Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 31, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
222171 2.4 注意 オラクル - Oracle Virtualization の Oracle VM VirtualBox における Core に関する脆弱性 CWE-noinfo
情報不足
CVE-2014-0406 2014-01-17 14:53 2014-01-14 Show GitHub Exploit DB Packet Storm
222172 3.5 注意 オラクル - Oracle Virtualization の Oracle VM VirtualBox における Core に関する脆弱性 CWE-noinfo
情報不足
CVE-2014-0405 2014-01-17 14:53 2014-01-14 Show GitHub Exploit DB Packet Storm
222173 2.4 注意 オラクル - Oracle Virtualization の Oracle VM VirtualBox における Core に関する脆弱性 CWE-noinfo
情報不足
CVE-2014-0404 2014-01-17 14:53 2014-01-14 Show GitHub Exploit DB Packet Storm
222174 3.5 注意 オラクル - Oracle Virtualization の Oracle VM VirtualBox における Core に関する脆弱性 CWE-noinfo
情報不足
CVE-2013-5892 2014-01-17 14:53 2014-01-14 Show GitHub Exploit DB Packet Storm
222175 9.3 危険 アドビシステムズ - Adobe Reader におけるサービス運用妨害 (アプリケーションクラッシュ) の脆弱性 CWE-noinfo
情報不足
CVE-2012-4363 2014-01-17 12:29 2012-08-21 Show GitHub Exploit DB Packet Storm
222176 5 警告 オラクル - Oracle E-Business Suite の Oracle Application Object Library における Discoverer に関する脆弱性 CWE-noinfo
情報不足
CVE-2014-0398 2014-01-17 12:13 2014-01-14 Show GitHub Exploit DB Packet Storm
222177 5.5 警告 オラクル - Oracle E-Business Suite の Oracle Payroll における Exception Reporting に関する脆弱性 CWE-noinfo
情報不足
CVE-2013-5890 2014-01-17 12:12 2014-01-14 Show GitHub Exploit DB Packet Storm
222178 1.7 注意 オラクル - Oracle E-Business Suite の Oracle Application Object Library における Logging に関する脆弱性 CWE-noinfo
情報不足
CVE-2013-5874 2014-01-17 12:11 2014-01-14 Show GitHub Exploit DB Packet Storm
222179 5 警告 オラクル - Oracle Fusion Middleware の Oracle WebCenter Portal における Page Service に関する脆弱性 CWE-noinfo
情報不足
CVE-2013-5869 2014-01-17 12:07 2014-01-14 Show GitHub Exploit DB Packet Storm
222180 2.6 注意 オラクル - Oracle Fusion Middleware の Oracle iPlanet Web Proxy Server における Administration に関する脆弱性 CWE-noinfo
情報不足
CVE-2013-5808 2014-01-17 12:06 2014-01-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 31, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
273631 7.5 HIGH
Network
mybb mybb
merge_system
MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allow remote attackers to obtain the installation path via vectors involving error log files. CWE-532
 Inclusion of Sensitive Information in Log Files
CVE-2015-8977 2024-11-21 11:39 2017-02-1 Show GitHub Exploit DB Packet Storm
273632 6.1 MEDIUM
Network
mybb mybb
merge_system
Cross-site scripting (XSS) vulnerability in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 might allow remote attackers to inject arbitrary web scr… CWE-79
Cross-site Scripting
CVE-2015-8976 2024-11-21 11:39 2017-02-1 Show GitHub Exploit DB Packet Storm
273633 6.1 MEDIUM
Network
mybb mybb
merge_system
Cross-site scripting (XSS) vulnerability in the error handler in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 might allow remote attackers to inj… CWE-79
Cross-site Scripting
CVE-2015-8975 2024-11-21 11:39 2017-02-1 Show GitHub Exploit DB Packet Storm
273634 10.0 CRITICAL
Network
mybb mybb
merge_system
SQL injection vulnerability in the Group Promotions module in the admin control panel in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allows remo… CWE-89
SQL Injection
CVE-2015-8974 2024-11-21 11:39 2017-02-1 Show GitHub Exploit DB Packet Storm
273635 8.3 HIGH
Network
mybb mybb
merge_system
xmlhttp.php in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allows remote attackers to bypass intended access restrictions via vectors related to… CWE-284
Improper Access Control
CVE-2015-8973 2024-11-21 11:39 2017-02-1 Show GitHub Exploit DB Packet Storm
273636 9.8 CRITICAL
Network
gnu chess Stack-based buffer overflow in the ValidateMove function in frontend/move.cc in GNU Chess (aka gnuchess) before 6.2.4 might allow context-dependent attackers to execute arbitrary code via a large inp… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2015-8972 2024-11-21 11:39 2017-01-24 Show GitHub Exploit DB Packet Storm
273637 7.8 HIGH
Local
debian
enlightenment
debian_linux
terminology
Terminology 0.7.0 allows remote attackers to execute arbitrary commands via escape sequences that modify the window title and then are written to the terminal, a similar issue to CVE-2003-0063. CWE-77
Command Injection
CVE-2015-8971 2024-11-21 11:39 2017-01-24 Show GitHub Exploit DB Packet Storm
273638 6.1 MEDIUM
Network
mustache.js_project mustache.js mustache package before 2.2.1 for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging a template with an attribute that is not quoted. CWE-79
Cross-site Scripting
CVE-2015-8862 2024-11-21 11:39 2017-01-24 Show GitHub Exploit DB Packet Storm
273639 6.1 MEDIUM
Network
handlebars.js_project handlebars.js The handlebars package before 4.0.0 for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging a template with an attribute that is not quoted. CWE-79
Cross-site Scripting
CVE-2015-8861 2024-11-21 11:39 2017-01-24 Show GitHub Exploit DB Packet Storm
273640 7.5 HIGH
Network
nodejs node.js The tar package before 2.0.0 for Node.js allows remote attackers to write to arbitrary files via a symlink attack in an archive. CWE-59
Link Following
CVE-2015-8860 2024-11-21 11:39 2017-01-24 Show GitHub Exploit DB Packet Storm