Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 22, 2026, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
224701 5 警告 The Tor Project - Tor におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2012-2249 2014-02-4 18:07 2012-10-20 Show GitHub Exploit DB Packet Storm
224702 6.8 警告 アップル
LibTIFF
- LibTIFF の tiff_getimage.c における整数オーバーフローの脆弱性 CWE-189
数値処理の問題
CVE-2012-1173 2014-02-4 18:04 2012-06-4 Show GitHub Exploit DB Packet Storm
224703 5 警告 KENT-WEB - Joyful Note におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-0812 2014-02-4 17:37 2014-01-31 Show GitHub Exploit DB Packet Storm
224704 2.1 注意 OpenBSD - 特定のプラットフォーム上で稼働する OpenSSH の ssh-keysign の ssh-keysign.c における重要な鍵情報を取得される脆弱性 - CVE-2011-4327 2014-02-4 17:05 2011-04-29 Show GitHub Exploit DB Packet Storm
224705 4.3 警告 Elgg Foundation - Elgg の Twitter ウィジェットにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-0234 2014-02-4 16:49 2013-01-26 Show GitHub Exploit DB Packet Storm
224706 2.1 注意 レッドハット - JBoss Enterprise Application Platform の EC2 Amazon Machine Image における重要な情報を読まれる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-3427 2014-02-4 16:36 2012-10-16 Show GitHub Exploit DB Packet Storm
224707 5 警告 Craig Drummond - cantata における重要な情報を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-7301 2014-02-4 15:44 2013-12-24 Show GitHub Exploit DB Packet Storm
224708 5 警告 Craig Drummond - cantata における絶対パストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2013-7300 2014-02-4 15:43 2013-12-24 Show GitHub Exploit DB Packet Storm
224709 4.3 警告 OpenStack
レッドハット
- OpenStack Oslo の python-qpid クライアントにおける重要な情報を取得される脆弱性 CWE-310
暗号の問題
CVE-2013-6491 2014-02-4 14:23 2013-05-30 Show GitHub Exploit DB Packet Storm
224710 5 警告 Schneider Electric - Schneider Electric Telvent SAGE 3030 RTU のファームウェアにおけるサービス運用妨害 (DoS) の脆弱性 CWE-20
CWE-399
CVE-2013-6143 2014-02-4 14:21 2013-12-30 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 22, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
196901 7.5 HIGH
Network
apache
netapp
myfaces
oncommand_insight
In the default configuration, Apache MyFaces Core versions 2.2.0 to 2.2.13, 2.3.0 to 2.3.7, 2.3-next-M1 to 2.3-next-M4, and 3.0.0-RC1 use cryptographically weak implicit and explicit cross-site reque… CWE-352
 Origin Validation Error
CVE-2021-26296 2024-11-21 14:56 2021-02-19 Show GitHub Exploit DB Packet Storm
196902 6.1 MEDIUM
Network
openenergymonitor emoncms Modules/input/Views/schedule.php in Emoncms through 10.2.7 allows XSS via the node parameter. CWE-79
Cross-site Scripting
CVE-2021-26716 2024-11-21 14:56 2021-02-21 Show GitHub Exploit DB Packet Storm
196903 5.4 MEDIUM
Network
apache livy Livy server version 0.7.0-incubating (only) is vulnerable to a cross site scripting issue in the session name. A malicious user could use this flaw to access logs and results of other users' sessions… CWE-79
Cross-site Scripting
CVE-2021-26544 2024-11-21 14:56 2021-02-20 Show GitHub Exploit DB Packet Storm
196904 6.1 MEDIUM
Network
chamilo chamilo Chamilo 1.11.14 allows XSS via a main/calendar/agenda_list.php?type= URI. CWE-79
Cross-site Scripting
CVE-2021-26746 2024-11-21 14:56 2021-02-19 Show GitHub Exploit DB Packet Storm
196905 9.8 CRITICAL
Network
netis-systems wf2780_firmware
wf2411_firmware
Netis WF2780 2.3.40404 and WF2411 1.1.29629 devices allow Shell Metacharacter Injection into the ping command, leading to remote code execution. CWE-78
OS Command 
CVE-2021-26747 2024-11-21 14:56 2021-02-19 Show GitHub Exploit DB Packet Storm
196906 7.5 HIGH
Network
digium certified_asterisk
asterisk
Incorrect access controls in res_srtp.c in Sangoma Asterisk 13.38.1, 16.16.0, 17.9.1, and 18.2.0 and Certified Asterisk 16.8-cert5 allow a remote unauthenticated attacker to prematurely terminate sec… NVD-CWE-Other
CVE-2021-26712 2024-11-21 14:56 2021-02-19 Show GitHub Exploit DB Packet Storm
196907 7.5 HIGH
Network
digium certified_asterisk
asterisk
An issue was discovered in Sangoma Asterisk 16.x before 16.16.1, 17.x before 17.9.2, and 18.x before 18.2.1 and Certified Asterisk before 16.8-cert6. When re-negotiating for T.38, if the initial remo… NVD-CWE-noinfo
CVE-2021-26717 2024-11-21 14:56 2021-02-19 Show GitHub Exploit DB Packet Storm
196908 7.8 HIGH
Local
avahi
debian
avahi
debian_linux
avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root via /etc/network/if-up.d/avahi-daemon, and allows a local attacker to cause a denial of service or create arbit… CWE-59
Link Following
CVE-2021-26720 2024-11-21 14:56 2021-02-18 Show GitHub Exploit DB Packet Storm
196909 9.8 CRITICAL
Network
phpgurukul car_rental_portal PHPGurukul Car Rental Project version 2.0 suffers from a remote shell upload vulnerability in changeimage1.php. CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2021-26809 2024-11-21 14:56 2021-02-18 Show GitHub Exploit DB Packet Storm
196910 5.3 MEDIUM
Network
apache airflow The lineage endpoint of the deprecated Experimental API was not protected by authentication in Airflow 2.0.0. This allowed unauthenticated users to hit that endpoint. This is low-severity issue as th… CWE-306
Missing Authentication for Critical Function
CVE-2021-26697 2024-11-21 14:56 2021-02-18 Show GitHub Exploit DB Packet Storm