Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 5, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
217121 6.5 警告 Postfix Admin Project - Postfix Admin の functions.inc.php の gen_show_status 関数における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2014-2655 2014-04-4 14:27 2014-02-19 Show GitHub Exploit DB Packet Storm
217122 4.3 警告 Splunk - Splunk の Splunk Web におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-2578 2014-04-4 12:15 2014-03-24 Show GitHub Exploit DB Packet Storm
217123 3.5 注意 OTRS プロジェクト - Open Ticket Request System におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-2553 2014-04-4 12:03 2014-04-1 Show GitHub Exploit DB Packet Storm
217124 6.8 警告 HitMyServer - WordPress 用 HMS Testimonials プラグインにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2013-4240 2014-04-4 11:19 2013-08-8 Show GitHub Exploit DB Packet Storm
217125 3.5 注意 IBM - IBM WebSphere Portal の IBM Connections 統合におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-0901 2014-04-3 18:29 2014-03-31 Show GitHub Exploit DB Packet Storm
217126 4.3 警告 IBM - IBM WebSphere Portal の WCM UI におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-0828 2014-04-3 18:29 2014-03-31 Show GitHub Exploit DB Packet Storm
217127 4.3 警告 シスコシステムズ - Cisco Security Manager の Web フレームワークにおける CRLF インジェクションの脆弱性 CWE-20
不適切な入力確認
CVE-2014-2138 2014-04-3 18:22 2014-04-1 Show GitHub Exploit DB Packet Storm
217128 4.3 警告 シスコシステムズ - Cisco Web セキュリティ アプライアンスの Web フレームワークにおける CRLF インジェクションの脆弱性 CWE-20
不適切な入力確認
CVE-2014-2137 2014-04-3 18:18 2014-04-1 Show GitHub Exploit DB Packet Storm
217129 4.3 警告 シスコシステムズ - Cisco Unity Connection の Web Inbox におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-2125 2014-04-3 18:17 2014-04-1 Show GitHub Exploit DB Packet Storm
217130 5 警告 Posh portal project - POSH の portal/scr_authentif.php の Remember Me 機能における重要な情報を取得される脆弱性 CWE-255
証明書・パスワード管理
CVE-2014-2212 2014-04-3 18:14 2014-02-20 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 6, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
294911 - condor_project
fedoraproject
redhat
condor
fedora
enterprise_mrg
Multiple format string vulnerabilities in Condor 7.2.0 through 7.6.4, and possibly certain 7.7.x versions, as used in Red Hat MRG Grid and possibly other products, allow local users to cause a denial… CWE-134
Use of Externally-Controlled Format String
CVE-2011-4930 2024-11-21 10:33 2014-02-11 Show GitHub Exploit DB Packet Storm
294912 - memcached memcached Multiple integer signedness errors in the (1) process_bin_sasl_auth, (2) process_bin_complete_sasl_auth, (3) process_bin_update, and (4) process_bin_append_prepend functions in Memcached 1.4.5 and ea… CWE-189
Numeric Errors
CVE-2011-4971 2024-11-21 10:33 2013-12-13 Show GitHub Exploit DB Packet Storm
294913 - freeradius freeradius modules/rlm_unix/rlm_unix.c in FreeRADIUS before 2.2.0, when unix mode is enabled for user authentication, does not properly check the password expiration in /etc/shadow, which allows remote authenti… CWE-255
Credentials Management
CVE-2011-4966 2024-11-21 10:33 2013-03-13 Show GitHub Exploit DB Packet Storm
294914 - jquery jquery Cross-site scripting (XSS) vulnerability in jQuery before 1.6.3, when using location.hash to select elements, allows remote attackers to inject arbitrary web script or HTML via a crafted tag. CWE-79
Cross-site Scripting
CVE-2011-4969 2024-11-21 10:33 2013-03-9 Show GitHub Exploit DB Packet Storm
294915 - appthemes classipress Multiple cross-site scripting (XSS) vulnerabilities in the Classipress theme before 3.1.5 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) twitter_id parameter … CWE-79
Cross-site Scripting
CVE-2011-5257 2024-11-21 10:33 2013-02-13 Show GitHub Exploit DB Packet Storm
294916 - limesurvey limesurvey Cross-site scripting (XSS) vulnerability in the tooltips in LimeSurvey before 1.91+ Build 11379-20111116, when viewing survey results, allows remote attackers to inject arbitrary web script or HTML v… CWE-79
Cross-site Scripting
CVE-2011-5256 2024-11-21 10:33 2013-02-13 Show GitHub Exploit DB Packet Storm
294917 - x3cms x3_cms Multiple cross-site scripting (XSS) vulnerabilities in admin/login in X3 CMS 0.4.3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO, (2) username, or … CWE-79
Cross-site Scripting
CVE-2011-5255 2024-11-21 10:33 2013-01-31 Show GitHub Exploit DB Packet Storm
294918 - connections_project connections Unspecified vulnerability in the Connections plugin before 0.7.1.6 for WordPress has unknown impact and attack vectors. NVD-CWE-noinfo
CVE-2011-5254 2024-11-21 10:33 2013-01-12 Show GitHub Exploit DB Packet Storm
294919 - thegr dl Dl Download Ticket Service 0.3 through 0.9 allows remote attackers to login as an arbitrary user by supplying an authorization header. CWE-287
Improper Authentication
CVE-2011-5253 2024-11-21 10:33 2013-01-12 Show GitHub Exploit DB Packet Storm
294920 - orchardproject orchard Open redirect vulnerability in Users/Account/LogOff in Orchard 1.0.x before 1.0.21, 1.1.x before 1.1.31, 1.2.x before 1.2.42, and 1.3.x before 1.3.10 allows remote attackers to redirect users to arbi… CWE-20
 Improper Input Validation 
CVE-2011-5252 2024-11-21 10:33 2013-01-12 Show GitHub Exploit DB Packet Storm