Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 4, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
202281 6.1 警告
Network
Benjamin Sterling - WordPress 用 photoxhibit プラグインにおける反射型クロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-1000143 2016-10-19 16:54 2016-02-9 Show GitHub Exploit DB Packet Storm
202282 6.1 警告
Network
parsi-font project - WordPress 用 parsi-font プラグインにおける反射型クロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-1000142 2016-10-19 16:54 2016-02-9 Show GitHub Exploit DB Packet Storm
202283 6.1 警告
Network
Page Layout Builder project - WordPress 用 page-layout-builder プラグインにおける反射型クロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-1000141 2016-10-19 16:54 2016-02-9 Show GitHub Exploit DB Packet Storm
202284 6.1 警告
Network
new-year-firework project - WordPress 用 new-year-firework プラグインにおける反射型クロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-1000140 2016-10-19 16:54 2016-02-9 Show GitHub Exploit DB Packet Storm
202285 6.1 警告
Network
Katz Web Services, Inc. - WordPress 用 Infusionsoft Gravity Forms プラグインにおける反射型クロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-1000139 2016-10-19 16:54 2016-02-9 Show GitHub Exploit DB Packet Storm
202286 6.1 警告
Network
indexisto project - WordPress 用 indexisto プラグインにおける反射型クロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-1000138 2016-10-19 16:54 2016-02-9 Show GitHub Exploit DB Packet Storm
202287 6.1 警告
Network
Hero Plugins - WordPress 用 Hero Maps Pro プラグインにおける反射型クロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-1000137 2016-10-19 16:54 2016-02-9 Show GitHub Exploit DB Packet Storm
202288 6.1 警告
Network
heat-trackr project - WordPress 用 heat-trackr プラグインにおける反射型クロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-1000136 2016-10-19 16:52 2016-02-9 Show GitHub Exploit DB Packet Storm
202289 6.1 警告
Network
HDW Tube project - WordPress 用 HDW Tube プラグインにおける反射型クロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-1000135 2016-10-19 16:52 2016-02-9 Show GitHub Exploit DB Packet Storm
202290 6.1 警告
Network
HDW Tube project - WordPress 用 HDW Tube プラグインにおける反射型クロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-1000134 2016-10-19 16:52 2016-02-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 5, 2026, 4:11 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
291981 - cisco firewall_services_module_software The authorization functionality in Cisco Firewall Services Module (FWSM) 3.1.x and 3.2.x before 3.2(25) and 4.x before 4.1(13), when multiple-context mode is enabled, allows local users to read or mo… CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-5506 2024-11-21 10:57 2013-10-13 Show GitHub Exploit DB Packet Storm
291982 - cisco unified_ip_phones_9900_series_firmware
unified_ip_phone_9951
unified_ip_phone_9971
The image-upgrade functionality on Cisco 9900 Unified IP phones allows local users to gain privileges by placing shell commands in an unspecified parameter, aka Bug ID CSCuh10334. CWE-20
 Improper Input Validation 
CVE-2013-5533 2024-11-21 10:57 2013-10-11 Show GitHub Exploit DB Packet Storm
291983 - cisco unified_ip_phones_9900_series_firmware
unified_ip_phone_9951
unified_ip_phone_9971
Buffer overflow in the web-application interface on Cisco 9900 IP phones allows remote attackers to cause a denial of service (webapp interface outage) via long values in unspecified fields, aka Bug … CWE-20
 Improper Input Validation 
CVE-2013-5532 2024-11-21 10:57 2013-10-11 Show GitHub Exploit DB Packet Storm
291984 - cisco unified_communications_manager Directory traversal vulnerability in the Tomcat administrative web interface in Cisco Unified Communications Manager allows remote authenticated users to read arbitrary files via directory traversal … CWE-22
Path Traversal
CVE-2013-5528 2024-11-21 10:57 2013-10-11 Show GitHub Exploit DB Packet Storm
291985 - cisco ios
ios_xe
The OSPF functionality in Cisco IOS and IOS XE allows remote attackers to cause a denial of service (device reload) via crafted options in an LSA type 11 packet, aka Bug ID CSCui21030. CWE-20
 Improper Input Validation 
CVE-2013-5527 2024-11-21 10:57 2013-10-10 Show GitHub Exploit DB Packet Storm
291986 - cisco unified_ip_phone_9951
unified_ip_phone_9971
Cisco 9900 fourth-generation IP phones do not properly perform SDP negotiation, which allows remote attackers to cause a denial of service (device reboot) via crafted SDP packets, aka Bug ID CSCuf066… CWE-20
 Improper Input Validation 
CVE-2013-5526 2024-11-21 10:57 2013-10-10 Show GitHub Exploit DB Packet Storm
291987 - cisco identity_services_engine_software SQL injection vulnerability in the web framework in Cisco Identity Services Engine (ISE) 1.2 and earlier allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, a… CWE-89
SQL Injection
CVE-2013-5525 2024-11-21 10:57 2013-10-10 Show GitHub Exploit DB Packet Storm
291988 - cisco identity_services_engine_software Cross-site scripting (XSS) vulnerability in the troubleshooting page in Cisco Identity Services Engine (ISE) 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via an unsp… CWE-79
Cross-site Scripting
CVE-2013-5524 2024-11-21 10:57 2013-10-10 Show GitHub Exploit DB Packet Storm
291989 - cisco identity_services_engine_software The Sponsor Portal in Cisco Identity Services Engine (ISE) 1.2 and earlier does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attack… CWE-20
 Improper Input Validation 
CVE-2013-5523 2024-11-21 10:57 2013-10-10 Show GitHub Exploit DB Packet Storm
291990 - cisco ios The remember feature in the DHCP server in Cisco IOS allows remote attackers to cause a denial of service (device reload) by acquiring a lease and then sending a DHCPRELEASE message, aka Bug ID CSCuh… NVD-CWE-noinfo
CVE-2013-5499 2024-11-21 10:57 2013-10-10 Show GitHub Exploit DB Packet Storm