Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 28, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
226491 2.1 注意 アップル - Apple iOS のパスコードロックの実装におけるパスコード要求を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-0980 2013-03-22 12:29 2013-03-19 Show GitHub Exploit DB Packet Storm
226492 1.9 注意 アップル - Apple iOS の Lockdown における任意のファイルのパーミッションを変更される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-0979 2013-03-22 12:29 2013-03-19 Show GitHub Exploit DB Packet Storm
226493 2.1 注意 アップル - Apple iOS および Apple TV のカーネルにおける ASLR 保護メカニズムを回避される脆弱性 CWE-200
情報漏えい
CVE-2013-0978 2013-03-22 12:28 2013-03-19 Show GitHub Exploit DB Packet Storm
226494 4.6 警告 アップル - Apple iOS および Apple TV の dyld におけるコード署名の要求を回避される脆弱性 CWE-noinfo
情報不足
CVE-2013-0977 2013-03-22 12:27 2013-03-19 Show GitHub Exploit DB Packet Storm
226495 7.2 危険 IBM - UNIX および Linux 上で稼働する IBM InfoSphere Information Server におけるアクセス制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-5938 2013-03-22 11:19 2013-03-20 Show GitHub Exploit DB Packet Storm
226496 4.3 警告 IBM - IBM Sterling Order Management におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-0506 2013-03-22 11:18 2013-03-18 Show GitHub Exploit DB Packet Storm
226497 5.5 警告 IBM - IBM Sterling Order Management における XPath インジェクション攻撃を実行される脆弱性 CWE-20
CWE-200
CVE-2013-0505 2013-03-22 11:18 2013-03-18 Show GitHub Exploit DB Packet Storm
226498 4 警告 CloudBees - CloudBees Jenkins におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2013-0331 2013-03-22 10:18 2013-02-16 Show GitHub Exploit DB Packet Storm
226499 4 警告 CloudBees - CloudBees Jenkins における任意のジョブを作成される脆弱性 CWE-noinfo
情報不足
CVE-2013-0330 2013-03-22 10:17 2013-02-16 Show GitHub Exploit DB Packet Storm
226500 7.5 危険 CloudBees - CloudBees Jenkins における CSRF 保護メカニズムを回避される脆弱性 CWE-noinfo
情報不足
CVE-2013-0329 2013-03-22 10:17 2013-02-16 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 28, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
274321 7.3 HIGH
Network
php php The php_str_replace_in_subject function in ext/standard/string.c in PHP 7.x before 7.0.0 allows remote attackers to execute arbitrary code via a crafted value in the third argument to the str_ireplac… NVD-CWE-noinfo
CVE-2015-6527 2024-11-21 11:35 2016-01-19 Show GitHub Exploit DB Packet Storm
274322 6.3 MEDIUM
Network
hp arcsight_logger HPE ArcSight Logger before 6.1P1 allows remote authenticated users to execute arbitrary code via unspecified input to the (1) Intellicus or (2) client-certificate upload component. CWE-20
 Improper Input Validation 
CVE-2015-6864 2024-11-21 11:35 2016-01-16 Show GitHub Exploit DB Packet Storm
274323 7.3 HIGH
Network
hp arcsight_logger HPE ArcSight Logger before 6.1P1 allows remote attackers to execute arbitrary code via unspecified input to the (1) Intellicus or (2) client-certificate upload component. CWE-20
 Improper Input Validation 
CVE-2015-6863 2024-11-21 11:35 2016-01-16 Show GitHub Exploit DB Packet Storm
274324 8.1 HIGH
Network
advantech webaccess Advantech WebAccess before 8.1 allows remote attackers to execute arbitrary code via vectors involving a browser plugin. NVD-CWE-noinfo
CVE-2015-6467 2024-11-21 11:35 2016-01-15 Show GitHub Exploit DB Packet Storm
274325 8.4 HIGH
Local
zarafa
fedoraproject
zarafa_collaboration_platform
fedora
zarafa-autorespond in Zarafa Collaboration Platform (ZCP) before 7.2.1 allows local users to gain privileges via a symlink attack on /tmp/zarafa-vacation-*. CWE-59
Link Following
CVE-2015-6566 2024-11-21 11:35 2016-01-12 Show GitHub Exploit DB Packet Storm
274326 7.8 HIGH
Local
apple mac_os_x Directory Utility in Apple OS X before 10.11.1 mishandles authentication for new sessions, which allows local users to gain privileges via unspecified vectors. CWE-264
Permissions, Privileges, and Access Controls
CVE-2015-6980 2024-11-21 11:35 2016-01-11 Show GitHub Exploit DB Packet Storm
274327 6.3 MEDIUM
Network
vmware player
workstation
esxi
fusion
The VMware Tools HGFS (aka Shared Folders) implementation in VMware Workstation 11.x before 11.1.2, VMware Player 7.x before 7.1.2, VMware Fusion 7.x before 7.1.2, and VMware ESXi 5.0 through 6.0 all… CWE-284
Improper Access Control
CVE-2015-6933 2024-11-21 11:35 2016-01-9 Show GitHub Exploit DB Packet Storm
274328 7.8 HIGH
Local
dell pre-boot_authentication_driver Dell Pre-Boot Authentication Driver (PBADRV.sys) 1.0.1.5 allows local users to write to arbitrary physical memory locations and gain privileges via a 0x0022201c IOCTL call. CWE-264
Permissions, Privileges, and Access Controls
CVE-2015-6856 2024-11-21 11:35 2016-01-9 Show GitHub Exploit DB Packet Storm
274329 8.4 HIGH
Local
hp ucmdb_browser HPE UCMDB Browser before 4.02 allows remote attackers to obtain sensitive information or bypass intended access restrictions via unspecified vectors. CWE-200
CWE-284
Information Exposure
Improper Access Control
CVE-2015-6862 2024-11-21 11:35 2016-01-8 Show GitHub Exploit DB Packet Storm
274330 7.8 HIGH
Local
google android The Widevine QSEE TrustZone application in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafted application that leverages QSEECOM access, aka i… CWE-264
Permissions, Privileges, and Access Controls
CVE-2015-6647 2024-11-21 11:35 2016-01-7 Show GitHub Exploit DB Packet Storm