Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 17, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
220051 2.1 注意 アップル - Apple iOS の Address Book における重要な情報を取得される脆弱性 CWE-310
暗号の問題
CVE-2014-4352 2014-09-19 18:20 2014-09-17 Show GitHub Exploit DB Packet Storm
220052 8.3 危険 (複数のベンダ) - 複数の Android アプリに SSL 証明書を適切に検証しない脆弱性 - - 2014-09-19 18:04 2014-09-3 Show GitHub Exploit DB Packet Storm
220053 6.5 警告 Spiceworks Inc. - SpiceWorks における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2012-2956 2014-09-19 17:46 2012-07-23 Show GitHub Exploit DB Packet Storm
220054 4.3 警告 Spiceworks Inc. - SpiceWorks におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-6658 2014-09-19 17:45 2012-07-23 Show GitHub Exploit DB Packet Storm
220055 6.8 警告 nongnu - GKSu における任意のコマンドを実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-2886 2014-09-19 16:49 2014-09-18 Show GitHub Exploit DB Packet Storm
220056 4.3 警告 Open-Xchange - Open-Xchange AppSuite のfrontend におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-5235 2014-09-19 16:40 2014-08-25 Show GitHub Exploit DB Packet Storm
220057 4.3 警告 Open-Xchange - Open-Xchange AppSuite の backend におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-5234 2014-09-19 16:36 2014-08-25 Show GitHub Exploit DB Packet Storm
220058 4.3 警告 Marcel Bokhorst - WordPress 用 Mini Mail Dashboard Widget プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-2583 2014-09-19 16:35 2012-08-8 Show GitHub Exploit DB Packet Storm
220059 4.3 警告 OrangeHRM - OrangeHRM におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-1507 2014-09-19 16:33 2012-04-24 Show GitHub Exploit DB Packet Storm
220060 6.5 警告 OrangeHRM - OrangeHRM の lib/models/benefits/Hsp.php の updateStatus 関数における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2012-1506 2014-09-19 16:32 2012-04-24 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 18, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
290791 - ibm security_access_manager_for_web_8.0_firmware
security_access_manager_for_web_appliance
security_access_manager_for_mobile_software
security_access_manager_for_web_software
security_access…
The Local Management Interface (LMI) in IBM Security Access Manager (ISAM) for Mobile 8.0 with firmware 8.0.0.0 through 8.0.0.3 and IBM Security Access Manager for Web 7.0, and 8.0 with firmware 8.0.… CWE-287
Improper Authentication
CVE-2014-3053 2024-11-21 11:07 2014-06-22 Show GitHub Exploit DB Packet Storm
290792 - ibm security_access_manager_for_web_8.0_firmware
security_access_manager_for_web_appliance
The reverse-proxy feature in IBM Security Access Manager (ISAM) for Web 8.0 with firmware 8.0.0.2 and 8.0.0.3 interprets the jct-nist-compliance parameter in the opposite of the intended manner, whic… CWE-16
Configuration
CVE-2014-3052 2024-11-21 11:07 2014-06-22 Show GitHub Exploit DB Packet Storm
290793 - belkin n150_f9k1009_firmware
n150_f9k1009
Absolute path traversal vulnerability in the webproc cgi module on the Belkin N150 F9K1009 v1 router with firmware before 1.00.08 allows remote attackers to read arbitrary files via a full pathname i… CWE-22
Path Traversal
CVE-2014-2962 2024-11-21 11:07 2014-06-19 Show GitHub Exploit DB Packet Storm
290794 - ibm curam_social_program_management Multiple cross-site scripting (XSS) vulnerabilities in IBM Curam Social Program Management 4.5 SP10 through 6.0.5.4 allow remote authenticated users to inject arbitrary web script or HTML via crafted… CWE-79
Cross-site Scripting
CVE-2014-3013 2024-11-21 11:07 2014-06-19 Show GitHub Exploit DB Packet Storm
290795 - ibm curam_social_program_management Multiple CRLF injection vulnerabilities in IBM Curam Social Program Management 5.2 SP1 through 6.0.5.4 allow remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response spli… NVD-CWE-Other
CVE-2014-3012 2024-11-21 11:07 2014-06-19 Show GitHub Exploit DB Packet Storm
290796 - f5 arx_data_manager SQL injection vulnerability in the web service in F5 ARX Data Manager 3.0.0 through 3.1.0 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. CWE-89
SQL Injection
CVE-2014-2949 2024-11-21 11:07 2014-06-19 Show GitHub Exploit DB Packet Storm
290797 - puppet puppet_enterprise Puppet Enterprise 2.8.x before 2.8.7 allows remote attackers to obtain sensitive information via vectors involving hiding and unhiding nodes. CWE-200
Information Exposure
CVE-2014-3249 2024-11-21 11:07 2014-06-17 Show GitHub Exploit DB Packet Storm
290798 - cisco ios_xe The mDNS implementation in Cisco IOS XE 3.12S does not properly interact with autonomic networking, which allows remote attackers to obtain sensitive networking-services information by sniffing the n… CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-3290 2024-11-21 11:07 2014-06-14 Show GitHub Exploit DB Packet Storm
290799 - cisco nx-os The HSRP implementation in Cisco NX-OS 6.2(2a) and earlier allows remote attackers to bypass authentication and cause a denial of service (group-member state modification and traffic blackholing) via… CWE-287
Improper Authentication
CVE-2014-3295 2024-11-21 11:07 2014-06-14 Show GitHub Exploit DB Packet Storm
290800 - castor_project
opensuse_project
opensuse
castor
opensuse
The default configuration for the Xerces SAX Parser in Castor before 1.3.3 allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XML document. CWE-611
XXE
CVE-2014-3004 2024-11-21 11:07 2014-06-11 Show GitHub Exploit DB Packet Storm