Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 20, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
224641 6.8 警告 WordPress.org - WordPress 用 WP Maintenance Mode プラグインにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2013-3250 2013-06-25 14:15 2013-06-5 Show GitHub Exploit DB Packet Storm
224642 4.3 警告 Suksit Sripitchayaphan - Drupal 用 Inf08 テーマの template.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-6572 2013-06-25 13:54 2012-09-12 Show GitHub Exploit DB Packet Storm
224643 4.3 警告 シスコシステムズ - Cisco WebEx Social におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2013-3392 2013-06-25 13:44 2013-06-21 Show GitHub Exploit DB Packet Storm
224644 8.3 危険 シスコシステムズ - Cisco TelePresence TC Software におけるルート権限のシェルアクセスを取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-3379 2013-06-24 18:32 2013-06-19 Show GitHub Exploit DB Packet Storm
224645 7.8 危険 シスコシステムズ - Cisco TelePresence TC Software および TE Software におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2013-3378 2013-06-24 18:16 2013-06-19 Show GitHub Exploit DB Packet Storm
224646 7.8 危険 シスコシステムズ - Cisco TelePresence TC Software および TE Software におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2013-3377 2013-06-24 18:08 2013-06-19 Show GitHub Exploit DB Packet Storm
224647 9 危険 Huawei - Huawei Seco Versatile Security Manager における権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-4633 2013-06-24 16:58 2013-04-3 Show GitHub Exploit DB Packet Storm
224648 7.8 危険 Huawei - Huawei Access Router (AR) におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2013-4632 2013-06-24 16:57 2013-04-7 Show GitHub Exploit DB Packet Storm
224649 7.8 危険 Huawei - 複数の Huawei AR ルータにおけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2013-4631 2013-06-24 16:54 2013-04-25 Show GitHub Exploit DB Packet Storm
224650 7.6 危険 Huawei - 複数の Huawei AR ルータにおけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2013-4630 2013-06-24 16:54 2013-03-13 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 21, 2026, 4:10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
278851 5.3 MEDIUM
Network
mantisbt mantisbt Incomplete blacklist vulnerability in the config_is_private function in config_api.php in MantisBT 1.3.x before 1.3.0 allows remote attackers to obtain sensitive master salt configuration information… CWE-200
Information Exposure
CVE-2014-9759 2024-11-21 11:21 2016-04-12 Show GitHub Exploit DB Packet Storm
278852 7.3 HIGH
Network
pcre pcre pcre_jit_compile.c in PCRE 8.35 does not properly use table jumps to optimize nested alternatives, which allows remote attackers to cause a denial of service (stack memory corruption) or possibly hav… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2014-9769 2024-11-21 11:21 2016-03-29 Show GitHub Exploit DB Packet Storm
278853 8.8 HIGH
Network
ibm tivoli_netview_access_services IBM Tivoli NetView Access Services (NVAS) allows remote authenticated users to gain privileges by entering the ADM command and modifying a "page ID" field to the EMSPG2 transaction code. NOTE: the v… CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-9768 2024-11-21 11:21 2016-03-18 Show GitHub Exploit DB Packet Storm
278854 9.8 CRITICAL
Network
atlassian bamboo The Ignite Realtime Smack XMPP API, as used in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0, allows remote configured XMPP servers to execute arbitrary Java code via serialized data in an X… CWE-20
 Improper Input Validation 
CVE-2014-9757 2024-11-21 11:21 2016-02-9 Show GitHub Exploit DB Packet Storm
278855 - libsndfile_project
canonical
opensuse
libsndfile
ubuntu_linux
leap
opensuse
The psf_fwrite function in file_io.c in libsndfile allows attackers to cause a denial of service (divide-by-zero error and application crash) via unspecified vectors related to the headindex variable. CWE-369
 Divide By Zero
CVE-2014-9756 2024-11-21 11:21 2015-11-20 Show GitHub Exploit DB Packet Storm
278856 - atutor atutor Unrestricted file upload vulnerability in mods/_core/properties/lib/course.inc.php in ATutor before 2.2 patch 6 allows remote authenticated users to execute arbitrary PHP code by uploading a file wit… NVD-CWE-Other
CVE-2014-9752 2024-11-21 11:21 2015-11-17 Show GitHub Exploit DB Packet Storm
278857 - squid-cache
opensuse
squid
opensuse
Squid 3.4.4 through 3.4.11 and 3.5.0.1 through 3.5.1, when Digest authentication is used, allow remote authenticated users to retain access by leveraging a stale nonce, aka "Nonce replay vulnerabilit… CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-9749 2024-11-21 11:21 2015-11-7 Show GitHub Exploit DB Packet Storm
278858 - ntp
redhat
debian
oracle
ntp
enterprise_linux_desktop
enterprise_linux_server
enterprise_linux_workstation
debian_linux
linux
The read_network_packet function in ntp_io.c in ntpd in NTP 4.x before 4.2.8p1 on Linux and OS X does not properly determine whether a source IP address is an IPv6 loopback address, which makes it ea… CWE-20
 Improper Input Validation 
CVE-2014-9751 2024-11-21 11:21 2015-10-6 Show GitHub Exploit DB Packet Storm
278859 - ntp
redhat
debian
oracle
ntp
enterprise_linux_desktop
enterprise_linux_server
enterprise_linux_workstation
debian_linux
linux
ntp_crypto.c in ntpd in NTP 4.x before 4.2.8p1, when Autokey Authentication is enabled, allows remote attackers to obtain sensitive information from process memory or cause a denial of service (daemo… CWE-20
 Improper Input Validation 
CVE-2014-9750 2024-11-21 11:21 2015-10-6 Show GitHub Exploit DB Packet Storm
278860 - freetype
debian
canonical
opensuse
freetype
debian_linux
ubuntu_linux
opensuse
The parse_encoding function in type1/t1load.c in FreeType before 2.5.3 allows remote attackers to cause a denial of service (infinite loop) via a "broken number-with-base" in a Postscript stream, as … CWE-399
 Resource Management Errors
CVE-2014-9745 2024-11-21 11:21 2015-09-15 Show GitHub Exploit DB Packet Storm