Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 21, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
240421 6.5 警告 WordPress.org - WordPress の xmlrpc.php におけるアクセス制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2010-5106 2012-09-19 11:23 2010-12-8 Show GitHub Exploit DB Packet Storm
240422 6.8 警告 サイバーリンク株式会社 - Power2Go にバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2011-5171 2012-09-19 10:41 2011-12-12 Show GitHub Exploit DB Packet Storm
240423 2.6 注意 マイクロソフト - Windows Phone 7 に SSL サーバ証明書の検証不備の脆弱性 CWE-310
暗号の問題
CVE-2012-2993 2012-09-19 10:39 2012-09-18 Show GitHub Exploit DB Packet Storm
240424 7.5 危険 CoSoSys Ltd - Endpoint Protector 4 の認証機能に脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-2994 2012-09-19 10:37 2012-09-18 Show GitHub Exploit DB Packet Storm
240425 3.5 注意 シスコシステムズ - Cisco IOS の SSLVPN の実装におけるサービス運用妨害 (デバイスクラッシュ) の脆弱性 CWE-DesignError
CVE-2012-3924 2012-09-18 16:57 2012-09-16 Show GitHub Exploit DB Packet Storm
240426 3.5 注意 シスコシステムズ - Cisco IOS の SSLVPN の実装におけるサービス運用妨害 (デバイスクラッシュ) の脆弱性 CWE-noinfo
情報不足
CVE-2012-3923 2012-09-18 16:56 2012-09-16 Show GitHub Exploit DB Packet Storm
240427 5 警告 シスコシステムズ - 複数の Cisco 製品で使用される Cisco ACE モジュールにおけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2012-3919 2012-09-18 16:54 2012-09-16 Show GitHub Exploit DB Packet Storm
240428 5 警告 シスコシステムズ - Cisco IOS の DMVPN トンネルの実装におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2012-3915 2012-09-18 16:54 2012-09-16 Show GitHub Exploit DB Packet Storm
240429 6.8 警告 シスコシステムズ - Cisco ISE 3300 シリーズの ISE 管理者ユーザインターフェースにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2012-3908 2012-09-18 16:53 2012-04-11 Show GitHub Exploit DB Packet Storm
240430 5 警告 シスコシステムズ - Cisco IPS 4200 シリーズセンサーの sensorApp におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2012-3901 2012-09-18 16:53 2010-07-22 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 21, 2026, 4:10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
286771 - apache cxf Apache CXF before 2.6.14 and 2.7.x before 2.7.11 allows remote attackers to cause a denial of service (memory consumption) via a large request with the Content-Type set to text/html to a SOAP endpoin… CWE-399
 Resource Management Errors
CVE-2014-0109 2024-11-21 11:01 2014-05-8 Show GitHub Exploit DB Packet Storm
286772 - theforeman foreman Session fixation vulnerability in Foreman before 1.4.2 allows remote attackers to hijack web sessions via the session id cookie. CWE-287
Improper Authentication
CVE-2014-0090 2024-11-21 11:01 2014-05-8 Show GitHub Exploit DB Packet Storm
286773 - openstack
canonical
neutron
ubuntu_linux
The l3-agent in OpenStack Neutron 2012.2 before 2013.2.3 does not check the tenant id when creating ports, which allows remote authenticated users to plug ports into the routers of arbitrary tenants … CWE-287
Improper Authentication
CVE-2014-0056 2024-11-21 11:01 2014-05-8 Show GitHub Exploit DB Packet Storm
286774 - google search_appliance_software Cross-site scripting (XSS) vulnerability on Google Search Appliance (GSA) devices before 7.0.14.G.216 and 7.2 before 7.2.0.G.114, when dynamic navigation is configured, allows remote attackers to inj… CWE-79
Cross-site Scripting
CVE-2014-0362 2024-11-21 11:01 2014-05-8 Show GitHub Exploit DB Packet Storm
286775 - apache struts CookieInterceptor in Apache Struts 2.x before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method, which allows remote attackers to "manipulate… CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-0116 2024-11-21 11:01 2014-05-8 Show GitHub Exploit DB Packet Storm
286776 - netty netty WebSocket08FrameDecoder in Netty 3.6.x before 3.6.9, 3.7.x before 3.7.1, 3.8.x before 3.8.2, 3.9.x before 3.9.1, and 4.0.x before 4.0.19 allows remote attackers to cause a denial of service (memory c… CWE-399
 Resource Management Errors
CVE-2014-0193 2024-11-21 11:01 2014-05-6 Show GitHub Exploit DB Packet Storm
286777 - openssl
mariadb
fedoraproject
debian
opensuse
suse
openssl
mariadb
fedora
debian_linux
opensuse
linux_enterprise_server
linux_enterprise_software_development_kit
linux_enterprise_desktop
linux_enterprise_workstation_extension
The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, does not properly manage a buffer pointer during certain recursive calls, which allows … CWE-476
 NULL Pointer Dereference
CVE-2014-0198 2024-11-21 11:01 2014-05-6 Show GitHub Exploit DB Packet Storm
286778 - php php sapi/fpm/fpm/fpm_unix.c in the FastCGI Process Manager (FPM) in PHP before 5.4.28 and 5.5.x before 5.5.12 uses 0666 permissions for the UNIX socket, which allows local users to gain privileges via a … CWE-269
 Improper Privilege Management
CVE-2014-0185 2024-11-21 11:01 2014-05-6 Show GitHub Exploit DB Packet Storm
286779 - redhat openshift openshift-origin-broker-util, as used in Red Hat OpenShift Enterprise 1.2.7 and 2.0.5, uses world-readable permissions for the mcollective client.cfg configuration file, which allows local users to o… CWE-310
Cryptographic Issues
CVE-2014-0164 2024-11-21 11:01 2014-05-6 Show GitHub Exploit DB Packet Storm
286780 - redhat jboss_web_framework_kit Multiple cross-site scripting (XSS) vulnerabilities in Red Hat JBoss Web Framework Kit 2.5.0 allow remote attackers to inject arbitrary web script or HTML via a (1) parameter or (2) id name. CWE-79
Cross-site Scripting
CVE-2014-0149 2024-11-21 11:01 2014-05-6 Show GitHub Exploit DB Packet Storm