Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 10, 2026, 2 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
209241 10 危険 日立
オラクル
- 複数の Oracle Java 製品における 2D に関する脆弱性 CWE-noinfo
情報不足
CVE-2015-2638 2015-11-5 18:04 2015-07-14 Show GitHub Exploit DB Packet Storm
209242 5 警告 サン・マイクロシステムズ
日立
オラクル
- 複数の Oracle Java 製品 における JAXP に関する脆弱性 CWE-noinfo
情報不足
CVE-2015-4911 2015-11-5 17:07 2015-10-20 Show GitHub Exploit DB Packet Storm
209243 5 警告 サン・マイクロシステムズ
日立
オラクル
- Oracle Java SE および Java SE Embedded における RMI に関する脆弱性 CWE-noinfo
情報不足
CVE-2015-4903 2015-11-5 17:07 2015-10-20 Show GitHub Exploit DB Packet Storm
209244 5 警告 サン・マイクロシステムズ
日立
オラクル
- Oracle Java SE における Deployment に関する脆弱性 CWE-noinfo
情報不足
CVE-2015-4902 2015-11-5 17:07 2015-10-20 Show GitHub Exploit DB Packet Storm
209245 10 危険 サン・マイクロシステムズ
日立
オラクル
- Oracle Java SE および Java SE Embedded における RMI に関する脆弱性 CWE-noinfo
情報不足
CVE-2015-4883 2015-11-5 17:07 2015-10-20 Show GitHub Exploit DB Packet Storm
209246 5 警告 サン・マイクロシステムズ
日立
オラクル
- Oracle Java SE および Java SE Embedded における CORBA に関する脆弱性 CWE-noinfo
情報不足
CVE-2015-4882 2015-11-5 17:07 2015-10-20 Show GitHub Exploit DB Packet Storm
209247 10 危険 サン・マイクロシステムズ
日立
オラクル
- Oracle Java SE および Java SE Embedded における CORBA に関する脆弱性 CWE-noinfo
情報不足
CVE-2015-4881 2015-11-5 17:07 2015-10-20 Show GitHub Exploit DB Packet Storm
209248 5.8 警告 日立
オラクル
- Oracle Java SE における Libraries に関する脆弱性 CWE-noinfo
情報不足
CVE-2015-4871 2015-11-5 17:07 2015-10-20 Show GitHub Exploit DB Packet Storm
209249 7.6 危険 日立
オラクル
- Oracle Java SE および Java SE Embedded における Libraries に関する脆弱性 CWE-noinfo
情報不足
CVE-2015-4868 2015-11-5 17:07 2015-10-20 Show GitHub Exploit DB Packet Storm
209250 10 危険 サン・マイクロシステムズ
日立
オラクル
- Oracle Java SE および Java SE Embedded における RMI に関する脆弱性 CWE-noinfo
情報不足
CVE-2015-4860 2015-11-5 17:07 2015-10-20 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 10, 2026, 5 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
297631 - drupal drupal The Image module in Drupal 7.x before 7.19, when a private file system is used, does not properly restrict access to derivative images, which allows remote attackers to read derivative images of othe… CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-0246 2024-11-21 10:47 2013-07-17 Show GitHub Exploit DB Packet Storm
297632 - drupal drupal The printer friendly version functionality in the Book module in Drupal 6.x before 6.28 and 7.x before 7.19 does not properly restrict access to node that are part of a book outline, which allows rem… CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-0245 2024-11-21 10:47 2013-07-17 Show GitHub Exploit DB Packet Storm
297633 - moxiecode
wordpress
fedoraproject
plupload
wordpress
fedora
Cross-site scripting (XSS) vulnerability in Plupload.as in Moxiecode plupload before 1.5.5, as used in WordPress before 3.5.1 and other products, allows remote attackers to inject arbitrary web scrip… CWE-79
Cross-site Scripting
CVE-2013-0237 2024-11-21 10:47 2013-07-9 Show GitHub Exploit DB Packet Storm
297634 - wordpress wordpress Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.1 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) gallery shortcodes or (2) the con… CWE-79
Cross-site Scripting
CVE-2013-0236 2024-11-21 10:47 2013-07-9 Show GitHub Exploit DB Packet Storm
297635 - wordpress wordpress The XMLRPC API in WordPress before 3.5.1 allows remote attackers to send HTTP requests to intranet servers, and conduct port-scanning attacks, by specifying a crafted source URL for a pingback, relat… NVD-CWE-Other
CVE-2013-0235 2024-11-21 10:47 2013-07-9 Show GitHub Exploit DB Packet Storm
297636 - ibm business_process_manager Multiple cross-site scripting (XSS) vulnerabilities in IBM Business Process Manager (BPM) 7.5.1.x, 8.0.0.x, and 8.0.1 before FP1 allow remote authenticated users to inject arbitrary web script or HTM… CWE-79
Cross-site Scripting
CVE-2013-0581 2024-11-21 10:47 2013-07-6 Show GitHub Exploit DB Packet Storm
297637 - ibm sterling_b2b_integrator
sterling_file_gateway
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to obtain sensitive information about application implementation via unspecified vectors… CWE-200
Information Exposure
CVE-2013-0568 2024-11-21 10:47 2013-07-3 Show GitHub Exploit DB Packet Storm
297638 - ibm sterling_b2b_integrator
sterling_file_gateway
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to obtain sensitive information about application implementation via unspecified vectors… CWE-200
Information Exposure
CVE-2013-0567 2024-11-21 10:47 2013-07-3 Show GitHub Exploit DB Packet Storm
297639 - ibm sterling_b2b_integrator
sterling_file_gateway
Multiple SQL injection vulnerabilities in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote authenticated users to execute arbitrary SQL commands via unspecif… CWE-89
SQL Injection
CVE-2013-0560 2024-11-21 10:47 2013-07-3 Show GitHub Exploit DB Packet Storm
297640 - ibm sterling_b2b_integrator
sterling_file_gateway
IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote attackers to obtain sensitive information about application implementation via unspecified vectors. CWE-200
Information Exposure
CVE-2013-0558 2024-11-21 10:47 2013-07-3 Show GitHub Exploit DB Packet Storm