Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 18, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
199431 6.1 警告
Network
Open-Xchange - Open-Xchange OX App Suite におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-5124 2016-12-28 11:38 2016-07-13 Show GitHub Exploit DB Packet Storm
199432 4.3 警告
Network
Open-Xchange - Open-Xchange OX App Suite における任意のテキストメッセージを挿入される脆弱性 CWE-451
ユーザインターフェースにおける重要情報の誤った表示
CVE-2016-4048 2016-12-28 11:38 2016-06-22 Show GitHub Exploit DB Packet Storm
199433 4.3 警告
Network
Open-Xchange - Open-Xchange OX App Suite における操作された文書へのアクセスを追跡される脆弱性 CWE-200
CWE-611
CVE-2016-4047 2016-12-28 11:38 2016-06-22 Show GitHub Exploit DB Packet Storm
199434 5.8 警告
Network
Open-Xchange - Open-Xchange OX App Suite の外部メールアカウントを構成する API におけるホストおよびサービスに関する情報を収集される脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2016-4046 2016-12-28 11:38 2016-06-22 Show GitHub Exploit DB Packet Storm
199435 6.1 警告
Network
Open-Xchange - Open-Xchange OX App Suite におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-4045 2016-12-28 11:38 2016-06-22 Show GitHub Exploit DB Packet Storm
199436 3.5
Network
Open-Xchange - Open-Xchange OX AppSuite のフロントエンドにおけるユーザアカウントにアクセスされる脆弱性 CWE-200
情報漏えい
CVE-2016-4027 2016-12-28 11:38 2016-06-20 Show GitHub Exploit DB Packet Storm
199437 6.1 警告
Network
Open-Xchange - Open-Xchange OX AppSuite の content sanitizer コンポーネントにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-4026 2016-12-28 11:38 2016-05-10 Show GitHub Exploit DB Packet Storm
199438 5.4 警告
Network
Open-Xchange - Open-Xchange OX AppSuite の Portal のタイルのラベルにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-3173 2016-12-28 11:38 2016-03-29 Show GitHub Exploit DB Packet Storm
199439 6.1 警告
Network
Open-Xchange - Open-Xchange OX Guard におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-6854 2016-12-27 17:35 2016-09-13 Show GitHub Exploit DB Packet Storm
199440 6.1 警告
Network
Open-Xchange - Open-Xchange OX Guard におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-6853 2016-12-27 17:35 2016-09-13 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 18, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
2041 9.8 CRITICAL
Network
- - WordPress TheCartPress 1.5.3.6 contains an unauthenticated privilege escalation vulnerability that allows attackers to create administrator accounts by submitting crafted requests to the AJAX handler… CWE-862
 Missing Authorization
CVE-2021-47932 2026-05-12 23:24 2026-05-10 Show GitHub Exploit DB Packet Storm
2042 9.8 CRITICAL
Network
- - WordPress MStore API 2.0.6 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to the REST API endpoint. Attackers… CWE-306
Missing Authentication for Critical Function
CVE-2021-47933 2026-05-12 23:24 2026-05-10 Show GitHub Exploit DB Packet Storm
2043 9.8 CRITICAL
Network
- - OpenCATS 0.9.4 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by uploading malicious PHP files disguised as resume attachments. Att… CWE-306
Missing Authentication for Critical Function
CVE-2021-47936 2026-05-12 23:24 2026-05-10 Show GitHub Exploit DB Packet Storm
2044 8.8 HIGH
Network
- - e107 CMS 2.3.0 contains a remote code execution vulnerability that allows authenticated users with theme installation permissions to execute arbitrary commands by uploading malicious theme files. Att… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2021-47937 2026-05-12 23:24 2026-05-10 Show GitHub Exploit DB Packet Storm
2045 8.8 HIGH
Network
- - ImpressCMS 1.4.2 contains a remote code execution vulnerability in the autotasks administrative interface that allows authenticated attackers to execute arbitrary PHP code by injecting malicious code… CWE-94
Code Injection
CVE-2021-47938 2026-05-12 23:24 2026-05-10 Show GitHub Exploit DB Packet Storm
2046 8.8 HIGH
Network
- - Evolution CMS 3.1.6 contains a remote code execution vulnerability that allows authenticated users with module creation permissions to execute arbitrary system commands by injecting PHP code into mod… CWE-94
Code Injection
CVE-2021-47939 2026-05-12 23:24 2026-05-10 Show GitHub Exploit DB Packet Storm
2047 9.8 CRITICAL
Network
- - WordPress Plugin Download From Files version 1.48 and earlier contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by exploiting the AJAX fi… CWE-306
Missing Authentication for Critical Function
CVE-2021-47940 2026-05-12 23:24 2026-05-10 Show GitHub Exploit DB Packet Storm
2048 8.2 HIGH
Network
- - WordPress Plugin Survey & Poll 1.5.7.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the wp_sap co… CWE-89
SQL Injection
CVE-2021-47941 2026-05-12 23:24 2026-05-10 Show GitHub Exploit DB Packet Storm
2049 8.8 HIGH
Network
- - TextPattern CMS 4.8.7 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary commands by uploading malicious PHP files through the file upload functio… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2021-47943 2026-05-12 23:24 2026-05-10 Show GitHub Exploit DB Packet Storm
2050 5.3 MEDIUM
Network
- - OpenCart 3.0.3.6 contains a cross-site request forgery vulnerability in the /account/edit endpoint that allows unauthenticated attackers to modify victim account details by tricking users into visiti… CWE-352
 Origin Validation Error
CVE-2021-47946 2026-05-12 23:24 2026-05-10 Show GitHub Exploit DB Packet Storm