Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 20, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
219711 4.3 警告 WP Symposium - WordPress 用の WP Symposium プラグインの invite.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-2695 2014-04-1 12:24 2013-04-12 Show GitHub Exploit DB Packet Storm
219712 5.8 警告 WP Symposium - WordPress 用の WP Symposium プラグインの invite.php におけるオープンリダイレクトの脆弱性 CWE-20
不適切な入力確認
CVE-2013-2694 2014-04-1 12:23 2013-04-12 Show GitHub Exploit DB Packet Storm
219713 4.3 警告 Cartpauj.com - WordPress 用 Mingle Forum プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-0734 2014-04-1 12:23 2013-02-20 Show GitHub Exploit DB Packet Storm
219714 5.8 警告 シーメンス - Siemens SIMATIC S7-1500 CPU PLC デバイスの統合 Web サーバにおけるヘッダを挿入される脆弱性 CWE-Other
その他
CVE-2014-2247 2014-03-31 15:09 2014-03-12 Show GitHub Exploit DB Packet Storm
219715 6.8 警告 ownCloud - ownCloud における Web セッションをハイジャックされる脆弱性 CWE-287
不適切な認証
CVE-2014-2047 2014-03-31 15:09 2014-03-7 Show GitHub Exploit DB Packet Storm
219716 4.3 警告 シスコシステムズ - Cisco Prime Security Manager のダッシュボード関連の HTML ドキュメントにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-2118 2014-03-31 15:07 2014-03-27 Show GitHub Exploit DB Packet Storm
219717 7.8 危険 シスコシステムズ - Cisco IOS および IOS XE におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2014-2113 2014-03-31 15:06 2014-03-26 Show GitHub Exploit DB Packet Storm
219718 7.8 危険 シスコシステムズ - Cisco IOS の SSL VPN 機能におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2014-2112 2014-03-31 15:05 2014-03-26 Show GitHub Exploit DB Packet Storm
219719 7.1 危険 シスコシステムズ - Cisco IOS の Application Layer Gateway モジュールにおけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2014-2111 2014-03-31 15:04 2014-03-26 Show GitHub Exploit DB Packet Storm
219720 7.8 危険 シスコシステムズ - Cisco IOS の TCP Input モジュールにおけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2014-2109 2014-03-31 15:03 2014-03-26 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 20, 2026, 4:14 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
295611 - extplorer extplorer eXtplorer 2.1.0b6 uses world writable permissions for the /var/lib/extplorer/ftp_tmp directory, which allows local users to delete or overwrite arbitrary files. CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-3454 2024-11-21 10:40 2012-08-8 Show GitHub Exploit DB Packet Storm
295612 - debian logol logol 1.5.0 uses world writable permissions for the /var/lib/logol/results directory, which allows local users to delete or overwrite arbitrary files. CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-3453 2024-11-21 10:40 2012-08-8 Show GitHub Exploit DB Packet Storm
295613 - gnome screensaver gnome-screensaver 3.4.x before 3.4.4 and 3.5.x before 3.5.4, when multiple screens are used, only locks the screen with the active focus, which allows physically proximate attackers to bypass screen … CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-3452 2024-11-21 10:40 2012-08-8 Show GitHub Exploit DB Packet Storm
295614 - openvswitch openvswitch Open vSwitch 1.4.2 uses world writable permissions for (1) /var/lib/openvswitch/pki/controllerca/incoming/ and (2) /var/lib/openvswitch/pki/switchca/incoming/, which allows local users to delete and … CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-3449 2024-11-21 10:40 2012-08-8 Show GitHub Exploit DB Packet Storm
295615 - kde kde_pim The HTMLQuoteColorer::process function in messageviewer/htmlquotecolorer.cpp in KDE PIM 4.6 through 4.8 does not disable JavaScript, Java, and Plugins, which allows remote attackers to inject arbitra… CWE-16
Configuration
CVE-2012-3413 2024-11-21 10:40 2012-08-8 Show GitHub Exploit DB Packet Storm
295616 - ganglia ganglia-web Unspecified vulnerability in Ganglia Web before 3.5.1 allows remote attackers to execute arbitrary PHP code via unknown attack vectors. NVD-CWE-noinfo
CVE-2012-3448 2024-11-21 10:40 2012-08-7 Show GitHub Exploit DB Packet Storm
295617 - php php pdo_sql_parser.re in the PDO extension in PHP before 5.3.14 and 5.4.x before 5.4.4 does not properly determine the end of the query string during parsing of prepared statements, which allows remote a… NVD-CWE-Other
CVE-2012-3450 2024-11-21 10:40 2012-08-7 Show GitHub Exploit DB Packet Storm
295618 - puppetlabs
puppet
puppet
puppet_enterprise
lib/puppet/network/authstore.rb in Puppet before 2.7.18, and Puppet Enterprise before 2.5.2, supports use of IP addresses in certnames without warning of potential risks, which might allow remote att… CWE-287
Improper Authentication
CVE-2012-3408 2024-11-21 10:40 2012-08-7 Show GitHub Exploit DB Packet Storm
295619 - siemens synco_ozw_web_server
synco_ozw_web_server_firmware
The Siemens Synco OZW Web Server devices OZW672.*, OZW772.*, and OZW775 with firmware before 4 have an unspecified default password, which makes it easier for remote attackers to obtain administrativ… CWE-255
Credentials Management
CVE-2012-3020 2024-11-21 10:40 2012-08-7 Show GitHub Exploit DB Packet Storm
295620 - djangoproject django The get_image_dimensions function in the image-handling functionality in Django before 1.3.2 and 1.4.x before 1.4.1 uses a constant chunk size in all attempts to determine dimensions, which allows re… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2012-3444 2024-11-21 10:40 2012-08-1 Show GitHub Exploit DB Packet Storm