Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 1, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
219951 7.5 危険 シトリックス・システムズ - Citrix NetScaler Application Delivery Controller および NetScaler Gateway の管理 GUI の Java アプレットにおける脆弱性 CWE-noinfo
情報不足
CVE-2014-2881 2014-05-2 16:34 2014-04-28 Show GitHub Exploit DB Packet Storm
219952 6.5 警告 フォーティネット - FortiGuard FortiWeb における権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-1957 2014-05-2 16:33 2014-02-13 Show GitHub Exploit DB Packet Storm
219953 7.5 危険 フォーティネット - FortiGuard FortiWeb における CRLF インジェクションの脆弱性 CWE-Other
その他
CVE-2014-1956 2014-05-2 16:32 2014-02-13 Show GitHub Exploit DB Packet Storm
219954 4.3 警告 フォーティネット - FortiGuard FortiWeb におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-1955 2014-05-2 16:30 2014-02-13 Show GitHub Exploit DB Packet Storm
219955 4.3 警告 vBulletin Solutions, Inc. - vBulletin におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-3135 2014-05-2 16:11 2014-04-18 Show GitHub Exploit DB Packet Storm
219956 5 警告 Ecava - Ecava IntegraXor における管理者アカウントの平文の資格情報を読まれる脆弱性 CWE-310
暗号の問題
CVE-2014-0786 2014-05-2 15:51 2014-02-21 Show GitHub Exploit DB Packet Storm
219957 4.6 警告 Canonical - Ubuntu Date and Time Indicator におけるグリーター画面の制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-7374 2014-05-2 15:50 2013-11-27 Show GitHub Exploit DB Packet Storm
219958 4.3 警告 SAP - SAP BusinessObjects の InfoView アプリケーションにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-3134 2014-05-2 15:43 2014-04-28 Show GitHub Exploit DB Packet Storm
219959 5 警告 SAP - SAP Netweaver Java Application Server における SLD に登録されている SAP システムのリストを取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-3133 2014-05-2 15:37 2014-04-28 Show GitHub Exploit DB Packet Storm
219960 4 警告 SAP - SAP Background Processing における重要な情報を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-3132 2014-05-2 15:32 2014-04-28 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 1, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
296331 - apache
paypal
axis
mass_pay
transactional_information_soap
payments_pro
activemq
Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service implementation in Apache ActiveMQ, and other products, do… CWE-20
 Improper Input Validation 
CVE-2012-5784 2024-11-21 10:45 2012-11-5 Show GitHub Exploit DB Packet Storm
296332 - apache
canonical
httpclient
ubuntu_linux
Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain name in the subject's … CWE-295
Improper Certificate Validation 
CVE-2012-5783 2024-11-21 10:45 2012-11-5 Show GitHub Exploit DB Packet Storm
296333 - amazon flexible_payments_service Amazon Flexible Payments Service (FPS) PHP Library does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, w… CWE-20
 Improper Input Validation 
CVE-2012-5782 2024-11-21 10:45 2012-11-5 Show GitHub Exploit DB Packet Storm
296334 - amazon elastic_load_balancing Amazon Elastic Load Balancing API Tools does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows… CWE-20
 Improper Input Validation 
CVE-2012-5781 2024-11-21 10:45 2012-11-5 Show GitHub Exploit DB Packet Storm
296335 - amazon merchant_sdk The Amazon merchant SDK does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-midd… CWE-20
 Improper Input Validation 
CVE-2012-5780 2024-11-21 10:45 2012-11-5 Show GitHub Exploit DB Packet Storm
296336 - justin_dodge hotblocks Cross-site scripting (XSS) vulnerability in the settings page (admin/settings/hotblocks) in the Hotblocks module 6.x-1.x before 6.x-1.8 for Drupal allows remote authenticated users with the "administ… CWE-79
Cross-site Scripting
CVE-2012-5705 2024-11-21 10:45 2012-11-1 Show GitHub Exploit DB Packet Storm
296337 - justin_dodge hotblocks The Hotblocks module 6.x-1.x before 6.x-1.8 for Drupal allows remote authenticated users with the "administer hotblocks" permission to cause a denial of service (infinite loop and time out) via a blo… CWE-399
 Resource Management Errors
CVE-2012-5704 2024-11-21 10:45 2012-11-1 Show GitHub Exploit DB Packet Storm
296338 - tp-link tl-wr841n
tl-wr841n_firmware
Directory traversal vulnerability in the web-based management feature on the TP-LINK TL-WR841N router with firmware 3.13.9 build 120201 Rel.54965n and earlier allows remote attackers to read arbitrar… CWE-22
Path Traversal
CVE-2012-5687 2024-11-21 10:45 2012-11-1 Show GitHub Exploit DB Packet Storm
296339 - exim exim Heap-based buffer overflow in the dkim_exim_query_dns_txt function in dkim.c in Exim 4.70 through 4.80, when DKIM support is enabled and acl_smtp_connect and acl_smtp_rcpt are not set to "warn contro… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2012-5671 2024-11-21 10:45 2012-11-1 Show GitHub Exploit DB Packet Storm
296340 - invisionpower
invisioncommunity
invision_power_board Unspecified vulnerability in admin/sources/base/core.php in Invision Power Board (aka IPB or IP.Board) 3.1.x through 3.3.x has unknown impact and remote attack vectors. NVD-CWE-noinfo
CVE-2012-5692 2024-11-21 10:45 2012-10-31 Show GitHub Exploit DB Packet Storm