Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 10, 2026, 2 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
227241 6.8 警告 Crunchify - WordPress 用 All in One Webmaster プラグインにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2013-2696 2013-04-30 17:52 2013-04-22 Show GitHub Exploit DB Packet Storm
227242 5 警告 Blink Web Effects - WordPress 用 Social Media Widget プラグインにおける任意のファイルのアップロードを強制される脆弱性 CWE-noinfo
情報不足
CVE-2013-1949 2013-04-30 17:51 2013-04-9 Show GitHub Exploit DB Packet Storm
227243 10 危険 Rob Westgeest - Ruby 用 md2pdf gem の converter.rb における任意のコマンドを実行される脆弱性 CWE-noinfo
情報不足
CVE-2013-1948 2013-04-30 17:51 2013-04-10 Show GitHub Exploit DB Packet Storm
227244 9.3 危険 Kelly D. Redding - Ruby 用 kelredd-pruview gem における任意のコマンドを実行される脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2013-1947 2013-04-30 17:50 2013-04-4 Show GitHub Exploit DB Packet Storm
227245 9.3 危険 karteek-docsplit - Ruby 用 Karteek Docsplit gem における任意のコマンドを実行される脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2013-1933 2013-04-30 17:49 2013-04-1 Show GitHub Exploit DB Packet Storm
227246 6.8 警告 Novell
plataformatec
- Ruby 用 Devise gem における不正な結果が返される脆弱性 CWE-399
リソース管理の問題
CVE-2013-0233 2013-04-30 17:48 2013-01-28 Show GitHub Exploit DB Packet Storm
227247 7.5 危険 Grape
Erik Michaels-Ober
- Grape などの製品で使用される Ruby 用 multi_xml gem におけるオブジェクトインジェクション攻撃を誘発される脆弱性 CWE-20
不適切な入力確認
CVE-2013-0175 2013-04-30 17:43 2013-01-10 Show GitHub Exploit DB Packet Storm
227248 5 警告 Ruby-lang.org - Ruby における safe-level の制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-4466 2013-04-30 17:29 2012-10-3 Show GitHub Exploit DB Packet Storm
227249 5 警告 Ruby-lang.org - Ruby における safe-level の制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-4464 2013-04-30 17:25 2012-10-3 Show GitHub Exploit DB Packet Storm
227250 5.4 警告 シトリックス・システムズ - NetScaler Access Gateway Enterprise Edition に脆弱性 CWE-noinfo
情報不足
CVE-2013-2767 2013-04-30 12:45 2013-04-26 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 10, 2026, 5 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
273271 7.6 HIGH
Network
google chrome Multiple use-after-free vulnerabilities in the formfiller implementation in PDFium, as used in Google Chrome before 48.0.2564.82, allow remote attackers to cause a denial of service or possibly have … NVD-CWE-Other
CVE-2016-1613 2024-11-21 11:46 2016-01-25 Show GitHub Exploit DB Packet Storm
273272 7.6 HIGH
Network
google chrome The LoadIC::UpdateCaches function in ic/ic.cc in Google V8, as used in Google Chrome before 48.0.2564.82, does not ensure receiver compatibility before performing a cast of an unspecified variable, w… CWE-20
 Improper Input Validation 
CVE-2016-1612 2024-11-21 11:46 2016-01-25 Show GitHub Exploit DB Packet Storm
273273 8.4 HIGH
Local
ecryptfs
canonical
opensuse
debian
fedoraproject
ecryptfs-utils
ubuntu_linux
leap
opensuse
debian_linux
fedora
mount.ecryptfs_private.c in eCryptfs-utils does not validate mount destination filesystem types, which allows local users to gain privileges by mounting over a nonstandard filesystem, as demonstrated… CWE-269
 Improper Privilege Management
CVE-2016-1572 2024-11-21 11:46 2016-01-23 Show GitHub Exploit DB Packet Storm
273274 6.3 MEDIUM
Network
citrix
xen
xenserver
xen
The paging_invlpg function in include/asm-x86/paging.h in Xen 3.3.x through 4.6.x, when using shadow mode paging or nested virtualization is enabled, allows local HVM guest users to cause a denial of… CWE-17
Code
CVE-2016-1571 2024-11-21 11:46 2016-01-23 Show GitHub Exploit DB Packet Storm
273275 8.5 HIGH
Network
xen xen The PV superpage functionality in arch/x86/mm.c in Xen 3.4.0, 3.4.1, and 4.1.x through 4.6.x allows local PV guests to obtain sensitive information, cause a denial of service, gain privileges, or hav… CWE-20
 Improper Input Validation 
CVE-2016-1570 2024-11-21 11:46 2016-01-23 Show GitHub Exploit DB Packet Storm
273276 7.5 HIGH
Network
cisco web_security_appliance The proxy engine on Cisco Web Security Appliance (WSA) devices with software 8.5.3-055, 9.1.0-000, and 9.5.0-235 allows remote attackers to bypass intended proxy restrictions via a malformed HTTP met… CWE-254
 7PK - Security Features
CVE-2016-1296 2024-11-21 11:46 2016-01-20 Show GitHub Exploit DB Packet Storm
273277 5.3 MEDIUM
Network
cisco adaptive_security_appliance_software Cisco Adaptive Security Appliance (ASA) Software 8.4 allows remote attackers to obtain sensitive information via an AnyConnect authentication attempt, aka Bug ID CSCuo65775. CWE-200
Information Exposure
CVE-2016-1295 2024-11-21 11:46 2016-01-16 Show GitHub Exploit DB Packet Storm
273278 6.1 MEDIUM
Network
cisco firesight_system_software Cross-site scripting (XSS) vulnerability in the Management Center in Cisco FireSIGHT System Software 6.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted cookie, aka Bug… CWE-79
Cross-site Scripting
CVE-2016-1294 2024-11-21 11:46 2016-01-16 Show GitHub Exploit DB Packet Storm
273279 6.1 MEDIUM
Network
cisco firesight_system_software Multiple cross-site scripting (XSS) vulnerabilities in the Management Center in Cisco FireSIGHT System Software 6.0.0 and 6.0.1 allow remote attackers to inject arbitrary web script or HTML via unspe… CWE-79
Cross-site Scripting
CVE-2016-1293 2024-11-21 11:46 2016-01-16 Show GitHub Exploit DB Packet Storm
273280 5.9 MEDIUM
Network
juniper junos Juniper Junos OS before 12.1X46-D45, 12.1X47 before 12.1X47-D30, 12.1X48 before 12.3X48-D20, and 15.1X49 before 15.1X49-D30 on SRX series devices, when the Real Time Streaming Protocol Application La… CWE-20
 Improper Input Validation 
CVE-2016-1262 2024-11-21 11:46 2016-01-16 Show GitHub Exploit DB Packet Storm