Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 18, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
229441 7.8 危険 MiniUPnP Project - MiniUPnP MiniUPnPd の HTTP サービスにおける整数符号エラーの脆弱性 CWE-189
数値処理の問題
CVE-2013-1462 2013-02-4 16:38 2013-01-31 Show GitHub Exploit DB Packet Storm
229442 7.8 危険 MiniUPnP Project - MiniUPnP MiniUPnPd の HTTP サービスにおけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2013-1461 2013-02-4 16:37 2013-01-31 Show GitHub Exploit DB Packet Storm
229443 10 危険 MiniUPnP Project - MiniUPnP MiniUPnPd の HTTP サービスにおけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2013-0230 2013-02-4 16:37 2013-01-31 Show GitHub Exploit DB Packet Storm
229444 7.8 危険 MiniUPnP Project - MiniUPnP MiniUPnPd の SSDP ハンドラにおけるサービス運用妨害 (サービスクラッシュ) の脆弱性 CWE-noinfo
情報不足
CVE-2013-0229 2013-02-4 16:36 2013-01-31 Show GitHub Exploit DB Packet Storm
229445 7.6 危険 DELL EMC (旧 EMC Corporation) - EMC AlphaStor の Drive Control Program におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2013-0930 2013-02-4 16:26 2013-01-31 Show GitHub Exploit DB Packet Storm
229446 9.3 危険 オラクル - Oracle Java SE 7 Update 11 における Java セキュリティサンドボックスを回避される脆弱性 CWE-noinfo
情報不足
CVE-2013-1490 2013-02-4 16:25 2013-01-31 Show GitHub Exploit DB Packet Storm
229447 4.3 警告 シスコシステムズ - Cisco Unified Communications Domain Manager におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-1113 2013-02-1 16:13 2013-01-25 Show GitHub Exploit DB Packet Storm
229448 5 警告 シスコシステムズ - Cisco Carrier Routing System におけるサービス運用妨害 (パケットロス) の脆弱性 CWE-20
不適切な入力確認
CVE-2013-1112 2013-02-1 16:13 2013-01-25 Show GitHub Exploit DB Packet Storm
229449 4.3 警告 IBM - IBM Cognos TM1 の Web コンポーネントにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-6350 2013-02-1 16:12 2013-01-31 Show GitHub Exploit DB Packet Storm
229450 4.3 警告 シスコシステムズ - Cisco NAC Appliance 上の Web 認証機能におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-6029 2013-02-1 16:12 2013-01-30 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 18, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
293301 - redhat openshift openshift-origin-broker-util, as used in Red Hat OpenShift Enterprise 1.2.7 and 2.0.5, uses world-readable permissions for the mcollective client.cfg configuration file, which allows local users to o… CWE-310
Cryptographic Issues
CVE-2014-0164 2024-11-21 11:01 2014-05-6 Show GitHub Exploit DB Packet Storm
293302 - redhat jboss_web_framework_kit Multiple cross-site scripting (XSS) vulnerabilities in Red Hat JBoss Web Framework Kit 2.5.0 allow remote attackers to inject arbitrary web script or HTML via a (1) parameter or (2) id name. CWE-79
Cross-site Scripting
CVE-2014-0149 2024-11-21 11:01 2014-05-6 Show GitHub Exploit DB Packet Storm
293303 - redhat
virt-who_project
enterprise_linux_desktop
enterprise_linux_workstation
enterprise_linux_server
virt-who
virt-who uses world-readable permissions for /etc/sysconfig/virt-who, which allows local users to obtain password for hypervisors by reading the file. CWE-310
Cryptographic Issues
CVE-2014-0189 2024-11-21 11:01 2014-05-2 Show GitHub Exploit DB Packet Storm
293304 - igniterealtime smack The ParseRoster component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify the from attribute of a roster-query IQ stanza, which allows remote attackers to spoof IQ responses vi… CWE-345
 Insufficient Verification of Data Authenticity
CVE-2014-0364 2024-11-21 11:01 2014-04-30 Show GitHub Exploit DB Packet Storm
293305 - igniterealtime smack The ServerTrustManager component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify basicConstraints and nameConstraints in X.509 certificate chains from SSL servers, which allows… CWE-295
Improper Certificate Validation 
CVE-2014-0363 2024-11-21 11:01 2014-04-30 Show GitHub Exploit DB Packet Storm
293306 - apache commons_beanutils
struts
Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commons-beanutils through 1.9.2, does not suppress the … CWE-20
 Improper Input Validation 
CVE-2014-0114 2024-11-21 11:01 2014-04-30 Show GitHub Exploit DB Packet Storm
293307 - f5 nginx The SPDY implementation in the ngx_http_spdy_module module in nginx 1.5.10 before 1.5.11, when running on a 32-bit platform, allows remote attackers to execute arbitrary code via a crafted request. CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2014-0088 2024-11-21 11:01 2014-04-29 Show GitHub Exploit DB Packet Storm
293308 - apache struts CookieInterceptor in Apache Struts before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" th… CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-0113 2024-11-21 11:01 2014-04-29 Show GitHub Exploit DB Packet Storm
293309 - apache struts ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code… CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-0112 2024-11-21 11:01 2014-04-29 Show GitHub Exploit DB Packet Storm
293310 - openstack
canonical
opensuse
neutron
ubuntu_linux
opensuse
The openvswitch-agent process in OpenStack Neutron 2013.1 before 2013.2.4 and 2014.1 before 2014.1.1 allows remote authenticated users to bypass security group restrictions via an invalid CIDR in a s… CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-0187 2024-11-21 11:01 2014-04-28 Show GitHub Exploit DB Packet Storm