Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 26, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
219841 5 警告 PaperThin - PaperThin CommonSpot における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2014-2871 2014-04-21 19:01 2014-04-14 Show GitHub Exploit DB Packet Storm
219842 4.3 警告 PaperThin - PaperThin CommonSpot におけるクロスサイトスクリプティングの脆弱性 CWE-Other
その他
CVE-2014-2861 2014-04-21 19:01 2014-04-14 Show GitHub Exploit DB Packet Storm
219843 4.3 警告 PaperThin - PaperThin CommonSpot におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-2860 2014-04-21 19:01 2014-04-14 Show GitHub Exploit DB Packet Storm
219844 7.5 危険 PaperThin - PaperThin CommonSpot におけるアクセス制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-2859 2014-04-21 19:01 2014-04-14 Show GitHub Exploit DB Packet Storm
219845 4 警告 コクヨS&T株式会社 - Android 版 CamiApp における Content Provider のアクセス制限不備の脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-1986 2014-04-21 18:31 2014-04-14 Show GitHub Exploit DB Packet Storm
219846 2.1 注意 PackageKit Project - PackageKit の Zypper バックエンドにおけるパッケージをダウングレードされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-1764 2014-04-21 18:28 2013-05-8 Show GitHub Exploit DB Packet Storm
219847 4.6 警告 bzip.org - bzip2 の bzexe コマンドにおける任意のコードを実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2011-4089 2014-04-21 17:56 2011-12-4 Show GitHub Exploit DB Packet Storm
219848 7.5 危険 Novell - SUSE Studio Onsite および SUSE Studio Extension for System z で使用される KIWI における任意のコマンドを実行される脆弱性 CWE-Other
その他
CVE-2011-4195 2014-04-21 17:27 2011-12-15 Show GitHub Exploit DB Packet Storm
219849 4.3 警告 Novell - SUSE Studio Onsite および SUSE Studio Extension for System z のオーバーレイファイルタブにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-4193 2014-04-21 17:25 2011-12-15 Show GitHub Exploit DB Packet Storm
219850 7.5 危険 Novell - SUSE Studio Onsite および SUSE Studio Extension for System z で使用される KIWI における任意のコマンドを実行される脆弱性 CWE-Other
その他
CVE-2011-4192 2014-04-21 17:24 2011-12-15 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 27, 2026, 4:52 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
294341 - ibm spss_samplepower Buffer overflow in the c1sizer ActiveX control in C1sizer.ocx in IBM SPSS SamplePower 3.0 before FP1 allows remote attackers to execute arbitrary code via a long TabCaption string. CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2012-5946 2024-11-21 10:45 2013-04-30 Show GitHub Exploit DB Packet Storm
294342 - ibm spss_samplepower Multiple buffer overflows in the Vsflex8l ActiveX control in IBM SPSS SamplePower 3.0 before FP1 allow remote attackers to execute arbitrary code via a long (1) ComboList or (2) ColComboList property… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2012-5945 2024-11-21 10:45 2013-04-30 Show GitHub Exploit DB Packet Storm
294343 - google authenticator pam_google_authenticator.c in the PAM module in Google Authenticator before 1.0 requires user-readable permissions for the secret file, which allows local users to bypass intended access restrictions… CWE-200
Information Exposure
CVE-2012-6140 2024-11-21 10:45 2013-04-24 Show GitHub Exploit DB Packet Storm
294344 - ibm tririga_application_platform Multiple cross-site request forgery (CSRF) vulnerabilities in IBM TRIRIGA Application Platform 2.x and 3.x before 3.3, and 8, allow remote attackers to hijack the authentication of arbitrary users fo… CWE-352
 Origin Validation Error
CVE-2012-5950 2024-11-21 10:45 2013-04-23 Show GitHub Exploit DB Packet Storm
294345 - ibm tririga_application_platform Multiple cross-site scripting (XSS) vulnerabilities in IBM TRIRIGA Application Platform 2.x and 3.x before 3.3, and 8, allow remote attackers to inject content, and conduct phishing attacks, via vect… CWE-79
Cross-site Scripting
CVE-2012-5949 2024-11-21 10:45 2013-04-23 Show GitHub Exploit DB Packet Storm
294346 - ibm tririga_application_platform Multiple cross-site scripting (XSS) vulnerabilities in IBM TRIRIGA Application Platform 2.x and 3.x before 3.3, and 8, allow remote attackers to inject arbitrary web script or HTML via vectors involv… CWE-79
Cross-site Scripting
CVE-2012-5948 2024-11-21 10:45 2013-04-23 Show GitHub Exploit DB Packet Storm
294347 - apache activemq Multiple cross-site scripting (XSS) vulnerabilities in the web demos in Apache ActiveMQ before 5.8.0 allow remote attackers to inject arbitrary web script or HTML via (1) the refresh parameter to Por… CWE-79
Cross-site Scripting
CVE-2012-6092 2024-11-21 10:45 2013-04-22 Show GitHub Exploit DB Packet Storm
294348 - xmlsoft
opensuse
libxslt
opensuse
libxslt before 1.1.28 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an (1) empty match attribute in a XSL key to the xsltAddKey function in keys.c or (… NVD-CWE-Other
CVE-2012-6139 2024-11-21 10:45 2013-04-13 Show GitHub Exploit DB Packet Storm
294349 - ibm sterling_file_gateway
gentran_integration_suite
sterling_integrator
sterling_b2b_integrator
Unspecified vulnerability in the CLA2 server in IBM Gentran Integration Suite 4.3, Sterling Integrator 5.0 and 5.1, and Sterling B2B Integrator 5.2, as used in IBM Sterling File Gateway 1.1 through 2… NVD-CWE-noinfo
CVE-2012-5937 2024-11-21 10:45 2013-04-13 Show GitHub Exploit DB Packet Storm
294350 - redhat openstack_folsom
openstack_essex
Red Hat OpenStack Essex and Folsom creates the /var/log/puppet directory with world-readable permissions, which allows local users to obtain sensitive information such as Puppet log files. CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-6120 2024-11-21 10:45 2013-04-11 Show GitHub Exploit DB Packet Storm