Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 26, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
213881 4.3 警告 Boone Gorges - WordPress 用 Unconfirmed プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-100018 2015-01-16 14:26 2014-04-10 Show GitHub Exploit DB Packet Storm
213882 4.3 警告 Photocrati Media - WordPress 用 Photocrati テーマの photocrati-gallery/ecomm-sizes.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-100016 2015-01-16 14:10 2014-01-29 Show GitHub Exploit DB Packet Storm
213883 7.5 危険 WP Symposium - WordPress 用 WP Symposium プラグインの UploadHandler.php における任意のコードを実行される脆弱性 CWE-Other
その他
CVE-2014-10021 2015-01-16 14:03 2014-12-11 Show GitHub Exploit DB Packet Storm
213884 4.3 警告 コルネ株式会社 - WordPress 用 Welcart e-Commerce プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-10016 2015-01-16 13:51 2014-03-3 Show GitHub Exploit DB Packet Storm
213885 7.5 危険 Another WordPress Classifieds Plugin - WordPress 用 Another WordPress Classifieds Plugin プラグインにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2014-10013 2015-01-16 13:37 2014-11-8 Show GitHub Exploit DB Packet Storm
213886 4.3 警告 Another WordPress Classifieds Plugin - WordPress 用 Another WordPress Classifieds Plugin プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-10012 2015-01-16 13:34 2014-11-8 Show GitHub Exploit DB Packet Storm
213887 1.9 注意 シーメンス - iOS 用 Siemens SIMATIC WinCC Sm@rtClient アプリにおける Sm@rtServer の認証情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2014-5233 2015-01-16 11:55 2014-08-13 Show GitHub Exploit DB Packet Storm
213888 1.9 注意 シーメンス - iOS 用 Siemens SIMATIC Sm@rtClient アプリにおけるアプリケーションのパスワード要求を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-5232 2015-01-16 11:52 2014-08-13 Show GitHub Exploit DB Packet Storm
213889 2.1 注意 シーメンス - iOS 用 Siemens SIMATIC WinCC Sm@rtClient アプリにおけるストレージからパスワードを抽出される脆弱性 CWE-200
情報漏えい
CVE-2014-5231 2015-01-16 11:41 2014-08-13 Show GitHub Exploit DB Packet Storm
213890 5 警告 Joomlaskin - WordPress 用 Joomlaskin JS Multi Hotel プラグインにおけるインストールパスを取得される脆弱性 CWE-200
情報漏えい
CVE-2014-100009 2015-01-16 11:34 2014-03-29 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 26, 2026, 4:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
2651 6.5 MEDIUM
Network
- - WebDyne::Session versions through 2.075 for Perl generates the session id insecurely. The session handler generates the session id from an MD5 hash seeded with a call to the built-in rand() function… CWE-338
CWE-340
 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
 Generation of Predictable Numbers or Identifiers
CVE-2026-5084 2026-05-13 01:48 2026-05-11 Show GitHub Exploit DB Packet Storm
2652 6.5 MEDIUM
Network
- - HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values. The unvalidated inputs are the method and URI in the request line, the URL host t… CWE-113
HTTP Response Splitting
CVE-2026-7010 2026-05-13 01:48 2026-05-12 Show GitHub Exploit DB Packet Storm
2653 9.8 CRITICAL
Network
- - Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Akilli Commerce Software Technologies Ltd. Co. E-Commerce Website allows SQL Injection. This iss… CWE-89
SQL Injection
CVE-2025-6577 2026-05-13 01:47 2026-05-12 Show GitHub Exploit DB Packet Storm
2654 8.8 HIGH
Network
- - Authorization bypass through User-Controlled key vulnerability in ABIS Technology Ltd. Co. BAPSİS allows Exploitation of Trusted Identifiers. This issue affects BAPSİS: before v.202604152042. CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-6001 2026-05-13 01:47 2026-05-12 Show GitHub Exploit DB Packet Storm
2655 8.8 HIGH
Network
- - Incorrect Authorization vulnerability in E-Kalite Software Hardware Engineering Design and Internet Services Industry and Trade Ltd. Co. Turboard FOR-S allows Privilege Escalation. This issue affect… CWE-863
 Incorrect Authorization
CVE-2026-2465 2026-05-13 01:47 2026-05-12 Show GitHub Exploit DB Packet Storm
2656 - - - ZEBRA is a Zcash node written entirely in Rust. Prior to version 4.4.0, a composite denial-of-service vulnerability in Zebra's block discovery pipeline allows an unauthenticated remote attacker to pe… CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2026-44499 2026-05-13 01:45 2026-05-9 Show GitHub Exploit DB Packet Storm
2657 5.3 MEDIUM
Network
- - novaGallery is a php image gallery. Prior to version 2.1.1, a path traversal vulnerability has been identified in novaGallery. This allows unauthenticated users to read image files outside the intend… CWE-22
Path Traversal
CVE-2026-42028 2026-05-13 01:45 2026-05-9 Show GitHub Exploit DB Packet Storm
2658 7.5 HIGH
Network
- - Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts. The built-in rand function is predictable, and unsuitable for cryptography. CWE-338
 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
CVE-2026-6659 2026-05-13 01:45 2026-05-9 Show GitHub Exploit DB Packet Storm
2659 - - - Emlog is an open source website building system. Prior to version 2.6.11, insecure plugin upload functionality allows attackers to upload and execute arbitrary PHP code, leading to complete server co… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2026-41517 2026-05-13 01:45 2026-05-9 Show GitHub Exploit DB Packet Storm
2660 9.1 CRITICAL
Network
- - Plunk is an open-source email platform built on top of AWS SES. Prior to version 0.9.0, the /webhooks/sns endpoint accepts Amazon SNS notification payloads from unauthenticated requests without verif… CWE-347
 Improper Verification of Cryptographic Signature
CVE-2026-42193 2026-05-13 01:45 2026-05-9 Show GitHub Exploit DB Packet Storm