Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 8, 2026, noon

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
216841 5.8 警告 フォーティネット - Fortinet Fortiweb におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2014-3115 2014-05-12 17:43 2014-05-7 Show GitHub Exploit DB Packet Storm
216842 4.3 警告 Google - Google 検索アプライアンス ダイナミック ナビゲーションにクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-0362 2014-05-12 17:43 2014-05-1 Show GitHub Exploit DB Packet Storm
216843 4.3 警告 Bradesco Gateway Plugin project - WP e-Commerce プラグインで使用される Wordpress 用 Bradesco Gateway プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-5916 2014-05-12 17:42 2013-09-23 Show GitHub Exploit DB Packet Storm
216844 2.1 注意 WpGetReady - WordPress 用 NextCellent Gallery プラグインの admin/manage-images.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-3123 2014-05-12 17:23 2014-04-23 Show GitHub Exploit DB Packet Storm
216845 3.5 注意 OpenStack - OpenStack Compute のインスタンスレスキューモードにおける特定の compute ホストファイルを読まれる脆弱性 CWE-200
情報漏えい
CVE-2014-0134 2014-05-12 17:20 2014-03-31 Show GitHub Exploit DB Packet Storm
216846 4.3 警告 Fedora Project
Digia
- Qt の QtGui の GIF デコーダにおけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2014-0190 2014-05-12 17:15 2014-04-24 Show GitHub Exploit DB Packet Storm
216847 1.9 注意 The Foreman - Foreman で使用される Kafo におけるパスワードおよびその他の重要な情報を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-0135 2014-05-12 17:02 2014-04-9 Show GitHub Exploit DB Packet Storm
216848 5 警告 The Foreman - Foreman における重要な情報を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-0192 2014-05-12 17:02 2014-04-24 Show GitHub Exploit DB Packet Storm
216849 6.8 警告 The Foreman - Foreman における Web セッションをハイジャックされる脆弱性 CWE-287
不適切な認証
CVE-2014-0090 2014-05-12 17:00 2014-02-26 Show GitHub Exploit DB Packet Storm
216850 4.3 警告 Slashes and Dots Sdn Bhd - Offiria におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-2689 2014-05-12 16:57 2014-05-7 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 8, 2026, 4:54 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
295581 - silverstripe silverstripe Cross-site scripting (XSS) vulnerability in the process function in SSViewer.php in SilverStripe before 2.3.13 and 2.4.x before 2.4.6 allows remote attackers to inject arbitrary web script or HTML vi… CWE-79
Cross-site Scripting
CVE-2011-4958 2024-11-21 10:33 2014-04-8 Show GitHub Exploit DB Packet Storm
295582 - condor_project
fedoraproject
redhat
condor
fedora
enterprise_mrg
Multiple format string vulnerabilities in Condor 7.2.0 through 7.6.4, and possibly certain 7.7.x versions, as used in Red Hat MRG Grid and possibly other products, allow local users to cause a denial… CWE-134
Use of Externally-Controlled Format String
CVE-2011-4930 2024-11-21 10:33 2014-02-11 Show GitHub Exploit DB Packet Storm
295583 - memcached memcached Multiple integer signedness errors in the (1) process_bin_sasl_auth, (2) process_bin_complete_sasl_auth, (3) process_bin_update, and (4) process_bin_append_prepend functions in Memcached 1.4.5 and ea… CWE-189
Numeric Errors
CVE-2011-4971 2024-11-21 10:33 2013-12-13 Show GitHub Exploit DB Packet Storm
295584 - freeradius freeradius modules/rlm_unix/rlm_unix.c in FreeRADIUS before 2.2.0, when unix mode is enabled for user authentication, does not properly check the password expiration in /etc/shadow, which allows remote authenti… CWE-255
Credentials Management
CVE-2011-4966 2024-11-21 10:33 2013-03-13 Show GitHub Exploit DB Packet Storm
295585 - jquery jquery Cross-site scripting (XSS) vulnerability in jQuery before 1.6.3, when using location.hash to select elements, allows remote attackers to inject arbitrary web script or HTML via a crafted tag. CWE-79
Cross-site Scripting
CVE-2011-4969 2024-11-21 10:33 2013-03-9 Show GitHub Exploit DB Packet Storm
295586 - appthemes classipress Multiple cross-site scripting (XSS) vulnerabilities in the Classipress theme before 3.1.5 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) twitter_id parameter … CWE-79
Cross-site Scripting
CVE-2011-5257 2024-11-21 10:33 2013-02-13 Show GitHub Exploit DB Packet Storm
295587 - limesurvey limesurvey Cross-site scripting (XSS) vulnerability in the tooltips in LimeSurvey before 1.91+ Build 11379-20111116, when viewing survey results, allows remote attackers to inject arbitrary web script or HTML v… CWE-79
Cross-site Scripting
CVE-2011-5256 2024-11-21 10:33 2013-02-13 Show GitHub Exploit DB Packet Storm
295588 - x3cms x3_cms Multiple cross-site scripting (XSS) vulnerabilities in admin/login in X3 CMS 0.4.3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO, (2) username, or … CWE-79
Cross-site Scripting
CVE-2011-5255 2024-11-21 10:33 2013-01-31 Show GitHub Exploit DB Packet Storm
295589 - connections_project connections Unspecified vulnerability in the Connections plugin before 0.7.1.6 for WordPress has unknown impact and attack vectors. NVD-CWE-noinfo
CVE-2011-5254 2024-11-21 10:33 2013-01-12 Show GitHub Exploit DB Packet Storm
295590 - thegr dl Dl Download Ticket Service 0.3 through 0.9 allows remote attackers to login as an arbitrary user by supplying an authorization header. CWE-287
Improper Authentication
CVE-2011-5253 2024-11-21 10:33 2013-01-12 Show GitHub Exploit DB Packet Storm