Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 10, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
216671 4.3 警告 Alex Kellner - TYPO3 用 powermail エクステンションの backend モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-3948 2014-06-6 15:13 2014-05-22 Show GitHub Exploit DB Packet Storm
216672 7.5 危険 Ingy dot Net - Perl 用 Spoon モジュールの Session::Cookie における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2012-6143 2014-06-6 14:51 2012-12-6 Show GitHub Exploit DB Packet Storm
216673 7.5 危険 Jochen Wiedmann - Perl 用 HTML::EP モジュールの Session::Cookie における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2012-6142 2014-06-6 14:50 2012-12-6 Show GitHub Exploit DB Packet Storm
216674 4 警告 ownCloud - ownCloud Server における任意のプレビュー画像にアクセスされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-3963 2014-06-6 14:11 2014-01-22 Show GitHub Exploit DB Packet Storm
216675 4 警告 ownCloud - ownCloud Server における他のユーザのファイル名を読まれる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-3838 2014-06-6 14:11 2014-04-29 Show GitHub Exploit DB Packet Storm
216676 4 警告 ownCloud - ownCloud Server の document アプリケーションにおける共有ファイルを列挙される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-3837 2014-06-6 14:10 2014-04-29 Show GitHub Exploit DB Packet Storm
216677 6.8 警告 ownCloud - ownCloud Server におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2014-3836 2014-06-6 14:10 2014-04-29 Show GitHub Exploit DB Packet Storm
216678 7.5 危険 ownCloud - ownCloud Server における LDAP インジェクション攻撃を実行される脆弱性 CWE-94
コード・インジェクション
CVE-2014-2051 2014-06-6 14:09 2014-03-3 Show GitHub Exploit DB Packet Storm
216679 4 警告 ownCloud - ownCloud Server における任意のカレンダーを読まれる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-0304 2014-06-6 14:08 2013-02-20 Show GitHub Exploit DB Packet Storm
216680 5 警告 ownCloud - ownCloud Server における重要な情報を取得される脆弱性 CWE-noinfo
情報不足
CVE-2013-0302 2014-06-6 14:07 2013-02-17 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 10, 2026, 4:58 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
293201 - apache wicket Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.21 and 1.5.x before 1.5.8 allows remote attackers to inject arbitrary web script or HTML via vectors involving a %00 sequenc… CWE-79
Cross-site Scripting
CVE-2012-3373 2024-11-21 10:40 2012-09-20 Show GitHub Exploit DB Packet Storm
293202 - oscommerce
paypal
online_merchant
website_payments_standard_module
The PayPal (aka MODULE_PAYMENT_PAYPAL_STANDARD) module before 1.1 in osCommerce Online Merchant before 2.3.4 allows remote attackers to set the payment recipient via a modified value of the merchant'… NVD-CWE-Other
CVE-2012-2991 2024-11-21 10:40 2012-09-20 Show GitHub Exploit DB Packet Storm
293203 - hp operations_orchestration Unspecified vulnerability in HP Operations Orchestration 9.0 before 9.03 allows remote attackers to execute arbitrary code via unknown vectors. NVD-CWE-noinfo
CVE-2012-3258 2024-11-21 10:40 2012-09-19 Show GitHub Exploit DB Packet Storm
293204 - siemens simatic_pcs7
wincc
WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allows remote attackers to discover a username and password via crafted parameters to unspecified method… CWE-200
Information Exposure
CVE-2012-3034 2024-11-21 10:40 2012-09-18 Show GitHub Exploit DB Packet Storm
293205 - siemens simatic_pcs7
wincc
SQL injection vulnerability in WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allows remote attackers to execute arbitrary SQL commands via a crafted S… CWE-89
SQL Injection
CVE-2012-3032 2024-11-21 10:40 2012-09-18 Show GitHub Exploit DB Packet Storm
293206 - siemens simatic_pcs7
wincc
Multiple cross-site scripting (XSS) vulnerabilities in WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allow remote attackers to inject arbitrary web sc… CWE-79
Cross-site Scripting
CVE-2012-3031 2024-11-21 10:40 2012-09-18 Show GitHub Exploit DB Packet Storm
293207 - siemens simatic_pcs7
wincc
WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, stores sensitive information under the web root with insufficient access control, which allows remote at… CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-3030 2024-11-21 10:40 2012-09-18 Show GitHub Exploit DB Packet Storm
293208 - siemens simatic_pcs7
wincc
Cross-site request forgery (CSRF) vulnerability in WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allows remote attackers to hijack the authentication … CWE-352
 Origin Validation Error
CVE-2012-3028 2024-11-21 10:40 2012-09-18 Show GitHub Exploit DB Packet Storm
293209 - cososys endpoint_protector_appliace_4 The CoSoSys Endpoint Protector 4 appliance establishes an EPProot password based entirely on the appliance serial number, which makes it easier for remote attackers to obtain access via a brute-force… CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-2994 2024-11-21 10:40 2012-09-18 Show GitHub Exploit DB Packet Storm
293210 5.9 MEDIUM
Network
microsoft windows_phone_7_firmware Microsoft Windows Phone 7 does not verify the domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL server for the (1) … CWE-295
Improper Certificate Validation 
CVE-2012-2993 2024-11-21 10:40 2012-09-18 Show GitHub Exploit DB Packet Storm