Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 18, 2026, 4:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
224741 4.3 警告 FreeNAC - FreeNAC におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-6559 2013-05-27 15:52 2013-05-23 Show GitHub Exploit DB Packet Storm
224742 6.8 警告 Heaventools Software - HeavenTools PE Explorer におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2012-6558 2013-05-27 15:46 2012-05-18 Show GitHub Exploit DB Packet Storm
224743 4.4 警告 GNU Project - GNU Grep おける整数オーバーフローの脆弱性 CWE-189
数値処理の問題
CVE-2012-5667 2013-05-27 15:46 2012-12-21 Show GitHub Exploit DB Packet Storm
224744 4.3 警告 zodiacdm - Vanilla Forums 用の AboutMe プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-6557 2013-05-27 15:43 2013-05-23 Show GitHub Exploit DB Packet Storm
224745 4.3 警告 jspautsch - Vanilla Forums 用の FirstLastNames プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-6556 2013-05-27 15:41 2013-05-23 Show GitHub Exploit DB Packet Storm
224746 4.3 警告 sahotataran - Vanilla Forums 用の LatestComment プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-6555 2013-05-27 15:40 2013-05-23 Show GitHub Exploit DB Packet Storm
224747 6.5 警告 activeCollab - activeCollab 用の Chat モジュールにおける任意の PHP コードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2012-6554 2013-05-27 15:36 2012-05-16 Show GitHub Exploit DB Packet Storm
224748 9.3 危険 アップル - Apple QuickTime におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2013-1021 2013-05-27 15:27 2013-05-22 Show GitHub Exploit DB Packet Storm
224749 9.3 危険 アップル - Apple QuickTime における任意のコードを実行される脆弱性 CWE-399
リソース管理の問題
CVE-2013-1020 2013-05-27 15:24 2013-05-22 Show GitHub Exploit DB Packet Storm
224750 9.3 危険 アップル - Apple QuickTime におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2013-1017 2013-05-27 15:13 2013-05-22 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 18, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
278291 9.8 CRITICAL
Network
imagemagick
suse
opensuse
imagemagick
linux_enterprise_software_development_kit
linux_enterprise_server
linux_enterprise_workstation_extension
linux_enterprise_desktop
opensuse
leap
distribute-cache.c in ImageMagick re-uses objects after they have been destroyed, which allows remote attackers to have unspecified impact via unspecified vectors. CWE-913
 Improper Control of Dynamically-Managed Code Resources
CVE-2014-9852 2024-11-21 11:21 2017-03-17 Show GitHub Exploit DB Packet Storm
278292 9.8 CRITICAL
Network
mcafee cloud_analysis_and_deconstructive_services Information disclosure vulnerability in McAfee (now Intel Security) Cloud Analysis and Deconstructive Services (CADS) 1.0.0.3x, 1.0.0.4d and earlier allows remote unauthenticated users to view, add, … CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-9921 2024-11-21 11:21 2017-03-15 Show GitHub Exploit DB Packet Storm
278293 5.9 MEDIUM
Network
mcafee application_control Unauthorized execution of binary vulnerability in McAfee (now Intel Security) McAfee Application Control (MAC) 6.0.0 before hotfix 9726, 6.0.1 before hotfix 9068, 6.1.0 before hotfix 692, 6.1.1 befor… CWE-284
Improper Access Control
CVE-2014-9920 2024-11-21 11:21 2017-03-15 Show GitHub Exploit DB Packet Storm
278294 5.5 MEDIUM
Local
busybox busybox The add_probe function in modutils/modprobe.c in BusyBox before 1.23.0 allows local users to bypass intended restrictions on loading kernel modules via a / (slash) character in a module name, as demo… CWE-20
 Improper Input Validation 
CVE-2014-9645 2024-11-21 11:21 2017-03-12 Show GitHub Exploit DB Packet Storm
278295 6.1 MEDIUM
Network
bilboplanet bilboplanet Multiple cross-site scripting (XSS) vulnerabilities in Bilboplanet 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) tribe_name or (2) tags parameter in a tribes page requ… CWE-79
Cross-site Scripting
CVE-2014-9916 2024-11-21 11:21 2017-02-24 Show GitHub Exploit DB Packet Storm
278296 6.1 MEDIUM
Network
alinto sogo Multiple cross-site scripting (XSS) vulnerabilities in the Web Calendar in SOGo before 2.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) title of an appointment or (2) c… CWE-79
Cross-site Scripting
CVE-2014-9905 2024-11-21 11:21 2017-02-18 Show GitHub Exploit DB Packet Storm
278297 6.1 MEDIUM
Network
gosa_project gosa Cross-site scripting (XSS) vulnerability in the displayLogin function in html/index.php in GOsa allows remote attackers to inject arbitrary web script or HTML via the username. CWE-79
Cross-site Scripting
CVE-2014-9760 2024-11-21 11:21 2017-02-14 Show GitHub Exploit DB Packet Storm
278298 7.8 HIGH
Local
linux
google
linux_kernel
android
Race condition in the ip4_datagram_release_cb function in net/ipv4/datagram.c in the Linux kernel before 3.15.2 allows local users to gain privileges or cause a denial of service (use-after-free) by … CWE-362
CWE-416
Race Condition
 Use After Free
CVE-2014-9914 2024-11-21 11:21 2017-02-7 Show GitHub Exploit DB Packet Storm
278299 6.1 MEDIUM
Network
nodejs node.js The validator package before 2.0.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter via hex-encoded characters. CWE-79
Cross-site Scripting
CVE-2014-9772 2024-11-21 11:21 2017-01-24 Show GitHub Exploit DB Packet Storm
278300 7.5 HIGH
Network
viprinet multichannel_vpn_router_300_firmware The hardware VPN client in Viprinet MultichannelVPN Router 300 version 2013070830/2013080900 does not validate the remote VPN endpoint identity (through the checking of the endpoint's SSL key) before… CWE-20
 Improper Input Validation 
CVE-2014-9755 2024-11-21 11:21 2017-01-21 Show GitHub Exploit DB Packet Storm