Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 21, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
221201 6.8 警告 Thomson - Thomson TWG87OUIR におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2014-4716 2014-07-8 14:42 2014-06-25 Show GitHub Exploit DB Packet Storm
221202 7.5 危険 NetIQ - NetIQ Security Manager の NQMcsVarSet ActiveX コントロールの DumpToFile メソッドにおけるディレクトリトラバーサルの脆弱性 CWE-94
コード・インジェクション
CVE-2014-0602 2014-07-8 14:40 2014-07-1 Show GitHub Exploit DB Packet Storm
221203 4.3 警告 Another Awesome Stuff - ZeroCMS の zero_view_article.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-4195 2014-07-8 14:18 2014-06-20 Show GitHub Exploit DB Packet Storm
221204 4.3 警告 The Cacti Group - Cacti におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-4002 2014-07-8 14:10 2014-06-15 Show GitHub Exploit DB Packet Storm
221205 6.8 警告 Frederic Guillot - Kanboard におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2014-3920 2014-07-8 14:06 2014-06-30 Show GitHub Exploit DB Packet Storm
221206 6.5 警告 Kerio Technologies - Kerio Control の Kerio Control Statistics における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2014-3857 2014-07-8 14:01 2014-06-30 Show GitHub Exploit DB Packet Storm
221207 4.3 警告 Invision Power Services, Inc - Invision Power IP.Board または IP.Nexus におけるクロスサイトスクリプティングの脆弱性 "Reflected Cross-Site Scripting (XSS)" (CWE-79) vulnerability in "Invision Power IP.Board" product
CWE-79
CVE-2014-3149 2014-07-8 13:40 2014-04-24 Show GitHub Exploit DB Packet Storm
221208 9.3 危険 マイクロソフト - Microsoft Internet Explorer 9 における任意のコードを実行される脆弱性 CWE-Other
その他
CVE-2014-0325 2014-07-8 12:32 2014-04-8 Show GitHub Exploit DB Packet Storm
221209 5 警告 サイレックス・テクノロジー株式会社 - SX-2000WG におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2014-3890 2014-07-7 18:35 2014-07-2 Show GitHub Exploit DB Packet Storm
221210 5 警告 サイレックス・テクノロジー株式会社 - SX-2000WG におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2014-3889 2014-07-7 18:34 2014-07-2 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 21, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
273671 6.5 MEDIUM
Network
openafs
debian
openafs
debian_linux
The newEntry function in ptserver/ptprocs.c in OpenAFS before 1.6.17 allows remote authenticated users from foreign Kerberos realms to bypass intended access restrictions and create arbitrary groups … CWE-284
Improper Access Control
CVE-2016-2860 2024-11-21 11:48 2016-05-14 Show GitHub Exploit DB Packet Storm
273672 7.5 HIGH
Network
fedoraproject
botan_project
fedora
botan
Botan 1.11.x before 1.11.29 does not enforce TLS policy for (1) signature algorithms and (2) ECC curves, which allows remote attackers to conduct downgrade attacks via unspecified vectors. CWE-20
 Improper Input Validation 
CVE-2016-2850 2024-11-21 11:48 2016-05-13 Show GitHub Exploit DB Packet Storm
273673 7.5 HIGH
Network
debian
fedoraproject
botan_project
debian_linux
fedora
botan
Botan before 1.10.13 and 1.11.x before 1.11.29 do not use a constant-time algorithm to perform a modular inverse on the signature nonce k, which might allow remote attackers to obtain ECDSA secret ke… CWE-200
Information Exposure
CVE-2016-2849 2024-11-21 11:48 2016-05-13 Show GitHub Exploit DB Packet Storm
273674 9.8 CRITICAL
Network
botan_project botan Heap-based buffer overflow in the P-521 reduction function in Botan 1.11.x before 1.11.27 allows remote attackers to cause a denial of service (memory overwrite and crash) or execute arbitrary code v… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2016-2196 2024-11-21 11:48 2016-05-13 Show GitHub Exploit DB Packet Storm
273675 9.8 CRITICAL
Network
botan_project
debian
botan
debian_linux
Integer overflow in the PointGFp constructor in Botan before 1.10.11 and 1.11.x before 1.11.27 allows remote attackers to overwrite memory and possibly execute arbitrary code via a crafted ECC point,… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2016-2195 2024-11-21 11:48 2016-05-13 Show GitHub Exploit DB Packet Storm
273676 7.5 HIGH
Network
debian
botan_project
debian_linux
botan
The ressol function in Botan before 1.10.11 and 1.11.x before 1.11.27 allows remote attackers to cause a denial of service (infinite loop) via unspecified input to the OS2ECP function, related to a c… CWE-20
 Improper Input Validation 
CVE-2016-2194 2024-11-21 11:48 2016-05-13 Show GitHub Exploit DB Packet Storm
273677 7.0 HIGH
Local
google android OpenSSLCipher.java in Conscrypt in Android 6.x before 2016-05-01 mishandles updates of the Additional Authenticated Data (AAD) array, which allows attackers to spoof message authentication via unspec… CWE-264
Permissions, Privileges, and Access Controls
CVE-2016-2462 2024-11-21 11:48 2016-05-9 Show GitHub Exploit DB Packet Storm
273678 7.0 HIGH
Local
google android OpenSSLCipher.java in Conscrypt in Android 6.x before 2016-05-01 mishandles resets of the Additional Authenticated Data (AAD) array, which allows attackers to spoof message authentication via unspeci… CWE-264
Permissions, Privileges, and Access Controls
CVE-2016-2461 2024-11-21 11:48 2016-05-9 Show GitHub Exploit DB Packet Storm
273679 5.5 MEDIUM
Local
google android mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not initialize certain data structures, which allows attackers to obtain sensitive info… CWE-200
Information Exposure
CVE-2016-2460 2024-11-21 11:48 2016-05-9 Show GitHub Exploit DB Packet Storm
273680 5.5 MEDIUM
Local
google android mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not initialize certain data structures, which allows attackers to obtain sensitive info… CWE-200
Information Exposure
CVE-2016-2459 2024-11-21 11:48 2016-05-9 Show GitHub Exploit DB Packet Storm