Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 19, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
224551 4.3 警告 Mozilla Foundation - Android 上の Mozilla Firefox における Firefox のアドオンを変更される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-0798 2013-06-13 15:33 2013-04-2 Show GitHub Exploit DB Packet Storm
224552 6.8 警告 アップル - Apple Mac OS X の IOAcceleratorFamily における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2013-0976 2013-06-13 15:06 2013-03-15 Show GitHub Exploit DB Packet Storm
224553 10 危険 Mozilla Foundation - Android 上で稼働する Mozilla Firefox のブラウザエンジンにおけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2013-0790 2013-06-13 14:57 2013-04-2 Show GitHub Exploit DB Packet Storm
224554 6.2 警告 Linux - Linux Kernel の arch/x86/kernel/msr.c におけるケイパビリティの制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-0268 2013-06-12 17:43 2013-02-3 Show GitHub Exploit DB Packet Storm
224555 4.3 警告 Dave Thomas
Ruby-lang.org
- Ruby で使用される RDoc の darkfish.js におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-0256 2013-06-12 17:40 2013-02-6 Show GitHub Exploit DB Packet Storm
224556 10 危険 オラクル - Oracle Java SE の JavaFX における脆弱性 CWE-noinfo
情報不足
CVE-2013-0439 2013-06-12 17:28 2013-02-1 Show GitHub Exploit DB Packet Storm
224557 5 警告 Apache Software Foundation - Apache CXF における認証を回避される脆弱性 CWE-287
不適切な認証
CVE-2013-0239 2013-06-12 16:56 2013-01-25 Show GitHub Exploit DB Packet Storm
224558 1.9 注意 Linux - Linux Kernel の net/bluetooth/hidp/core.c における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2013-0349 2013-06-12 16:42 2013-02-3 Show GitHub Exploit DB Packet Storm
224559 6.2 警告 Linux - 32-bit Xen paravirt_ops プラットフォーム上で稼働する Linux Kernel における権限を取得される脆弱性 CWE-189
数値処理の問題
CVE-2013-0228 2013-06-12 16:41 2013-02-17 Show GitHub Exploit DB Packet Storm
224560 6 警告 OpenStack
Canonical
- 複数の OpenStack 製品における VM へのアクセス権を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-0335 2013-06-12 16:39 2013-02-16 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 19, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
278851 - sap businessobjects SAP BusinessObjects Edge 4.1 allows remote attackers to obtain the SI_PLATFORM_SEARCH_SERVER_LOGON_TOKEN token and gain privileges via a crafted CORBA call, aka SAP Note 2039905. CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-9387 2024-11-21 11:20 2014-12-18 Show GitHub Exploit DB Packet Storm
278852 - dokuwiki
mageia
dokuwiki
mageia
The default file type whitelist configuration in conf/mime.conf in the Media Manager in DokuWiki before 2014-09-29b allows remote attackers to execute arbitrary web script or HTML by uploading an SWF… CWE-79
Cross-site Scripting
CVE-2014-9253 2024-11-21 11:20 2014-12-18 Show GitHub Exploit DB Packet Storm
278853 7.8 HIGH
Local
linux
redhat
canonical
opensuse
suse
google
linux_kernel
enterprise_linux_eus
ubuntu_linux
evergreen
suse_linux_enterprise_server
android
arch/x86/kernel/entry_64.S in the Linux kernel before 3.17.5 does not properly handle faults associated with the Stack Segment (SS) segment register, which allows local users to gain privileges by tr… CWE-269
 Improper Privilege Management
CVE-2014-9322 2024-11-21 11:20 2014-12-17 Show GitHub Exploit DB Packet Storm
278854 - manageengine netflow_analyzer Directory traversal vulnerability in the CollectorConfInfoServlet servlet in ManageEngine NetFlow Analyzer allows remote attackers to execute arbitrary code via a .. (dot dot) in the filename. CWE-22
Path Traversal
CVE-2014-9373 2024-11-21 11:20 2014-12-17 Show GitHub Exploit DB Packet Storm
278855 - manageengine password_manager_pro Directory traversal vulnerability in the UploadAccountActivities servlet in ManageEngine Password Manager Pro (PMP) before 7103 allows remote attackers to delete arbitrary files via a .. (dot dot) in… CWE-22
Path Traversal
CVE-2014-9372 2024-11-21 11:20 2014-12-17 Show GitHub Exploit DB Packet Storm
278856 - zohocorp manageengine_desktop_central The NativeAppServlet in ManageEngine Desktop Central MSP before 90075 allows remote attackers to execute arbitrary code via a crafted JSON object. CWE-20
 Improper Input Validation 
CVE-2014-9371 2024-11-21 11:20 2014-12-17 Show GitHub Exploit DB Packet Storm
278857 - docker docker Docker before 1.3.3 does not properly validate image IDs, which allows remote attackers to conduct path traversal attacks and spoof repositories via a crafted image in a (1) "docker load" operation o… CWE-20
 Improper Input Validation 
CVE-2014-9358 2024-11-21 11:20 2014-12-17 Show GitHub Exploit DB Packet Storm
278858 - docker docker Docker 1.3.2 allows remote attackers to execute arbitrary code with root privileges via a crafted (1) image or (2) build in a Dockerfile in an LZMA (.xz) archive, related to the chroot for archive ex… CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-9357 2024-11-21 11:20 2014-12-17 Show GitHub Exploit DB Packet Storm
278859 - firebirdsql
opensuse
debian
canonical
firebird
evergreen
debian_linux
ubuntu_linux
The xdr_status_vector function in Firebird before 2.1.7 and 2.5.x before 2.5.3 SU1 allows remote attackers to cause a denial of service (NULL pointer dereference, segmentation fault, and crash) via a… CWE-476
 NULL Pointer Dereference
CVE-2014-9323 2024-11-21 11:20 2014-12-17 Show GitHub Exploit DB Packet Storm
278860 - debian
sixapart
debian_linux
movable_type
SQL injection vulnerability in the XML-RPC interface in Movable Type before 5.18, 5.2.x before 5.2.11, and 6.x before 6.0.6 allows remote attackers to execute arbitrary SQL commands via unspecified v… CWE-89
SQL Injection
CVE-2014-9057 2024-11-21 11:20 2014-12-17 Show GitHub Exploit DB Packet Storm