Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 6, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
220071 4 警告 TYPO3 Association - TYPO3 の Backend History モジュールにおける任意のレコードの履歴を読まれる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-6146 2014-05-22 15:18 2012-11-8 Show GitHub Exploit DB Packet Storm
220072 7.5 危険 Construtiva Internet Software - Construtiva CIS Manager における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2014-3749 2014-05-22 15:13 2014-05-16 Show GitHub Exploit DB Packet Storm
220073 6.8 警告 マイクロソフト - Microsoft Visual Studio で配布される Microsoft Debug Interface Access SDK おける任意のコードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2014-3802 2014-05-22 14:40 2014-05-14 Show GitHub Exploit DB Packet Storm
220074 6.8 警告 Beetel - Beetel 450TC2 ルータのファームウェアにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2014-3792 2014-05-22 14:35 2014-04-30 Show GitHub Exploit DB Packet Storm
220075 5.8 警告 Zenoss, Inc. - Zenoss の zport/acl_users/cookieAuthHelper/login_form におけるオープンリダイレクトの脆弱性 CWE-20
不適切な入力確認
CVE-2014-3739 2014-05-22 12:14 2014-05-14 Show GitHub Exploit DB Packet Storm
220076 4.3 警告 Zenoss, Inc. - Zenoss におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-3738 2014-05-22 12:13 2014-05-14 Show GitHub Exploit DB Packet Storm
220077 10 危険 ジュニパーネットワークス - Juniper Junos Space における任意のコマンドを実行される脆弱性 CWE-noinfo
情報不足
CVE-2014-3412 2014-05-22 11:48 2014-05-14 Show GitHub Exploit DB Packet Storm
220078 4.3 警告 Seo Panel - Seo Panel におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-1855 2014-05-22 11:32 2014-05-14 Show GitHub Exploit DB Packet Storm
220079 4.3 警告 日立 - Hitachi Web Server のステータス情報表示機能におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2006-5752
CVE-2007-5809
2014-05-21 18:27 2007-10-5 Show GitHub Exploit DB Packet Storm
220080 4.3 警告 IBM
Apache Software Foundation
富士通
サイバートラスト株式会社
サン・マイクロシステムズ
ターボリナックス
ヒューレット・パッカード
オラクル
日立
レッドハット
- Apache HTTP Server の mod_status モジュールにおけるクロスサイトスクリプティングの脆弱性 - CVE-2006-5752 2014-05-21 18:26 2007-06-26 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 7, 2026, 4:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
296501 - cob\'s_products cobime The COBIME application before 0.9.4 for Android uses weak permissions for unspecified files, which allows attackers to obtain sensitive information via an application that accesses the local filesyst… CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-0720 2024-11-21 10:48 2013-03-28 Show GitHub Exploit DB Packet Storm
296502 - codedesign artime_japanese_input The ArtIME Japanese Input application 1.1.2 and earlier for Android uses weak permissions for unspecified files, which allows attackers to obtain sensitive information via an application that accesse… CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-0719 2024-11-21 10:48 2013-03-28 Show GitHub Exploit DB Packet Storm
296503 - simeji simeji The Simeji application 4.8.1 and earlier for Android uses weak permissions for unspecified files, which allows attackers to obtain sensitive information via an application that accesses the local fil… CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-0718 2024-11-21 10:48 2013-03-28 Show GitHub Exploit DB Packet Storm
296504 - mailup wp-mailup ajax.functions.php in the MailUp plugin before 1.3.3 for WordPress does not properly restrict access to unspecified Ajax functions, which allows remote attackers to modify plugin settings and conduct… CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-0731 2024-11-21 10:48 2013-03-23 Show GitHub Exploit DB Packet Storm
296505 - linux linux_kernel The flush_signal_handlers function in kernel/signal.c in the Linux kernel before 3.8.4 preserves the value of the sa_restorer field across an exec operation, which makes it easier for local users to … CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-0914 2024-11-21 10:48 2013-03-22 Show GitHub Exploit DB Packet Storm
296506 - canonical ubuntu_linux pam-xdg-support, as used in Ubuntu 12.10, does not properly handle the PATH environment variable, which allows local users to gain privileges via unspecified vectors related to sudo. CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-1052 2024-11-21 10:48 2013-03-22 Show GitHub Exploit DB Packet Storm
296507 - debian
canonical
apt
advanced_package_tool
ubuntu_linux
apt 0.8.16, 0.9.7, and possibly other versions does not properly handle InRelease files, which allows man-in-the-middle attackers to modify packages before installation via unknown vectors, possibly … CWE-20
 Improper Input Validation 
CVE-2013-1051 2024-11-21 10:48 2013-03-22 Show GitHub Exploit DB Packet Storm
296508 - windriver vxworks The web server in Wind River VxWorks 5.5 through 6.9 allows remote attackers to cause a denial of service (daemon crash) via a crafted URI. CWE-20
 Improper Input Validation 
CVE-2013-0716 2024-11-21 10:48 2013-03-21 Show GitHub Exploit DB Packet Storm
296509 - windriver vxworks The WebCLI component in Wind River VxWorks 5.5 through 6.9 allows remote authenticated users to cause a denial of service (CLI session crash) via a crafted command string. CWE-20
 Improper Input Validation 
CVE-2013-0715 2024-11-21 10:48 2013-03-21 Show GitHub Exploit DB Packet Storm
296510 - windriver vxworks IPSSH (aka the SSH server) in Wind River VxWorks 6.5 through 6.9 allows remote attackers to execute arbitrary code or cause a denial of service (daemon hang) via a crafted public-key authentication r… CWE-20
 Improper Input Validation 
CVE-2013-0714 2024-11-21 10:48 2013-03-21 Show GitHub Exploit DB Packet Storm