Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":July 1, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
222291 7.5 危険 The Cacti Group - Cacti の graph settings スクリプトにおける任意のコマンドを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2014-5261 2014-08-25 15:33 2014-06-28 Show GitHub Exploit DB Packet Storm
222292 5.8 警告 Esri - ESRI ArcGIS for Server におけるオープンリダイレクトの脆弱性 CWE-Other
その他
CVE-2014-5122 2014-08-25 15:06 2014-08-15 Show GitHub Exploit DB Packet Storm
222293 4.3 警告 Esri - ESRI ArcGIS for Server におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-5121 2014-08-25 15:06 2014-08-15 Show GitHub Exploit DB Packet Storm
222294 7.5 危険 Free Reprintables - Free Reprintables ArticleFR における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2014-5097 2014-08-25 14:55 2014-08-20 Show GitHub Exploit DB Packet Storm
222295 7.5 危険 BSS Company - Bank Soft Systems RBS BS-Client における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2014-4197 2014-08-25 14:55 2014-07-1 Show GitHub Exploit DB Packet Storm
222296 5 警告 shopizer-ecommerce - Shopizer の com/salesmanager/central/profile/ProfileAction.java におけるパスワードを推測される脆弱性 CWE-287
不適切な認証
CVE-2014-5385 2014-08-25 14:55 2014-07-10 Show GitHub Exploit DB Packet Storm
222297 3.5 注意 The phpMyAdmin Project - phpMyAdmin のビュー操作ページにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-5274 2014-08-25 14:54 2014-08-17 Show GitHub Exploit DB Packet Storm
222298 3.5 注意 The phpMyAdmin Project - phpMyAdmin におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-5273 2014-08-25 14:54 2014-08-17 Show GitHub Exploit DB Packet Storm
222299 4.3 警告 Ben Gillbanks - 複数の製品で使用される TimThumb の timthumb.php の displayError 関数におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-5303 2014-08-25 13:39 2010-09-8 Show GitHub Exploit DB Packet Storm
222300 4.3 警告 Ben Gillbanks - 複数の製品で使用される TimThumb の timthumb.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-5302 2014-08-25 12:30 2010-09-8 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:July 1, 2026, 4:27 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
273821 8.8 HIGH
Network
nuuo
netgear
nvrmini_2
readynas_surveillance
cgi-bin/cgi_main in NUUO NVRmini 2 1.7.6 through 3.0.0 and NETGEAR ReadyNAS Surveillance 1.1.2 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the sn param… CWE-78
OS Command 
CVE-2016-5679 2024-11-21 11:54 2016-09-1 Show GitHub Exploit DB Packet Storm
273822 9.8 CRITICAL
Network
nuuo nvrmini_2
nvrsolo
NUUO NVRmini 2 1.0.0 through 3.0.0 and NUUO NVRsolo 1.0.0 through 3.0.0 have hardcoded root credentials, which allows remote attackers to obtain administrative access via unspecified vectors. CWE-798
 Use of Hard-coded Credentials
CVE-2016-5678 2024-11-21 11:54 2016-09-1 Show GitHub Exploit DB Packet Storm
273823 7.5 HIGH
Network
netgear
nuuo
readynas_surveillance
nvrmini_2
nvrsolo
NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 have a hardcoded qwe23622260 password for the nuuoeng account, which allows… CWE-200
Information Exposure
CVE-2016-5677 2024-11-21 11:54 2016-09-1 Show GitHub Exploit DB Packet Storm
273824 7.5 HIGH
Network
netgear
nuuo
readynas_surveillance
nvrsolo
nvrmini_2
cgi-bin/cgi_system in NUUO NVRmini 2 1.7.5 through 2.x, NUUO NVRsolo 1.7.5 through 2.x, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to reset the administrator passwo… CWE-285
Improper Authorization
CVE-2016-5676 2024-11-21 11:54 2016-09-1 Show GitHub Exploit DB Packet Storm
273825 9.8 CRITICAL
Network
netgear
nuuo
readynas_surveillance
crystal
nvrsolo
nvrmini_2
handle_daylightsaving.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, NUUO Crystal 2.2.1 through 3.2.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remot… CWE-20
 Improper Input Validation 
CVE-2016-5675 2024-11-21 11:54 2016-09-1 Show GitHub Exploit DB Packet Storm
273826 9.8 CRITICAL
Network
netgear
nuuo
readynas_surveillance
nvrmini_2
nvrsolo
__debugging_center_utils___.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.7.5 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to execute arbit… CWE-20
 Improper Input Validation 
CVE-2016-5674 2024-11-21 11:54 2016-09-1 Show GitHub Exploit DB Packet Storm
273827 9.8 CRITICAL
Network
vmware vrealize_automation VMware vRealize Automation 7.0.x before 7.1 allows remote attackers to execute arbitrary code via unspecified vectors. NVD-CWE-noinfo
CVE-2016-5336 2024-11-21 11:54 2016-08-31 Show GitHub Exploit DB Packet Storm
273828 7.8 HIGH
Local
vmware identity_manager
vrealize_automation
VMware Identity Manager 2.x before 2.7 and vRealize Automation 7.0.x before 7.1 allow local users to obtain root access via unspecified vectors. NVD-CWE-noinfo
CVE-2016-5335 2024-11-21 11:54 2016-08-31 Show GitHub Exploit DB Packet Storm
273829 9.8 CRITICAL
Network
vmware photon_os VMware Photos OS OVA 1.0 before 2016-08-14 has a default SSH public key in an authorized_keys file, which allows remote attackers to obtain SSH access by leveraging knowledge of the private key. CWE-798
 Use of Hard-coded Credentials
CVE-2016-5333 2024-11-21 11:54 2016-08-31 Show GitHub Exploit DB Packet Storm
273830 5.3 MEDIUM
Network
vmware vrealize_log_insight Directory traversal vulnerability in VMware vRealize Log Insight 2.x and 3.x before 3.6.0 allows remote attackers to read arbitrary files via unspecified vectors. CWE-22
Path Traversal
CVE-2016-5332 2024-11-21 11:54 2016-08-31 Show GitHub Exploit DB Packet Storm