Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 7, 2026, 12:09 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
252091 6.4 警告 オラクル - Oracle Enterprise Manager Grid Control の Real User Experience Insight コンポーネントにおける脆弱性 CWE-noinfo
情報不足
CVE-2010-3594 2011-02-14 15:24 2011-01-18 Show GitHub Exploit DB Packet Storm
252092 3.5 注意 オラクル - Oracle Fusion Middleware の Oracle BI Publisher コンポーネントにおける脆弱性 CWE-noinfo
情報不足
CVE-2010-4427 2011-02-14 15:24 2011-01-18 Show GitHub Exploit DB Packet Storm
252093 3.5 注意 オラクル - Oracle Fusion Middleware の Oracle BI Publisher コンポーネントにおける脆弱性 CWE-noinfo
情報不足
CVE-2010-4425 2011-02-14 15:23 2011-01-18 Show GitHub Exploit DB Packet Storm
252094 4.3 警告 オラクル - Oracle Fusion Middleware の Oracle WebLogic Server コンポーネントにおける脆弱性 CWE-noinfo
情報不足
CVE-2010-4453 2011-02-14 15:15 2011-01-18 Show GitHub Exploit DB Packet Storm
252095 5 警告 オラクル - Oracle Fusion Middleware の Oracle GoldenGate Veridata コンポーネントにおける脆弱性 CWE-noinfo
情報不足
CVE-2010-4416 2011-02-14 15:14 2011-01-18 Show GitHub Exploit DB Packet Storm
252096 5.5 警告 オラクル - Oracle Fusion Middleware の Oracle Discoverer コンポーネントにおける脆弱性 CWE-noinfo
情報不足
CVE-2010-3588 2011-02-14 15:14 2011-01-18 Show GitHub Exploit DB Packet Storm
252097 5.8 警告 オラクル - Oracle Fusion Middleware の Oracle WebLogic Server コンポーネントにおける脆弱性 CWE-noinfo
情報不足
CVE-2010-4437 2011-02-14 15:14 2011-01-18 Show GitHub Exploit DB Packet Storm
252098 7.2 危険 サイバートラスト株式会社
レッドハット
SystemTap
- SystemTap の staprun runtime ツールにおける権限昇格の脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2010-4170 2011-02-10 14:54 2010-11-17 Show GitHub Exploit DB Packet Storm
252099 2.1 注意 サイバートラスト株式会社
レッドハット
SystemTap
- SystemTap の staprun runtime ツールにおけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2010-4171 2011-02-10 14:53 2010-11-17 Show GitHub Exploit DB Packet Storm
252100 5 警告 The PHP Group
チェック・ポイント・ソフトウェア・テクノロジーズ
レッドハット
- PHP の zend_strtod 関数にて使用される strtod.c におけるサービス運用妨害 (DoS) の脆弱性 CWE-189
数値処理の問題
CVE-2010-4645 2011-02-10 14:53 2010-12-30 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 7, 2026, 4:22 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
280591 - jasig uportal uPortal before 4.0.13.1 does not properly check the CONFIG permission, which allows remote authenticated users to configure portlets by leveraging the SUBSCRIBE permission for a portlet. CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-3417 2024-11-21 11:08 2014-05-29 Show GitHub Exploit DB Packet Storm
280592 - jasig uportal uPortal before 4.0.13.1 does not properly check the MANAGE permissions, which allows remote authenticated users to manage arbitrary portlets by leveraging the SUBSCRIBE permission for the portlet-adm… CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-3416 2024-11-21 11:08 2014-05-29 Show GitHub Exploit DB Packet Storm
280593 - sharetronix sharetronix SQL injection vulnerability in Sharetronix before 3.4 allows remote authenticated users to execute arbitrary SQL commands via the invite_users[] parameter to the /invite page for a group. CWE-89
SQL Injection
CVE-2014-3415 2024-11-21 11:08 2014-05-29 Show GitHub Exploit DB Packet Storm
280594 - sharetronix sharetronix Cross-site request forgery (CSRF) vulnerability in Sharetronix before 3.4 allows remote attackers to hijack the authentication of administrators for requests that add administrative privileges to a u… CWE-352
 Origin Validation Error
CVE-2014-3414 2024-11-21 11:08 2014-05-29 Show GitHub Exploit DB Packet Storm
280595 - mayan-edms mayan_edms Multiple cross-site scripting (XSS) vulnerabilities in apps/common/templates/calculate_form_title.html in Mayan EDMS 0.13 allow remote authenticated users to inject arbitrary web script or HTML via a… CWE-79
Cross-site Scripting
CVE-2014-3840 2024-11-21 11:08 2014-05-27 Show GitHub Exploit DB Packet Storm
280596 - imember360 imember360 The iMember360 plugin 3.8.012 through 3.9.001 for WordPress does not properly restrict access, which allows remote attackers to delete arbitrary users via a request containing a user name in the Emai… CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-3849 2024-11-21 11:08 2014-05-23 Show GitHub Exploit DB Packet Storm
280597 - imember360 imember360 The iMember360 plugin before 3.9.001 for WordPress does not properly restrict access, which allows remote attackers to obtain database credentials via the i4w_dbinfo parameter. CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-3848 2024-11-21 11:08 2014-05-23 Show GitHub Exploit DB Packet Storm
280598 - openstack heat OpenStack Orchestration API (Heat) 2013.2 through 2013.2.3 and 2014.1, when creating the stack for a template using a provider template, allows remote authenticated users to obtain the provider templ… CWE-200
Information Exposure
CVE-2014-3801 2024-11-21 11:08 2014-05-23 Show GitHub Exploit DB Packet Storm
280599 - pandasecurity panda_av_pro_2014
panda_internet_security_2014
panda_global_protection_2014
panda_gold_protection
Unspecified vulnerability in Panda Gold Protection and Global Protection 2014 7.01.01 and earlier, Internet Security 2014 19.01.01 and earlier, and AV Pro 2014 13.01.01 and earlier allows local users… NVD-CWE-noinfo
CVE-2014-3450 2024-11-21 11:08 2014-05-23 Show GitHub Exploit DB Packet Storm
280600 - nullsoft winamp Winamp 5.666 and earlier allows remote attackers to cause a denial of service (memory corruption and crash) via a malformed .FLV file, related to f263.w5s. CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2014-3442 2024-11-21 11:08 2014-05-23 Show GitHub Exploit DB Packet Storm