Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":July 1, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
226341 7.5 危険 Open Web Analytics - Open Web Analytics のパスワードリセットのページにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2014-1206 2014-01-20 10:16 2014-01-9 Show GitHub Exploit DB Packet Storm
226342 10 危険 LOREX Technology - 複数の Lorex Edge 製品のファームウェアの INetViewX ActiveX コントロールにおけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2014-1201 2014-01-20 10:16 2014-01-9 Show GitHub Exploit DB Packet Storm
226343 7.5 危険 WellinTech - 複数の WellinTech 製品の ActiveX コントロールにおける任意の DLL コードをダウンロードされる脆弱性 CWE-94
コード・インジェクション
CVE-2013-2827 2014-01-20 10:15 2014-01-14 Show GitHub Exploit DB Packet Storm
226344 6.4 警告 WellinTech - 複数の WellinTech 製品におけるアクセス制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-2826 2014-01-20 10:14 2014-01-14 Show GitHub Exploit DB Packet Storm
226345 3.5 注意 VASCO - VASCO IDENTIKEY Authentication Server に認証不備の脆弱性 CWE-287
CWE-Other
CVE-2013-7292 2014-01-17 18:20 2014-01-9 Show GitHub Exploit DB Packet Storm
226346 7.2 危険 サン・マイクロシステムズ
オラクル
- Sun Solaris の dbm_open() および dbminit() 関数におけるバッファオーバーフローの脆弱性 - CVE-2003-1067 2014-01-17 18:10 2003-06-19 Show GitHub Exploit DB Packet Storm
226347 9.3 危険 オラクル - Oracle Java SE における Hotspot に関する脆弱性 CWE-noinfo
情報不足
CVE-2014-0408 2014-01-17 17:17 2014-01-14 Show GitHub Exploit DB Packet Storm
226348 9.3 危険 オラクル - Oracle Java SE における Install に関する脆弱性 CWE-noinfo
情報不足
CVE-2014-0385 2014-01-17 17:17 2014-01-14 Show GitHub Exploit DB Packet Storm
226349 6.8 警告 オラクル - Oracle MySQL の MySQL Server における GIS に関する脆弱性 CWE-noinfo
情報不足
CVE-2013-5860 2014-01-17 17:14 2014-01-14 Show GitHub Exploit DB Packet Storm
226350 6.8 警告 オラクル - Oracle MySQL の MySQL Server における Stored Procedure に関する脆弱性 CWE-noinfo
情報不足
CVE-2013-5882 2014-01-17 17:14 2014-01-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:July 1, 2026, 4:27 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
274281 7.8 HIGH
Local
akabei_soft2 happy_wardrobe AKABEi SOFT2 games allow remote attackers to execute arbitrary OS commands via crafted saved data, as demonstrated by Happy Wardrobe. CWE-78
OS Command 
CVE-2016-4853 2024-11-21 11:53 2016-09-2 Show GitHub Exploit DB Packet Storm
274282 6.1 MEDIUM
Network
let\'s_php\! simple_chat Cross-site scripting (XSS) vulnerability in Let's PHP! simple chat before 2016-08-15 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. CWE-79
Cross-site Scripting
CVE-2016-4851 2024-11-21 11:53 2016-09-2 Show GitHub Exploit DB Packet Storm
274283 6.1 MEDIUM
Network
clip-bucket clipbucket Cross-site scripting (XSS) vulnerability in ClipBucket before 2.8.1 RC2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. CWE-79
Cross-site Scripting
CVE-2016-4848 2024-11-21 11:53 2016-09-2 Show GitHub Exploit DB Packet Storm
274284 6.5 MEDIUM
Network
netapp oncommand_system_manager NetApp OnCommand System Manager 8.3.x before 8.3.2P5 allows remote authenticated users to cause a denial of service via unspecified vectors. NVD-CWE-noinfo
CVE-2016-5047 2024-11-21 11:53 2016-09-1 Show GitHub Exploit DB Packet Storm
274285 9.8 CRITICAL
Network
readydesk readydesk Unrestricted file upload vulnerability in chat/sendfile.aspx in ReadyDesk 9.1 allows remote attackers to execute arbitrary code by uploading and requesting a .aspx file. CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2016-5050 2024-11-21 11:53 2016-08-27 Show GitHub Exploit DB Packet Storm
274286 7.5 HIGH
Network
readydesk readydesk Directory traversal vulnerability in chat/openattach.aspx in ReadyDesk 9.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the SESID parameter in conjunction with a filename in … CWE-22
Path Traversal
CVE-2016-5049 2024-11-21 11:53 2016-08-27 Show GitHub Exploit DB Packet Storm
274287 9.8 CRITICAL
Network
readydesk readydesk SQL injection vulnerability in chat/staff/default.aspx in ReadyDesk 9.1 allows remote attackers to execute arbitrary SQL commands via the user name field. CWE-89
SQL Injection
CVE-2016-5048 2024-11-21 11:53 2016-08-27 Show GitHub Exploit DB Packet Storm
274288 7.5 HIGH
Network
f5 big-ip_edge_gateway
big-ip_protocol_security_module
big-ip_analytics
big-ip_application_security_manager
big-ip_advanced_firewall_manager
big-ip_domain_name_system
big-ip_policy_enf…
Virtual servers in F5 BIG-IP systems 11.2.1 HF11 through HF15, 11.4.1 HF4 through HF10, 11.5.3 through 11.5.4, 11.6.0 HF5 through HF7, and 12.0.0, when configured with a TCP profile, allow remote att… CWE-284
Improper Access Control
CVE-2016-5023 2024-11-21 11:53 2016-08-26 Show GitHub Exploit DB Packet Storm
274289 9.8 CRITICAL
Network
zmodo zp-ibh-13w
zp-ne-14-s
ZModo ZP-NE14-S and ZP-IBH-13W devices have a hardcoded root password, which makes it easier for remote attackers to obtain access via a TELNET session. CWE-798
 Use of Hard-coded Credentials
CVE-2016-5081 2024-11-21 11:53 2016-08-24 Show GitHub Exploit DB Packet Storm
274290 5.3 MEDIUM
Network
theforeman foreman Foreman before 1.11.4 and 1.12.x before 1.12.1 does not properly restrict access to preview provisioning templates, which allows remote authenticated users with permission to view some hosts to obtai… CWE-200
Information Exposure
CVE-2016-4995 2024-11-21 11:53 2016-08-20 Show GitHub Exploit DB Packet Storm