Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 30, 2026, 2 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
202251 7.5 重要
Network
wptf-image-gallery project - WordPress 用 wptf-image-gallery プラグインにおけるファイルをダウンロードされる脆弱性 CWE-200
CWE-Other
CVE-2015-1000007 2016-10-12 11:46 2015-07-17 Show GitHub Exploit DB Packet Storm
202252 7.5 重要
Network
andycheeseman - WordPress 用 Recent Backups プラグインにおけるファイルをダウンロードされる脆弱性 CWE-22
パス・トラバーサル
CVE-2015-1000006 2016-10-12 11:46 2015-07-13 Show GitHub Exploit DB Packet Storm
202253 7.5 重要
Network
FlaxlandsConsulting - WordPress 用 Candidate Application Form プラグインにおけるファイルをダウンロードされる脆弱性 CWE-22
パス・トラバーサル
CVE-2015-1000005 2016-10-12 11:46 2015-07-12 Show GitHub Exploit DB Packet Storm
202254 9.8 緊急
Network
fast-image-adder project - WordPress 用 fast-image-adder プラグインにおけるファイルをアップロードされる脆弱性 CWE-Other
その他
CVE-2015-1000001 2016-10-12 11:46 2015-07-10 Show GitHub Exploit DB Packet Storm
202255 9.8 緊急
Network
MailCWP project - WordPress 用 MailCWP プラグインにおけるファイルをアップロードされる脆弱性 CWE-Other
その他
CVE-2015-1000000 2016-10-12 11:46 2015-07-9 Show GitHub Exploit DB Packet Storm
202256 9.8 緊急
Network
Huge-IT - Joomla 用 Huge-IT Catalog における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2016-1000125 2016-10-12 11:44 2016-09-16 Show GitHub Exploit DB Packet Storm
202257 9.8 緊急
Network
Huge-IT - Huge-IT Portfolio Gallery における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2016-1000124 2016-10-12 11:44 2016-09-16 Show GitHub Exploit DB Packet Storm
202258 9.8 緊急
Network
Huge-IT - Joomla 用 Huge-IT Video Gallery における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2016-1000123 2016-10-12 11:44 2016-09-15 Show GitHub Exploit DB Packet Storm
202259 6.1 警告
Network
Huge-IT - Joomla 用 Huge-IT Image Gallery におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-1000114 2016-10-12 11:44 2016-07-14 Show GitHub Exploit DB Packet Storm
202260 9.8 緊急
Network
Huge-IT - Joomla 用 Huge-IT Image Gallery における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2016-1000113 2016-10-12 11:44 2016-07-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 30, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
289761 - gnu libmicrohttpd The MHD_http_unescape function in libmicrohttpd before 0.9.32 might allow remote attackers to obtain sensitive information or cause a denial of service (crash) via unspecified vectors that trigger an… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2013-7038 2024-11-21 11:00 2013-12-14 Show GitHub Exploit DB Packet Storm
289762 - mcafee email_gateway Multiple SQL injection vulnerabilities in /admin/cgi-bin/rpc/doReport/18 in McAfee Email Gateway 7.6 allow remote authenticated users to execute arbitrary SQL commands via the (1) events_col, (2) eve… CWE-89
SQL Injection
CVE-2013-7092 2024-11-21 11:00 2013-12-14 Show GitHub Exploit DB Packet Storm
289763 - synacor zimbra_collaboration_suite Directory traversal vulnerability in /res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx%20TemplateMsg.js.zgz in Zimbra 7.2.2 and 8.0.2 allows remote attackers to read arbitrary files via a .. (… CWE-22
Path Traversal
CVE-2013-7091 2024-11-21 11:00 2013-12-14 Show GitHub Exploit DB Packet Storm
289764 - devscripts_devel_team devscripts The get_main_source_dir function in scripts/uscan.pl in devscripts before 2.13.8, when using USCAN_EXCLUSION, allows remote attackers to execute arbitrary commands via shell metacharacters in a direc… CWE-94
Code Injection
CVE-2013-7050 2024-11-21 11:00 2013-12-14 Show GitHub Exploit DB Packet Storm
289765 - juniper screenos
netscreen-5200
netscreen-5400
Juniper NetScreen Firewall running ScreenOS 5.4, 6.2, or 6.3, when the Ping of Death screen is disabled, allows remote attackers to cause a denial of service via a crafted packet. NVD-CWE-noinfo
CVE-2013-6958 2024-11-21 11:00 2013-12-14 Show GitHub Exploit DB Packet Storm
289766 - juniper idp250
idp8200
idp800
idp75
Cross-site scripting (XSS) vulnerability in the web administrative component in Juniper IDP allows remote attackers to inject arbitrary web script or HTML via unspecified vectors to the ACM web serve… CWE-79
Cross-site Scripting
CVE-2013-6957 2024-11-21 11:00 2013-12-14 Show GitHub Exploit DB Packet Storm
289767 - juniper ive_os Cross-site scripting (XSS) vulnerability in the Secure Access Service Web rewriting feature in Juniper Junos Pulse Secure Access Service (aka SSL VPN) with IVE OS before 7.1r17, 7.3 before 7.3r8, 7.4… CWE-79
Cross-site Scripting
CVE-2013-6956 2024-11-21 11:00 2013-12-14 Show GitHub Exploit DB Packet Storm
289768 - cisco unified_communications_manager The TFTP service in Cisco Unified Communications Manager (aka CUCM or Unified CM) allows remote attackers to obtain sensitive information from a phone via an RRQ operation, as demonstrated by discove… CWE-310
Cryptographic Issues
CVE-2013-7030 2024-11-21 11:00 2013-12-13 Show GitHub Exploit DB Packet Storm
289769 - zippyyum subway_ordering_for_california The ZippyYum Subway CA Kiosk app 3.4 for iOS uses cleartext storage in SQLite cache databases, which allows attackers to obtain sensitive information by reading data elements, as demonstrated by pass… CWE-310
Cryptographic Issues
CVE-2013-6986 2024-11-21 11:00 2013-12-13 Show GitHub Exploit DB Packet Storm
289770 - cisco scientific_atlanta__dpr\/epr2320_firmware
scientific_atlanta__dpr\/epr2320
scientific_atlanta__dpr2325_firmware
scientific_atlanta__dpr2325
Multiple cross-site request forgery (CSRF) vulnerabilities on Cisco Scientific Atlanta DPR2320R2 routers with software 2.0.2r1262-090417 allow remote attackers to hijack the authentication of adminis… CWE-352
 Origin Validation Error
CVE-2013-7043 2024-11-21 11:00 2013-12-11 Show GitHub Exploit DB Packet Storm