Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
209871 5.4 警告 equifax - Android 用 Equifax Mobile アプリケーションにおけるサーバになりすまされる脆弱性 CWE-310
暗号の問題
CVE-2014-6879 2014-12-17 09:57 2014-09-3 Show GitHub Exploit DB Packet Storm
209872 5.4 警告 rbfcu - Android 用 RBFCU Mobile アプリケーションにおけるサーバになりすまされる脆弱性 CWE-310
暗号の問題
CVE-2014-6878 2014-12-17 09:57 2014-09-3 Show GitHub Exploit DB Packet Storm
209873 5.4 警告 santanderbank - Android 用 Santander Personal Banking アプリケーションにおけるサーバになりすまされる脆弱性 CWE-310
暗号の問題
CVE-2014-6877 2014-12-17 09:57 2014-09-3 Show GitHub Exploit DB Packet Storm
209874 5.4 警告 serve - Android 用 American Express Serve アプリケーションにおけるサーバになりすまされる脆弱性 CWE-310
暗号の問題
CVE-2014-6876 2014-12-17 09:57 2014-09-3 Show GitHub Exploit DB Packet Storm
209875 5.4 警告 woodforest - Android 用 Woodforest Mobile Banking アプリケーションにおけるサーバになりすまされる脆弱性 CWE-310
暗号の問題
CVE-2014-6875 2014-12-17 09:57 2014-09-3 Show GitHub Exploit DB Packet Storm
209876 5.4 警告 concursive - Android 用 ModSim Connected アプリケーションにおけるサーバになりすまされる脆弱性 CWE-310
暗号の問題
CVE-2014-6874 2014-12-17 09:57 2014-09-3 Show GitHub Exploit DB Packet Storm
209877 5.4 警告 amecuae - Android 用 AMGC アプリケーションにおけるサーバになりすまされる脆弱性 CWE-310
暗号の問題
CVE-2014-6873 2014-12-17 09:57 2014-09-3 Show GitHub Exploit DB Packet Storm
209878 5.4 警告 ttnetmuzik - Android 用 TTNET Muzik アプリケーションにおけるサーバになりすまされる脆弱性 CWE-310
暗号の問題
CVE-2014-6872 2014-12-17 09:57 2014-09-3 Show GitHub Exploit DB Packet Storm
209879 5.4 警告 hogs fly crazy project - Android 用 Hogs Fly Crazy アプリケーションにおけるサーバになりすまされる脆弱性 CWE-310
暗号の問題
CVE-2014-6871 2014-12-17 09:57 2014-09-3 Show GitHub Exploit DB Packet Storm
209880 5.4 警告 bgenergy - Android 用 BGEnergy アプリケーションにおけるサーバになりすまされる脆弱性 CWE-310
暗号の問題
CVE-2014-6870 2014-12-17 09:57 2014-09-3 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 23, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
252631 - - - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in VdoCipher allows Stored XSS.This issue affects VdoCipher: from n/a through 1.29. CWE-79
Cross-site Scripting
CVE-2024-47639 2024-10-8 02:47 2024-10-5 Show GitHub Exploit DB Packet Storm
252632 - - - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in vCita Online Booking & Scheduling Calendar for WordPress by vcita allows Reflected XSS.Thi… CWE-79
Cross-site Scripting
CVE-2024-47638 2024-10-8 02:47 2024-10-5 Show GitHub Exploit DB Packet Storm
252633 - - - Cross-Site Request Forgery (CSRF) vulnerability in TinyPNG.This issue affects TinyPNG: from n/a through 3.4.3. CWE-352
 Origin Validation Error
CVE-2024-47635 2024-10-8 02:47 2024-10-5 Show GitHub Exploit DB Packet Storm
252634 - - - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Zoho Forms allows Stored XSS.This issue affects Zoho Forms: from n/a through 4.0. CWE-79
Cross-site Scripting
CVE-2024-47633 2024-10-8 02:47 2024-10-5 Show GitHub Exploit DB Packet Storm
252635 - - - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in deTheme DethemeKit For Elementor allows Stored XSS.This issue affects DethemeKit For Eleme… CWE-79
Cross-site Scripting
CVE-2024-47632 2024-10-8 02:47 2024-10-5 Show GitHub Exploit DB Packet Storm
252636 - - - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in bPlugins LLC Logo Carousel – Clients logo carousel for WP allows Stored XSS.This issue aff… CWE-79
Cross-site Scripting
CVE-2024-47631 2024-10-8 02:47 2024-10-5 Show GitHub Exploit DB Packet Storm
252637 5.3 MEDIUM
Network
automattic sensei_lms The Sensei LMS WordPress plugin before 4.24.2 does not properly protect some its REST API routes, allowing unauthenticated attackers to leak email templates. NVD-CWE-noinfo
CVE-2024-7786 2024-10-8 02:46 2024-09-4 Show GitHub Exploit DB Packet Storm
252638 4.3 MEDIUM
Network
snapshot_backup_project snapshot_backup The Snapshot Backup WordPress plugin through 2.1.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add St… CWE-352
 Origin Validation Error
CVE-2024-7689 2024-10-8 02:45 2024-09-9 Show GitHub Exploit DB Packet Storm
252639 4.3 MEDIUM
Network
azindex_project azindex The AZIndex WordPress plugin through 0.8.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS… CWE-352
 Origin Validation Error
CVE-2024-7687 2024-10-8 02:45 2024-09-9 Show GitHub Exploit DB Packet Storm
252640 4.8 MEDIUM
Network
myeventon eventon The EventON WordPress plugin before 2.2.17 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when un… CWE-79
Cross-site Scripting
CVE-2024-6910 2024-10-8 02:45 2024-09-9 Show GitHub Exploit DB Packet Storm