Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 15, 2026, 4:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
216311 7.5 危険 HumHub - HumHub の protected/modules_core/notification/controllers/ListController.php の actionIndex 関数における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2014-9528 2015-01-9 16:32 2014-11-28 Show GitHub Exploit DB Packet Storm
216312 7.5 危険 Debian - Debian mime-support パッケージの run-mailcap における任意のコマンドを実行される脆弱性 CWE-Other
その他
CVE-2014-7209 2015-01-9 16:25 2014-12-29 Show GitHub Exploit DB Packet Storm
216313 4.3 警告 Palo Alto Networks - Palo Alto Networks PAN-OS の web-based デバイス管理インターフェースにおけるクロスサイトスクリプティングの脆弱性 CWE-89
SQLインジェクション
CVE-2014-3764 2015-01-9 16:19 2014-12-22 Show GitHub Exploit DB Packet Storm
216314 4.3 警告 Apache Software Foundation - Apache Solr の Admin UI Plugin / Stats ページにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-3628 2015-01-9 16:04 2014-12-29 Show GitHub Exploit DB Packet Storm
216315 4.3 警告 コンクリートファイブ - concrete5 におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-9526 2015-01-9 15:58 2014-12-9 Show GitHub Exploit DB Packet Storm
216316 6.8 警告 Timed Popup project - WordPress 用 Timed Popup プラグインにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2014-9525 2015-01-9 15:55 2014-12-12 Show GitHub Exploit DB Packet Storm
216317 6.8 警告 Vinoj Cardoza - WordPress 用 Facebook Like Box プラグインにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2014-9524 2015-01-9 15:54 2014-12-12 Show GitHub Exploit DB Packet Storm
216318 6.8 警告 Smartcat - WordPress 用 Our Team Showcase プラグインにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2014-9523 2015-01-9 15:54 2014-12-12 Show GitHub Exploit DB Packet Storm
216319 4.3 警告 Papoo Software - CMS Papoo Light におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-9522 2015-01-9 15:25 2014-12-15 Show GitHub Exploit DB Packet Storm
216320 7.5 危険 InfiniteWP - InfiniteWP Admin Panel の uploadScript.php における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2014-9521 2015-01-9 14:59 2014-12-10 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 15, 2026, 4:10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
296711 - crunchify foursquare-checkins Cross-site request forgery (CSRF) vulnerability in the FourSquare Checkins plugin before 1.3 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that in… CWE-352
 Origin Validation Error
CVE-2013-2709 2024-11-21 10:52 2013-04-26 Show GitHub Exploit DB Packet Storm
296712 - citrix netscaler_access_gateway_firmware
netscaler_access_gateway
Unspecified vulnerability in Citrix NetScaler Access Gateway Enterprise Edition (AGEE) before 9.3.62.4 and 10.x through 10.0.74.4, and NetScaler AGEE Common Criteria build before 9.3.53.6, allows rem… NVD-CWE-noinfo
CVE-2013-2767 2024-11-21 10:52 2013-04-26 Show GitHub Exploit DB Packet Storm
296713 - crunchify all-in-on-webmaster Cross-site request forgery (CSRF) vulnerability in the All in One Webmaster plugin before 8.2.4 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that… CWE-352
 Origin Validation Error
CVE-2013-2696 2024-11-21 10:52 2013-04-26 Show GitHub Exploit DB Packet Storm
296714 - lexmark markvision Lexmark Markvision Enterprise before 1.8 provides a diagnostic interface on TCP port 9789, which allows remote attackers to execute arbitrary code, change the configuration, or obtain sensitive fleet… CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-3055 2024-11-21 10:52 2013-04-25 Show GitHub Exploit DB Packet Storm
296715 - linux linux_kernel The crypto API in the Linux kernel through 3.9-rc8 does not initialize certain length variables, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvms… CWE-200
Information Exposure
CVE-2013-3076 2024-11-21 10:52 2013-04-22 Show GitHub Exploit DB Packet Storm
296716 - siemens simatic_s7-1200_firmware
simatic_s7-1200_cpu_1211c_firmware
simatic_s7-1200_cpu_1212c_firmware
simatic_s7-1200_cpu_1212fc_firmware
simatic_s7-1200_cpu_1214_fc_firmware
simatic_s7-1200_…
Siemens SIMATIC S7-1200 PLCs 2.x and 3.x allow remote attackers to cause a denial of service (defect-mode transition and control outage) via crafted packets to UDP port 161 (aka the SNMP port). NVD-CWE-noinfo
CVE-2013-2780 2024-11-21 10:52 2013-04-22 Show GitHub Exploit DB Packet Storm
296717 - apache activemq The web console in Apache ActiveMQ before 5.8.0 does not require authentication, which allows remote attackers to obtain sensitive information or cause a denial of service via HTTP requests. CWE-287
Improper Authentication
CVE-2013-3060 2024-11-21 10:52 2013-04-22 Show GitHub Exploit DB Packet Storm
296718 - mitsubishi-automation
schneider-electric
mitsubishi_mx_component
citectfacilities
citectscada
Multiple buffer overflows in ActUWzd.dll 1.0.0.1 in Mitsubishi MX Component 3, as distributed in Citect CitectFacilities 7.10 and CitectScada 7.10r1, allow remote attackers to execute arbitrary code … CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2013-3075 2024-11-21 10:52 2013-04-19 Show GitHub Exploit DB Packet Storm
296719 - lester_chan wp-downloadmanager Cross-site request forgery (CSRF) vulnerability in the WP-DownloadManager plugin before 1.61 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that in… CWE-352
 Origin Validation Error
CVE-2013-2697 2024-11-21 10:52 2013-04-19 Show GitHub Exploit DB Packet Storm
296720 - google chrome_os Google Chrome OS before 26.0.1410.57 does not properly enforce origin restrictions for the O3D and Google Talk plug-ins, which allows remote attackers to bypass the domain-whitelist protection mechan… CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-2835 2024-11-21 10:52 2013-04-17 Show GitHub Exploit DB Packet Storm