Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 19, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228571 7.8 危険 Arecont Vision - AV1355DN にサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2013-0139 2013-04-22 16:55 2013-04-15 Show GitHub Exploit DB Packet Storm
228572 4.9 警告 シスコシステムズ - Cisco ASA 上で稼働するクライアントレス SSL VPN におけるサービス運用妨害 (DoS) の脆弱性 CWE-362
競合状態
CVE-2013-1199 2013-04-22 16:49 2013-04-17 Show GitHub Exploit DB Packet Storm
228573 7.5 危険 Joomla! - Joomla! における重要な情報を取得される脆弱性 CWE-Other
その他
CVE-2013-1453 2013-04-22 16:48 2013-02-4 Show GitHub Exploit DB Packet Storm
228574 5 警告 シスコシステムズ - Cisco ASA デバイスの ISAKMP の実装におけるグループを列挙される脆弱性 CWE-200
情報漏えい
CVE-2013-1194 2013-04-22 16:46 2013-04-17 Show GitHub Exploit DB Packet Storm
228575 7.5 危険 シスコシステムズ - Cisco Network Admission Control Manager における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2013-1177 2013-04-22 16:39 2013-04-17 Show GitHub Exploit DB Packet Storm
228576 7.1 危険 シスコシステムズ - Cisco TelePresence MCU デバイスおよび TelePresence Server におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2013-1176 2013-04-22 16:38 2013-04-17 Show GitHub Exploit DB Packet Storm
228577 4.3 警告 chatelao - PHP Address Book の edit.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-1749 2013-04-22 16:32 2013-04-18 Show GitHub Exploit DB Packet Storm
228578 7.5 危険 chatelao - PHP Address Book における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2013-1748 2013-04-22 16:17 2013-04-18 Show GitHub Exploit DB Packet Storm
228579 10 危険 Rockwell Automation - Rockwell Automation RSLinx Enterprise の LogReceiver.exe におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2012-4715 2013-04-22 16:02 2013-04-5 Show GitHub Exploit DB Packet Storm
228580 7.8 危険 Rockwell Automation - Rockwell Automation FactoryTalk Services Platform の RNADiagnostics.dll における整数オーバーフローの脆弱性 CWE-189
数値処理の問題
CVE-2012-4714 2013-04-22 16:01 2013-04-5 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 19, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
273661 4.7 MEDIUM
Network
cmsmadesimple cms_made_simple CMS Made Simple 2.x before 2.1.3 and 1.x before 1.12.2, when Smarty Cache is activated, allow remote attackers to conduct cache poisoning attacks, modify links, and conduct cross-site scripting (XSS)… CWE-79
Cross-site Scripting
CVE-2016-2784 2024-11-21 11:48 2016-05-26 Show GitHub Exploit DB Packet Storm
273662 7.8 HIGH
Local
huawei mobile_broadband_hl_service The Huawei Mobile Broadband HL Service 22.001.25.00.03 and earlier uses a weak ACL for the MobileBrServ program data directory, which allows local users to gain SYSTEM privileges by modifying VERSION… CWE-264
Permissions, Privileges, and Access Controls
CVE-2016-2855 2024-11-21 11:48 2016-05-24 Show GitHub Exploit DB Packet Storm
273663 5.3 MEDIUM
Network
moodle moodle Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not properly restrict links, which allows remote attackers to obtain sensitive URL inf… CWE-264
Permissions, Privileges, and Access Controls
CVE-2016-2190 2024-11-21 11:48 2016-05-23 Show GitHub Exploit DB Packet Storm
273664 8.6 HIGH
Network
wordpress wordpress The wp_http_validate_url function in wp-includes/http.php in WordPress before 4.4.2 allows remote attackers to conduct server-side request forgery (SSRF) attacks via a zero value in the first octet o… NVD-CWE-Other
CVE-2016-2222 2024-11-21 11:48 2016-05-22 Show GitHub Exploit DB Packet Storm
273665 7.4 HIGH
Network
wordpress wordpress Open redirect vulnerability in the wp_validate_redirect function in wp-includes/pluggable.php in WordPress before 4.4.2 allows remote attackers to redirect users to arbitrary web sites and conduct ph… NVD-CWE-Other
CVE-2016-2221 2024-11-21 11:48 2016-05-22 Show GitHub Exploit DB Packet Storm
273666 9.1 CRITICAL
Network
symantec anti-virus_engine The kernel component in Symantec Anti-Virus Engine (AVE) 20151.1 before 20151.1.1.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory access violation and system … CWE-399
 Resource Management Errors
CVE-2016-2208 2024-11-21 11:48 2016-05-19 Show GitHub Exploit DB Packet Storm
273667 9.8 CRITICAL
Network
php php Stack-based buffer overflow in ext/phar/tar.c in PHP before 5.5.32, 5.6.x before 5.6.18, and 7.x before 7.0.3 allows remote attackers to cause a denial of service (application crash) or possibly have… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2016-2554 2024-11-21 11:48 2016-05-16 Show GitHub Exploit DB Packet Storm
273668 9.8 CRITICAL
Network
meteocontrol web\'log_pro
web\'log_pro_unlimited
web\'log_basic_100
web\'log_light
Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited allows remote attackers to obtain sensitive cleartext information via unspecified vectors. CWE-200
Information Exposure
CVE-2016-2298 2024-11-21 11:48 2016-05-15 Show GitHub Exploit DB Packet Storm
273669 9.4 CRITICAL
Network
meteocontrol web\'log_pro
web\'log_pro_unlimited
web\'log_basic_100
web\'log_light
Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited allows remote attackers to execute arbitrary commands via an "access command shell-like feature." NVD-CWE-noinfo
CVE-2016-2297 2024-11-21 11:48 2016-05-15 Show GitHub Exploit DB Packet Storm
273670 9.4 CRITICAL
Network
meteocontrol web\'log_pro
web\'log_pro_unlimited
web\'log_basic_100
web\'log_light
Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited does not require authentication for "post-admin" login pages, which allows remote attackers to obtain sensitive information or modify dat… CWE-254
 7PK - Security Features
CVE-2016-2296 2024-11-21 11:48 2016-05-15 Show GitHub Exploit DB Packet Storm