Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 2, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
219791 6.4 警告 Microweber - Microweber の userfiles/modules/admin/backup/delete.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2013-5984 2014-05-14 11:53 2013-09-26 Show GitHub Exploit DB Packet Storm
219792 7.5 危険 Mark Evans - Ruby 用 fog-dragonfly gem の lib/dragonfly/imagemagickutils.rb における任意のコマンドを実行される脆弱性 CWE-Other
その他
CVE-2013-5671 2014-05-14 11:46 2013-08-16 Show GitHub Exploit DB Packet Storm
219793 6.8 警告 MediaWiki - MediaWiki 用 SemanticForms 拡張機能の特別ページにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2014-3455 2014-05-14 11:45 2013-11-13 Show GitHub Exploit DB Packet Storm
219794 6.8 警告 MediaWiki - MediaWiki 用 SemanticForms 拡張機能の Special:CreateCategory におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2014-3454 2014-05-14 11:44 2013-11-13 Show GitHub Exploit DB Packet Storm
219795 5 警告 MediaWiki - MediaWiki における削除されたページについての情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2013-6472 2014-05-14 11:44 2013-12-19 Show GitHub Exploit DB Packet Storm
219796 4.3 警告 MediaWiki - MediaWiki におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-6454 2014-05-14 11:43 2013-12-13 Show GitHub Exploit DB Packet Storm
219797 7.5 危険 MediaWiki - MediaWiki における脆弱性 CWE-20
不適切な入力確認
CVE-2013-6453 2014-05-14 11:43 2013-12-16 Show GitHub Exploit DB Packet Storm
219798 4.3 警告 MediaWiki - MediaWiki におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-6452 2014-05-14 11:42 2013-11-25 Show GitHub Exploit DB Packet Storm
219799 4.3 警告 SpringSource - Spring Framework の Spring MVC におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-1904 2014-05-14 10:35 2014-02-18 Show GitHub Exploit DB Packet Storm
219800 10 危険 3S-Smart Software Solutions
Festo
- CODESYS Runtime System の Runtime Toolkit におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2012-6069 2014-05-13 17:19 2013-01-11 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 2, 2026, 4:18 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
296311 - nagios
icinga
nagios
icinga
Multiple stack-based buffer overflows in the get_history function in history.cgi in Nagios Core before 3.4.4, and Icinga 1.6.x before 1.6.2, 1.7.x before 1.7.4, and 1.8.x before 1.8.4, might allow re… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2012-6096 2024-11-21 10:45 2013-01-23 Show GitHub Exploit DB Packet Storm
296312 - 3s-software codesys_runtime_system Directory traversal vulnerability in the Runtime Toolkit in CODESYS Runtime System 2.3.x and 2.4.x allows remote attackers to read, overwrite, or create arbitrary files via a .. (dot dot) in a reques… CWE-22
Path Traversal
CVE-2012-6069 2024-11-21 10:45 2013-01-22 Show GitHub Exploit DB Packet Storm
296313 - 3s-software codesys_runtime_system The Runtime Toolkit in CODESYS Runtime System 2.3.x and 2.4.x does not require authentication, which allows remote attackers to (1) execute commands via the command-line interface in the TCP listener… CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-6068 2024-11-21 10:45 2013-01-22 Show GitHub Exploit DB Packet Storm
296314 - php php The openssl_encrypt function in ext/openssl/openssl.c in PHP 5.3.9 through 5.3.13 does not initialize a certain variable, which allows remote attackers to obtain sensitive information from process me… CWE-200
Information Exposure
CVE-2012-6113 2024-11-21 10:45 2013-01-20 Show GitHub Exploit DB Packet Storm
296315 - cisco adaptive_security_appliance_software
adaptive_security_appliance
asa_1000v_cloud_firewall
asa_5500
Cisco Adaptive Security Appliances (ASA) devices with firmware 8.x through 8.4(1) do not properly manage SSH sessions, which allows remote authenticated users to cause a denial of service (device cra… CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-5717 2024-11-21 10:45 2013-01-19 Show GitHub Exploit DB Packet Storm
296316 - rpm rpm The rpmpkgRead function in lib/package.c in RPM 4.10.x before 4.10.2 does not return an error code in certain situations involving an "unparseable signature," which allows remote attackers to bypass … CWE-255
Credentials Management
CVE-2012-6088 2024-11-21 10:45 2013-01-18 Show GitHub Exploit DB Packet Storm
296317 - fireflymediaserver firefly_media_server Firefly Media Server 1.0.0.1359 allows remote attackers to cause a denial of service (NULL pointer dereference) via a (1) crafted Connection HTTP header; a return carriage control character in the (2… NVD-CWE-Other
CVE-2012-5875 2024-11-21 10:45 2013-01-18 Show GitHub Exploit DB Packet Storm
296318 5.5 MEDIUM
Local
inkscape
fedoraproject
canonical
opensuse
inkscape
fedora
ubuntu_linux
opensuse
The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in a SVG file, aka an XML external entity (XXE) injection attack. CWE-611
XXE
CVE-2012-5656 2024-11-21 10:45 2013-01-18 Show GitHub Exploit DB Packet Storm
296319 - specview specview Directory traversal vulnerability in the web server in SpecView 2.5 build 853 and earlier allows remote attackers to read arbitrary files via a ... (dot dot dot) in a URI. CWE-22
Path Traversal
CVE-2012-5972 2024-11-21 10:45 2013-01-18 Show GitHub Exploit DB Packet Storm
296320 - elite-board elite_bulletin_board Multiple SQL injection vulnerabilities in the (1) update_whosonline_reg and (2) update_whosonline_guest functions in Elite Bulletin Board before 2.1.22 allow remote attackers to execute arbitrary SQL… CWE-89
SQL Injection
CVE-2012-5874 2024-11-21 10:45 2013-01-12 Show GitHub Exploit DB Packet Storm