Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 21, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
220521 2.1 注意 IBM - Windows および OS X 上で稼動する IBM Tivoli Storage Manager のバックアップ/アーカイブ・クライアントのプリファレンス・エディターおよび Java GUI 構成ウィザードにおけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2014-0876 2014-08-19 12:23 2014-08-12 Show GitHub Exploit DB Packet Storm
220522 4.3 警告 IBM - IBM GCM16 および GCM32 Global Console Manager スイッチのファームウェアにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-3080 2014-08-19 11:53 2014-07-14 Show GitHub Exploit DB Packet Storm
220523 5 警告 IBM - IBM InfoSphere Master Data Management - Collaborative Edition および InfoSphere Master Data Management Server for Product Information Management における重要な情報を取得される脆弱性 CWE-255
証明書・パスワード管理
CVE-2014-4775 2014-08-19 11:42 2014-08-12 Show GitHub Exploit DB Packet Storm
220524 6.8 警告 IBM - IBM InfoSphere Master Data Management - Collaborative Edition および InfoSphere Master Data Management Server for Product Information Management におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2014-0969 2014-08-19 11:40 2014-08-14 Show GitHub Exploit DB Packet Storm
220525 6.5 警告 IBM - IBM InfoSphere Master Data Management - Collaborative Edition および InfoSphere Master Data Management Server for Product Information Management における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2014-0966 2014-08-19 11:40 2014-08-14 Show GitHub Exploit DB Packet Storm
220526 9.3 危険 Iridium Communications - Iridium の衛星通信用端末上で稼動する Pilot Below Deck Equipment および OpenPort における任意のコードを実行される脆弱性 CWE-Other
その他
CVE-2014-0327 2014-08-19 11:25 2014-08-7 Show GitHub Exploit DB Packet Storm
220527 9.3 危険 Iridium Communications - Iridium の衛星通信用端末上で稼働する Pilot Below Deck Equipment および OpenPort の実装におけるハードコードされた認証情報を読まれる脆弱性 CWE-Other
その他
CVE-2014-0326 2014-08-19 11:25 2014-08-7 Show GitHub Exploit DB Packet Storm
220528 10 危険 Cobham plc - Cobham Sailor の衛星通信用端末に認証情報がハードコードされている問題 CWE-Other
その他
CVE-2014-2940 2014-08-18 18:03 2014-08-7 Show GitHub Exploit DB Packet Storm
220529 9.3 危険 Cobham plc - Cobham thraneLINK デバイスのファームウェアアップデート機能に脆弱性 CWE-Other
その他
CVE-2014-0328 2014-08-18 18:02 2014-08-7 Show GitHub Exploit DB Packet Storm
220530 7.8 危険 Cobham plc - Cobham SATCOM 製品のウェブインターフェースのパスワード復元メカニズムに脆弱性 CWE-Other
その他
CVE-2013-7180 2014-08-18 18:00 2014-08-7 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 21, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
294331 - hp service_manager Cross-site scripting (XSS) vulnerability in the Mobility Web Client and Service Request Catalog (SRC) components in HP Service Manager (SM) 7.21 and 9.x before 9.34 allows remote attackers to inject … CWE-79
Cross-site Scripting
CVE-2013-6222 2024-11-21 10:58 2014-08-24 Show GitHub Exploit DB Packet Storm
294332 - ibm power_760_firmware
power_770
power_780
power_795
power_ese
power_740_firmware
power_710
power_720
power_730
power_740
power_770_firmware
power_750
power_760
pow…
Unspecified vulnerability on IBM Power 7 Systems 740 before 740.70 01Ax740_121, 760 before 760.40 Ax760_078, and 770 before 770.30 01Ax770_062 allows local users to gain Service Processor privileges … NVD-CWE-noinfo
CVE-2013-6306 2024-11-21 10:58 2014-08-23 Show GitHub Exploit DB Packet Storm
294333 - yealink sip-t38g cgi-bin/cgiServer.exx in Yealink VoIP Phone SIP-T38G allows remote authenticated users to execute arbitrary commands by calling the system method in the body of a request, as demonstrated by running … CWE-78
OS Command 
CVE-2013-5758 2024-11-21 10:58 2014-08-4 Show GitHub Exploit DB Packet Storm
294334 - yealink sip-t38g Absolute path traversal vulnerability in Yealink VoIP Phone SIP-T38G allows remote authenticated users to read arbitrary files via a full pathname in the dumpConfigFile function in the command parame… CWE-22
Path Traversal
CVE-2013-5757 2024-11-21 10:58 2014-08-4 Show GitHub Exploit DB Packet Storm
294335 - yealink sip-t38g Directory traversal vulnerability in Yealink VoIP Phone SIP-T38G allows remote authenticated users to read arbitrary files via a .. (dot dot) in the page parameter to cgi-bin/cgiServer.exx. CWE-22
Path Traversal
CVE-2013-5756 2024-11-21 10:58 2014-08-4 Show GitHub Exploit DB Packet Storm
294336 - oracle mojarra Oracle Mojarra 2.2.x before 2.2.6 and 2.1.x before 2.1.28 does not perform appropriate encoding when a (1) <h:outputText> tag or (2) EL expression is used after a scriptor style block, which allows r… CWE-79
Cross-site Scripting
CVE-2013-5855 2024-11-21 10:58 2014-07-17 Show GitHub Exploit DB Packet Storm
294337 - yealink sip-t38g config/.htpasswd in Yealink IP Phone SIP-T38G has a hardcoded password of (1) user (s7C9Cx.rLsWFA) for the user account, (2) admin (uoCbM.VEiKQto) for the admin account, and (3) var (jhl3iZAe./qXM) f… CWE-255
Credentials Management
CVE-2013-5755 2024-11-21 10:58 2014-07-16 Show GitHub Exploit DB Packet Storm
294338 - dahuasecurity dvr_firmware Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive information including user credentials, change user passwords, clear log files, and perfo… CWE-287
Improper Authentication
CVE-2013-6117 2024-11-21 10:58 2014-07-12 Show GitHub Exploit DB Packet Storm
294339 - ibm marketing_platform SQL injection vulnerability in IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. CWE-89
SQL Injection
CVE-2013-6311 2024-11-21 10:58 2014-06-28 Show GitHub Exploit DB Packet Storm
294340 - ibm marketing_platform Cross-site scripting (XSS) vulnerability in IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. CWE-79
Cross-site Scripting
CVE-2013-6310 2024-11-21 10:58 2014-06-28 Show GitHub Exploit DB Packet Storm