Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 28, 2026, 2:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
241231 6.9 警告 ROXIO - Roxio MyDVD における権限を取得される脆弱性 CWE-Other
その他
CVE-2010-5195 2012-09-10 13:31 2012-09-6 Show GitHub Exploit DB Packet Storm
241232 3.6 注意 X.Org Foundation - X.Org xserver の Render 拡張における任意のメモリを読まれる脆弱性 CWE-20
不適切な入力確認
CVE-2010-4819 2012-09-7 16:51 2010-08-20 Show GitHub Exploit DB Packet Storm
241233 8.5 危険 X.Org Foundation - X.Org xserver の GLX 拡張におけるサービス運用妨害 (サーバクラッシュ) の脆弱性 CWE-20
不適切な入力確認
CVE-2010-4818 2012-09-7 16:51 2011-01-10 Show GitHub Exploit DB Packet Storm
241234 4.3 警告 phpList - phpList の public_html/lists/admin/ におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-2741 2012-09-7 16:35 2012-03-21 Show GitHub Exploit DB Packet Storm
241235 7.5 危険 phpList - phpList の public_html/lists/admin における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2012-2740 2012-09-7 16:35 2012-03-21 Show GitHub Exploit DB Packet Storm
241236 6.8 警告 Wishlist project - Drupal 用 Wishlist モジュールにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2012-2069 2012-09-7 16:34 2012-03-21 Show GitHub Exploit DB Packet Storm
241237 6.8 警告 ownCloud - ownCloud におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2012-4753 2012-09-7 16:32 2012-07-20 Show GitHub Exploit DB Packet Storm
241238 4.3 警告 デル - Crowbar の Crowbar barclamp におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-3551 2012-09-7 16:06 2012-09-5 Show GitHub Exploit DB Packet Storm
241239 4.3 警告 OpenStack - OpenStack Folsom および Essex における任意のテナントに任意のユーザを追加される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-3542 2012-09-7 16:05 2012-08-30 Show GitHub Exploit DB Packet Storm
241240 2.6 注意 サイボウズ - サイボウズ KUNAI for Android における WebView クラスに関する脆弱性 CWE-Other
その他
CVE-2012-4012 2012-09-7 16:01 2012-09-7 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 28, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
286871 - jordy_meow media_file_renamer Multiple cross-site scripting (XSS) vulnerabilities in the (1) callback_multicheck, (2) callback_radio, and (3) callback_wysiwygin functions in mfrh_class.settings-api.php in the Media File Renamer p… CWE-79
Cross-site Scripting
CVE-2014-2040 2024-11-21 11:05 2014-03-4 Show GitHub Exploit DB Packet Storm
286872 - posh_project posh SQL injection vulnerability in portal/addtoapplication.php in POSH (aka Posh portal or Portaneo) 3.0 before 3.3.0 allows remote attackers to execute arbitrary SQL commands via the rssurl parameter. CWE-89
SQL Injection
CVE-2014-2211 2024-11-21 11:05 2014-03-4 Show GitHub Exploit DB Packet Storm
286873 - artifex mupdf Stack-based buffer overflow in the xps_parse_color function in xps/xps-common.c in MuPDF 1.3 and earlier allows remote attackers to execute arbitrary code via a large number of entries in the Context… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2014-2013 2024-11-21 11:05 2014-03-4 Show GitHub Exploit DB Packet Storm
286874 - mybb mybb Cross-site scripting (XSS) vulnerability in Upload/search.php in MyBB 1.6.12 and earlier allows remote attackers to inject arbitrary web script or HTML via the keywords parameter in a do_search actio… CWE-79
Cross-site Scripting
CVE-2014-1840 2024-11-21 11:05 2014-03-4 Show GitHub Exploit DB Packet Storm
286875 - google
lenovo
android
shareit
java/android/webkit/BrowserFrame.java in Android before 4.4 uses the addJavascriptInterface API in conjunction with creating an object of the SearchBoxImpl class, which allows attackers to execute ar… CWE-94
Code Injection
CVE-2014-1939 2024-11-21 11:05 2014-03-3 Show GitHub Exploit DB Packet Storm
286876 - drinkedin drinkedin_barfinder The DrinkedIn BarFinder application for Android, when Adobe PhoneGap 2.9.0 or earlier is used, allows remote attackers to execute arbitrary JavaScript code, and consequently obtain sensitive fine-geo… CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-1887 2024-11-21 11:05 2014-03-3 Show GitHub Exploit DB Packet Storm
286877 - edinburghtour edinburgh_by_bus The Edinburgh by Bus application for Android, when Adobe PhoneGap 2.9.0 or earlier is used, allows remote attackers to execute arbitrary JavaScript code, and consequently access external-storage reso… CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-1886 2024-11-21 11:05 2014-03-3 Show GitHub Exploit DB Packet Storm
286878 - hsgroup forzearmate The ForzeArmate application for Android, when Adobe PhoneGap 2.9.0 or earlier is used, allows remote attackers to execute arbitrary JavaScript code, and consequently obtain write access to external-s… CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-1885 2024-11-21 11:05 2014-03-3 Show GitHub Exploit DB Packet Storm
286879 - apache
adobe
cordova
phonegap
Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier on Windows Phone 7 and 8 do not properly restrict navigation events, which allows remote attackers to bypass intended device-reso… CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-1884 2024-11-21 11:05 2014-03-3 Show GitHub Exploit DB Packet Storm
286880 - adobe phonegap Adobe PhoneGap before 2.6.0 on Android uses the shouldOverrideUrlLoading callback instead of the proper shouldInterceptRequest callback, which allows remote attackers to bypass intended device-resour… CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-1883 2024-11-21 11:05 2014-03-3 Show GitHub Exploit DB Packet Storm