2012-5782 2024-11-21 10:45 2012-11-5 Show GitHub Exploit DB Packet Storm
296527 - amazon elastic_load_balancing Amazon Elastic Load Balancing API Tools does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows… CWE-20
 Improper Input Validation 
CVE-2012-5781 2024-11-21 10:45 2012-11-5 Show GitHub Exploit DB Packet Storm
296528 - amazon merchant_sdk The Amazon merchant SDK does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-midd… CWE-20
 Improper Input Validation 
CVE-2012-5780 2024-11-21 10:45 2012-11-5 Show GitHub Exploit DB Packet Storm
296529 - justin_dodge hotblocks Cross-site scripting (XSS) vulnerability in the settings page (admin/settings/hotblocks) in the Hotblocks module 6.x-1.x before 6.x-1.8 for Drupal allows remote authenticated users with the "administ… CWE-79
Cross-site Scripting
CVE-2012-5705 2024-11-21 10:45 2012-11-1 Show GitHub Exploit DB Packet Storm
296530 - justin_dodge hotblocks The Hotblocks module 6.x-1.x before 6.x-1.8 for Drupal allows remote authenticated users with the "administer hotblocks" permission to cause a denial of service (infinite loop and time out) via a blo… CWE-399
 Resource Management Errors
CVE-2012-5704 2024-11-21 10:45 2012-11-1 Show GitHub Exploit DB Packet Storm