Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 18, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
216311 7.5 危険 Jan Bartels - TYPO3 用 WEC Map エクステンションにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2014-6295 2014-10-7 17:39 2014-02-12 Show GitHub Exploit DB Packet Storm
216312 4.3 警告 External links click statistics project - TYPO3 用 External links click statistics エクステンションにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-6294 2014-10-7 17:38 2014-02-12 Show GitHub Exploit DB Packet Storm
216313 7.5 危険 Kennziffer.com - TYPO3 用 Statistics エクステンションにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2014-6293 2014-10-7 17:37 2014-02-12 Show GitHub Exploit DB Packet Storm
216314 6.4 警告 Alex Kellner - TYPO3 用 femanager エクステンションにおける他のフロントエンドユーザのレコードを変更または削除される脆弱性 CWE-noinfo
情報不足
CVE-2014-6292 2014-10-7 17:36 2014-02-12 Show GitHub Exploit DB Packet Storm
216315 4.3 警告 Alphabetic Sitemap project - TYPO3 用 Alphabetic Sitemap エクステンションにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-6291 2014-10-7 17:34 2014-02-12 Show GitHub Exploit DB Packet Storm
216316 7.5 危険 Rupert Germann - TYPO3 用 News エクステンションにおける脆弱性 CWE-20
不適切な入力確認
CVE-2014-6290 2014-10-7 17:33 2014-02-12 Show GitHub Exploit DB Packet Storm
216317 7.5 危険 Daniel Lienert
Michael Knoll
- TYPO3 用 Yet Another Gallery および Tools for Extbase development エクステンションの Ajax dispatcher for Extbase におけるアクセス制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-6289 2014-10-7 17:30 2014-02-12 Show GitHub Exploit DB Packet Storm
216318 7.5 危険 Alex Kellner - TYPO3 用 powermail エクステンションにおける CAPTCHA 保護メカニズムを回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-6288 2014-10-7 17:29 2014-04-10 Show GitHub Exploit DB Packet Storm
216319 7.5 危険 Alex Kellner - TYPO3 用 powermail エクステンションにおける任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2014-3947 2014-10-7 17:28 2014-05-22 Show GitHub Exploit DB Packet Storm
216320 9.3 危険 TP-LINK Technologies - TP-LINK WR1043ND ルータのファームウェアにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2013-2645 2014-10-7 16:48 2013-04-29 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 18, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
294971 - cms-center simple_web_content_management_system Multiple SQL injection vulnerabilities in Simple Web Content Management System 1.1 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) item_delete.php, (2) item_statu… CWE-89
SQL Injection
CVE-2012-3791 2024-11-21 10:41 2012-06-22 Show GitHub Exploit DB Packet Storm
294972 - adiscon loganalyzer Cross-site scripting (XSS) vulnerability in index.php in Adiscon LogAnalyzer before 3.4.4 and 3.5.x before 3.5.5 allows remote attackers to inject arbitrary web script or HTML via the highlight param… CWE-79
Cross-site Scripting
CVE-2012-3790 2024-11-21 10:41 2012-06-21 Show GitHub Exploit DB Packet Storm
294973 - wordpress plugin_newsletter_plugin Directory traversal vulnerability in preview.php in the Plugin Newsletter plugin 1.5 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the data parameter. CWE-22
Path Traversal
CVE-2012-3588 2024-11-21 10:41 2012-06-20 Show GitHub Exploit DB Packet Storm
294974 - debian advanced_package_tool APT 0.7.x before 0.7.25 and 0.8.x before 0.8.16, when using the apt-key net-update to import keyrings, relies on GnuPG argument order and does not check GPG subkeys, which might allow remote attacker… CWE-20
 Improper Input Validation 
CVE-2012-3587 2024-11-21 10:41 2012-06-20 Show GitHub Exploit DB Packet Storm
294975 - digium asterisk chan_skinny.c in the Skinny (aka SCCP) channel driver in Asterisk Open Source 10.x before 10.5.1 allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon cr… NVD-CWE-Other
CVE-2012-3553 2024-11-21 10:41 2012-06-20 Show GitHub Exploit DB Packet Storm
294976 - wordpress fcchat_widget Unrestricted file upload vulnerability in html/Upload.php in the FCChat Widget plugin 2.2.13.1 and earlier for WordPress allows remote attackers to execute arbitrary code by uploading a file with a f… CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-3578 2024-11-21 10:41 2012-06-17 Show GitHub Exploit DB Packet Storm
294977 - nmedia member_conversation Unrestricted file upload vulnerability in doupload.php in the Nmedia Member Conversation plugin before 1.4 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an … CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-3577 2024-11-21 10:41 2012-06-17 Show GitHub Exploit DB Packet Storm
294978 - jquindlen wpstorecart Unrestricted file upload vulnerability in php/upload.php in the wpStoreCart plugin before 2.5.30 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable… CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-3576 2024-11-21 10:41 2012-06-16 Show GitHub Exploit DB Packet Storm
294979 - rbx_gallery rbx_gallery Unrestricted file upload vulnerability in uploader.php in the RBX Gallery plugin 2.1 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, … CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-3575 2024-11-21 10:41 2012-06-16 Show GitHub Exploit DB Packet Storm
294980 - tbelmans mm_forms_community Unrestricted file upload vulnerability in includes/doajaxfileupload.php in the MM Forms Community plugin 2.2.5 and 2.2.6 for WordPress allows remote attackers to execute arbitrary code by uploading a… NVD-CWE-Other
CVE-2012-3574 2024-11-21 10:41 2012-06-16 Show GitHub Exploit DB Packet Storm