Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 11, 2026, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
216641 4.3 警告 Flash Photo Gallery project - WordPress 用 Flash Photo Gallery プラグインの fpg_preview.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-4529 2014-07-4 18:26 2014-04-25 Show GitHub Exploit DB Packet Storm
216642 4.3 警告 Game tabs project - WordPress 用 Game tabs プラグインの main_page.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-4531 2014-07-4 18:26 2014-04-25 Show GitHub Exploit DB Packet Storm
216643 4.3 警告 Rodrigo Primo - WordPress 用 Social Connect プラグインの diagnostics/test.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-4551 2014-07-4 18:26 2014-04-25 Show GitHub Exploit DB Packet Storm
216644 4.3 警告 EnvialoSimple - WordPress 用 EnvialoSimple: Email Marketing and Newsletters プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-4527 2014-07-4 18:26 2014-05-28 Show GitHub Exploit DB Packet Storm
216645 4.3 警告 efence project - WordPress 用 efence プラグインの callback.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-4526 2014-07-4 18:26 2014-05-28 Show GitHub Exploit DB Packet Storm
216646 4.3 警告 WP Easy Post Types project - WordPress 用 WP Easy Post Types プラグインの classes/custom-image/media.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-4524 2014-07-4 18:26 2014-05-28 Show GitHub Exploit DB Packet Storm
216647 4.3 警告 Diverse Solutions - WordPress 用 dsSearchAgent: WordPress Edition プラグインの client-assist.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-4522 2014-07-4 18:26 2014-04-25 Show GitHub Exploit DB Packet Storm
216648 6.8 警告 Cherokee Project - Cherokee の validator_ldap.c 内の cherokee_validator_ldap_check 関数における認証を回避される脆弱性 CWE-287
不適切な認証
CVE-2014-4668 2014-07-4 14:01 2014-02-12 Show GitHub Exploit DB Packet Storm
216649 5.1 警告 Google - Android の KeyStore サービスの /system/bin/keystore におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2014-3100 2014-07-4 13:56 2014-06-23 Show GitHub Exploit DB Packet Storm
216650 5.5 警告 IBM - IBM Sametime Meeting Server の stconf.nsf におけるアップロードの制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-3088 2014-07-4 11:24 2014-07-1 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 12, 2026, 5:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
292621 - mozilla
suse
opensuse
canonical
firefox
seamonkey
thunderbird
linux_enterprise_server
linux_enterprise_desktop
opensuse
linux_enterprise_software_development_kit
ubuntu_linux
The XrayWrapper implementation in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 does not consider the compartment during property filtering, which allows remote atta… CWE-200
Information Exposure
CVE-2012-4208 2024-11-21 10:42 2012-11-21 Show GitHub Exploit DB Packet Storm
292622 - mozilla
suse
opensuse
canonical
redhat
firefox
seamonkey
thunderbird
thunderbird_esr
linux_enterprise_server
linux_enterprise_desktop
opensuse
linux_enterprise_software_development_kit
ubuntu_linux
enterprise_li…
Use-after-free vulnerability in the nsPlaintextEditor::FireClipboardEvent function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x befor… CWE-416
 Use After Free
CVE-2012-4215 2024-11-21 10:42 2012-11-21 Show GitHub Exploit DB Packet Storm
292623 - mozilla
suse
opensuse
redhat
canonical
firefox
seamonkey
thunderbird
thunderbird_esr
linux_enterprise_server
linux_enterprise_desktop
opensuse
linux_enterprise_software_development_kit
enterprise_linux_server
en…
Use-after-free vulnerability in the nsTextEditorState::PrepareEditor function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.… CWE-416
 Use After Free
CVE-2012-4214 2024-11-21 10:42 2012-11-21 Show GitHub Exploit DB Packet Storm
292624 - mozilla
suse
opensuse
redhat
canonical
firefox
seamonkey
thunderbird
thunderbird_esr
linux_enterprise_server
linux_enterprise_desktop
opensuse
linux_enterprise_software_development_kit
enterprise_linux_server
en…
Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 do not prevent use of a "top" frame name-attribut… CWE-79
Cross-site Scripting
CVE-2012-4209 2024-11-21 10:42 2012-11-21 Show GitHub Exploit DB Packet Storm
292625 - mozilla
suse
opensuse
redhat
debian
canonical
firefox
seamonkey
thunderbird
thunderbird_esr
linux_enterprise_server
linux_enterprise_desktop
opensuse
linux_enterprise_software_development_kit
enterprise_linux_server
en…
The HZ-GB-2312 character-set implementation in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 do… CWE-79
Cross-site Scripting
CVE-2012-4207 2024-11-21 10:42 2012-11-21 Show GitHub Exploit DB Packet Storm
292626 - mozilla firefox Untrusted search path vulnerability in the installer in Mozilla Firefox before 17.0 and Firefox ESR 10.x before 10.0.11 on Windows allows local users to gain privileges via a Trojan horse DLL in the … NVD-CWE-Other
CVE-2012-4206 2024-11-21 10:42 2012-11-21 Show GitHub Exploit DB Packet Storm
292627 - mozilla
canonical
suse
opensuse
firefox
seamonkey
thunderbird
ubuntu_linux
linux_enterprise_desktop
linux_enterprise_software_development_kit
opensuse
linux_enterprise_server
Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 assign the system principal, rather than the sandbox principal, to XMLHttpRequest objects created in sandboxes, which a… CWE-352
 Origin Validation Error
CVE-2012-4205 2024-11-21 10:42 2012-11-21 Show GitHub Exploit DB Packet Storm
292628 - mozilla
suse
opensuse
canonical
firefox
seamonkey
thunderbird
linux_enterprise_server
linux_enterprise_desktop
opensuse
linux_enterprise_software_development_kit
ubuntu_linux
The str_unescape function in the JavaScript engine in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a deni… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2012-4204 2024-11-21 10:42 2012-11-21 Show GitHub Exploit DB Packet Storm
292629 - mozilla firefox The New Tab page in Mozilla Firefox before 17.0 uses a privileged context for execution of JavaScript code by bookmarklets, which allows user-assisted remote attackers to run arbitrary programs by le… CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-4203 2024-11-21 10:42 2012-11-21 Show GitHub Exploit DB Packet Storm
292630 - mozilla
suse
opensuse
canonical
redhat
firefox
seamonkey
thunderbird
thunderbird_esr
linux_enterprise_server
linux_enterprise_desktop
opensuse
linux_enterprise_software_development_kit
ubuntu_linux
enterprise_li…
Heap-based buffer overflow in the image::RasterImage::DrawFrameTo function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.1… CWE-787
 Out-of-bounds Write
CVE-2012-4202 2024-11-21 10:42 2012-11-21 Show GitHub Exploit DB Packet Storm