Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 21, 2026, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
219721 9.3 危険 マイクロソフト - Microsoft Word 2003 におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2014-1758 2014-04-10 15:39 2014-04-8 Show GitHub Exploit DB Packet Storm
219722 7.5 危険 TIBCO Software - 複数の TIBCO 製品におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2014-2543 2014-04-10 11:54 2014-04-8 Show GitHub Exploit DB Packet Storm
219723 4.3 警告 TIBCO Software - 複数の TIBCO 製品におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-2542 2014-04-10 11:54 2014-04-8 Show GitHub Exploit DB Packet Storm
219724 5 警告 TIBCO Software - 複数の TIBCO 製品における重要な情報を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-2541 2014-04-10 11:54 2014-04-8 Show GitHub Exploit DB Packet Storm
219725 4.3 警告 ClipBucket - ClipBucket におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-6644 2014-04-9 13:51 2012-01-9 Show GitHub Exploit DB Packet Storm
219726 7.5 危険 ClipBucket - ClipBucket の includes/functions.php の update_counter 関数における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2012-6643 2014-04-9 13:50 2012-01-9 Show GitHub Exploit DB Packet Storm
219727 4.3 警告 ClipBucket - ClipBucket におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-6642 2014-04-9 13:50 2012-01-9 Show GitHub Exploit DB Packet Storm
219728 4.3 警告 danielb - Drupal 用 Finder モジュールのオートコンプリート機能におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-6645 2014-04-9 12:21 2012-02-8 Show GitHub Exploit DB Packet Storm
219729 4.3 警告 danielb - Drupal 用 Finder モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-1561 2014-04-9 12:21 2012-02-8 Show GitHub Exploit DB Packet Storm
219730 7.5 危険 Advanced Forum Signatures Project - MyBB 用 Advanced Forum Signatures プラグインの signature.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2011-5278 2014-04-9 12:12 2011-10-10 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 21, 2026, 4:10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
293291 - ibm tivoli_federated_identity_manager
tivoli_federated_identity_manager_business_gateway
IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.11, 6.2.1 before 6.2.1.3, and 6.2.2 before 6.2.2.2 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.2.0 before 6.2.0.1… CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-6359 2024-11-21 10:46 2013-01-19 Show GitHub Exploit DB Packet Storm
293292 - samba samba Samba 4.0.x before 4.0.1, in certain Active Directory domain-controller configurations, does not properly interpret Access Control Entries that are based on an objectClass, which allows remote authen… CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-0172 2024-11-21 10:46 2013-01-18 Show GitHub Exploit DB Packet Storm
293293 - cisco quad
webex_social
Cross-site scripting (XSS) vulnerability in Cisco WebEx Social (formerly Cisco Quad) allows remote attackers to inject arbitrary web script or HTML via a crafted RSS service link, aka Bug ID CSCub619… CWE-79
Cross-site Scripting
CVE-2012-6397 2024-11-21 10:46 2013-01-18 Show GitHub Exploit DB Packet Storm
293294 - cisco prime_lan_management_solution Cisco Prime LAN Management Solution (LMS) 4.1 through 4.2.2 on Linux does not properly validate authentication and authorization requests in TCP sessions, which allows remote attackers to execute arb… CWE-20
 Improper Input Validation 
CVE-2012-6392 2024-11-21 10:46 2013-01-18 Show GitHub Exploit DB Packet Storm
293295 - rubyonrails
debian
ruby_on_rails
rails
debian_linux
active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly restrict casts of string values, which … CWE-20
 Improper Input Validation 
CVE-2013-0156 2024-11-21 10:46 2013-01-14 Show GitHub Exploit DB Packet Storm
293296 - rubyonrails
debian
ruby_on_rails
rails
debian_linux
Ruby on Rails 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly consider differences in parameter handling between the Active Record component and the JSON implement… CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-0155 2024-11-21 10:46 2013-01-14 Show GitHub Exploit DB Packet Storm
293297 - xen xen The get_page_type function in xen/arch/x86/mm.c in Xen 4.2, when debugging is enabled, allows local PV or HVM guest administrators to cause a denial of service (assertion failure and hypervisor crash… NVD-CWE-noinfo
CVE-2013-0154 2024-11-21 10:46 2013-01-12 Show GitHub Exploit DB Packet Storm
293298 - hp pki_activex_control The KillProcess method in the HP PKI ActiveX control (HPPKI.ocx) before 1.2.0.1 allows remote attackers to cause a denial of service (kill process) via the partial or full name of a process. CWE-20
 Improper Input Validation 
CVE-2012-6501 2024-11-21 10:46 2013-01-12 Show GitHub Exploit DB Packet Storm
293299 - pragyan_cms_project pragyan_cms Directory traversal vulnerability in download.lib.php in Pragyan CMS 3.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the fileget parameter in a profile action to… CWE-22
Path Traversal
CVE-2012-6500 2024-11-21 10:46 2013-01-12 Show GitHub Exploit DB Packet Storm
293300 - age_verification_project age_verification Open redirect vulnerability in age-verification.php in the Age Verification plugin 0.4 and earlier for WordPress allows remote attackers to redirect users to arbitrary web sites and conduct phishing … CWE-20
 Improper Input Validation 
CVE-2012-6499 2024-11-21 10:46 2013-01-12 Show GitHub Exploit DB Packet Storm