Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 14, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
219751 5 警告 WerdsWords - WordPress 用 Download Shortcode プラグインの force-download.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2014-5465 2014-09-4 18:53 2014-08-28 Show GitHub Exploit DB Packet Storm
219752 4.3 警告 Quick Post Widget - WordPress 用 Quick Post Widget プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-4226 2014-09-4 18:44 2012-08-10 Show GitHub Exploit DB Packet Storm
219753 9.3 危険 Mathias Kettner GmbH - Check_MK の wato コンポーネントにおける任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2014-5340 2014-09-4 17:03 2014-05-27 Show GitHub Exploit DB Packet Storm
219754 4.9 警告 Mathias Kettner GmbH - Check_MK における任意の場所に check_mk config ファイルを書き込まれる脆弱性 CWE-noinfo
情報不足
CVE-2014-5339 2014-09-4 17:03 2014-05-27 Show GitHub Exploit DB Packet Storm
219755 9.3 危険 Mozilla Foundation - Mozilla Firefox および Thunderbird の DirectionalityUtils.cpp における任意のコードを実行される脆弱性 CWE-Other
その他
CVE-2014-1567 2014-09-4 16:07 2014-09-2 Show GitHub Exploit DB Packet Storm
219756 4.3 警告 Mozilla Foundation - Android 上で稼働する Mozilla Firefox における Firefox プロファイルディレクトリから重要な情報を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-1566 2014-09-4 16:06 2014-09-2 Show GitHub Exploit DB Packet Storm
219757 5 警告 Mozilla Foundation - Mozilla Firefox および Thunderbird の Web Audio API の実装におけるプロセスメモリから重要な情報を取得される脆弱性 CWE-119
バッファエラー
CVE-2014-1565 2014-09-4 16:06 2014-09-2 Show GitHub Exploit DB Packet Storm
219758 4.3 警告 Mozilla Foundation - Mozilla Firefox および Thunderbird におけるプロセスメモリから重要な情報を取得される脆弱性 CWE-Other
その他
CVE-2014-1564 2014-09-4 16:06 2014-09-2 Show GitHub Exploit DB Packet Storm
219759 10 危険 Mozilla Foundation - Mozilla Firefox および Thunderbird のブラウザエンジンにおけるサービス運用妨害 (DoS) の脆弱性 CWE-119
CWE-noinfo
CVE-2014-1562 2014-09-4 16:04 2014-09-2 Show GitHub Exploit DB Packet Storm
219760 10 危険 Mozilla Foundation - Mozilla Firefox および Thunderbird のブラウザエンジンにおけるサービス運用妨害 (DoS) の脆弱性 CWE-119
CWE-noinfo
CVE-2014-1554 2014-09-4 16:04 2014-09-2 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 14, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
290891 5.3 MEDIUM
Network
open-xchange open-xchange_appsuite The backend in Open-Xchange (OX) AppSuite 7.4.2 before 7.4.2-rev9 allows remote attackers to obtain sensitive information about user email addresses in opportunistic circumstances by leveraging a fai… CWE-200
Information Exposure
CVE-2014-2078 2024-11-21 11:05 2018-04-11 Show GitHub Exploit DB Packet Storm
290892 9.8 CRITICAL
Network
3ds catia Stack-based buffer overflow in Dassault Systemes CATIA V5-6R2013 allows remote attackers to execute arbitrary code via a crafted packet, related to "CATV5_Backbone_Bus." CWE-787
 Out-of-bounds Write
CVE-2014-2073 2024-11-21 11:05 2018-04-11 Show GitHub Exploit DB Packet Storm
290893 8.8 HIGH
Network
opendocman opendocman OpenDocMan 1.2.7 and earlier does not properly validate allowed actions, which allows remote authenticated users to bypass an intended access restrictions and assign administrative privileges to them… CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-1946 2024-11-21 11:05 2018-04-11 Show GitHub Exploit DB Packet Storm
290894 6.5 MEDIUM
Network
buddypress buddypress The Group creation process in the Buddypress plugin before 1.9.2 for WordPress allows remote authenticated users to gain control of arbitrary groups by leveraging a missing permissions check. CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-1889 2024-11-21 11:05 2018-04-11 Show GitHub Exploit DB Packet Storm
290895 9.8 CRITICAL
Network
owncloud owncloud The user_openid app in ownCloud Server before 5.0.15 allows remote attackers to obtain access by leveraging an insecure OpenID implementation. CWE-284
Improper Access Control
CVE-2014-2048 2024-11-21 11:05 2018-03-27 Show GitHub Exploit DB Packet Storm
290896 5.9 MEDIUM
Network
maradns_project
deadwood_project
maradns
deadwood
Deadwood before 2.3.09, 3.x before 3.2.05, and as used in MaraDNS before 1.4.14 and 2.x before 2.0.09, allow remote attackers to cause a denial of service (out-of-bounds read and crash) by leveraging… CWE-20
CWE-125
 Improper Input Validation 
Out-of-bounds Read
CVE-2014-2032 2024-11-21 11:05 2018-03-21 Show GitHub Exploit DB Packet Storm
290897 5.9 MEDIUM
Network
maradns_project
deadwood_project
maradns
deadwood
Deadwood before 2.3.09, 3.x before 3.2.05, and as used in MaraDNS before 1.4.14 and 2.x before 2.0.09, allow remote attackers to cause a denial of service (out-of-bounds read and crash) by leveraging… CWE-125
Out-of-bounds Read
CVE-2014-2031 2024-11-21 11:05 2018-03-21 Show GitHub Exploit DB Packet Storm
290898 8.8 HIGH
Network
subscribe_to_comments_reloaded_project subscribe_to_comments_reloaded Cross-site request forgery (CSRF) vulnerability in the Subscribe To Comments Reloaded plugin before 140219 for WordPress allows remote attackers to hijack the authentication of administrators for req… CWE-352
 Origin Validation Error
CVE-2014-2274 2024-11-21 11:05 2018-03-20 Show GitHub Exploit DB Packet Storm
290899 7.8 HIGH
Local
echor_project echor The perform_request function in /lib/echor/backplane.rb in echor 0.1.6 Ruby Gem allows local users to steal the login credentials by watching the process table. CWE-255
Credentials Management
CVE-2014-1835 2024-11-21 11:05 2018-02-3 Show GitHub Exploit DB Packet Storm
290900 7.8 HIGH
Local
echor_project echor The perform_request function in /lib/echor/backplane.rb in echor 0.1.6 Ruby Gem allows local users to inject arbitrary code by adding a semi-colon in their username or password. CWE-77
Command Injection
CVE-2014-1834 2024-11-21 11:05 2018-02-3 Show GitHub Exploit DB Packet Storm