Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 2, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
217461 4.3 警告 Plone Foundation
Zope Foundation
- Plone で使用される Zope の AccessControl/AuthEncoding.py におけるパスワードを取得される脆弱性 CWE-362
競合状態
CVE-2012-5507 2014-10-3 15:06 2012-11-6 Show GitHub Exploit DB Packet Storm
217462 4.3 警告 ヒューレット・パッカード - HP System Management Homepage におけるクリックジャッキング攻撃を実行される脆弱性 CWE-20
不適切な入力確認
CVE-2014-2642 2014-10-3 15:06 2014-09-30 Show GitHub Exploit DB Packet Storm
217463 5 警告 Plone Foundation - Plone の python_scripts.py におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2012-5506 2014-10-3 15:06 2012-11-6 Show GitHub Exploit DB Packet Storm
217464 6 警告 ヒューレット・パッカード - HP System Management Homepage におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2014-2641 2014-10-3 15:05 2014-09-30 Show GitHub Exploit DB Packet Storm
217465 5 警告 Plone Foundation - Plone の atat.py におけるプライベートデータ構造を読まれる脆弱性 CWE-200
情報漏えい
CVE-2012-5505 2014-10-3 14:53 2012-11-6 Show GitHub Exploit DB Packet Storm
217466 5 警告 Plone Foundation - Plone の Kupu の kupu_spellcheck.py におけるサービス運用妨害 (DoS) 状態にされる脆弱性 CWE-399
リソース管理の問題
CVE-2012-5496 2014-10-3 14:51 2012-11-6 Show GitHub Exploit DB Packet Storm
217467 6.5 警告 Plone Foundation
Zope Foundation
- Plone で使用される Zope における制限された属性へのアクセス権を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-5489 2014-10-3 14:47 2012-11-6 Show GitHub Exploit DB Packet Storm
217468 6.4 警告 Plone Foundation
Zope Foundation
- Plone で使用される Zope の ZPublisher.HTTPRequest._scrubHeader における任意の HTTP ヘッダを挿入される脆弱性 CWE-Other
その他
CVE-2012-5486 2014-10-3 14:47 2012-11-6 Show GitHub Exploit DB Packet Storm
217469 4.3 警告 Your Online Shop - Your Online Shop におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-6618 2014-10-3 14:19 2014-09-20 Show GitHub Exploit DB Packet Storm
217470 4.3 警告 MediaWiki - MediaWiki におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-7199 2014-10-3 11:48 2014-09-24 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 2, 2026, 4:18 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
290941 - siemens scalance_x-200_series_firmware
scalance_x-200
scalance_x-200irt
The integrated web server on Siemens SCALANCE X-200 switches with firmware before 4.5.0 and X-200IRT switches with firmware before 5.1.0 does not properly enforce authentication requirements, which a… CWE-287
Improper Authentication
CVE-2013-5944 2024-11-21 10:58 2013-10-3 Show GitHub Exploit DB Packet Storm
290942 - springsignage xibo Directory traversal vulnerability in Spring Signage Xibo 1.2.x before 1.2.3 and 1.4.x before 1.4.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the p parameter to index.php. CWE-22
Path Traversal
CVE-2013-5979 2024-11-21 10:58 2013-10-3 Show GitHub Exploit DB Packet Storm
290943 - f5 big-ip_access_policy_manager Cross-site scripting (XSS) vulnerability in the access policy logout page (logout.inc) in F5 BIG-IP APM 10.1.0 through 10.2.4 and 11.1.0 through 11.3.0 allows remote attackers to inject arbitrary web… CWE-79
Cross-site Scripting
CVE-2013-5976 2024-11-21 10:58 2013-10-2 Show GitHub Exploit DB Packet Storm
290944 - f5 big-ip_access_policy_manager The access policy logon page (logon.inc) in F5 BIG-IP APM 11.1.0 through 11.2.1 allows remote attackers to conduct clickjacking attacks via unspecified vectors. CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-5975 2024-11-21 10:58 2013-10-2 Show GitHub Exploit DB Packet Storm
290945 - david_king
canonical
vino
ubuntu_linux
The vino_server_client_data_pending function in vino-server.c in GNOME Vino 2.26.1, 2.32.1, 3.7.3, and earlier, and 3.8 when encryption is disabled, does not properly clear client data when an error … CWE-20
 Improper Input Validation 
CVE-2013-5745 2024-11-21 10:58 2013-10-2 Show GitHub Exploit DB Packet Storm
290946 - metaclassy byword The Metaclassy Byword app 2.x before 2.1 for iOS does not require confirmation of Replace file actions, which allows remote attackers to overwrite arbitrary files via the name and text parameters in … CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-5725 2024-11-21 10:58 2013-10-1 Show GitHub Exploit DB Packet Storm
290947 - cdsincdesign simple_dropbox_upload_form Unrestricted file upload vulnerability in multi.php in Simple Dropbox Upload plugin before 1.8.8.1 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executab… NVD-CWE-Other
CVE-2013-5963 2024-11-21 10:58 2013-10-1 Show GitHub Exploit DB Packet Storm
290948 - envato complete_gallery_manager_plugin Unrestricted file upload vulnerability in frames/upload-images.php in the Complete Gallery Manager plugin before 3.3.4 rev40279 for WordPress allows remote attackers to execute arbitrary code by uplo… NVD-CWE-Other
CVE-2013-5962 2024-11-21 10:58 2013-10-1 Show GitHub Exploit DB Packet Storm
290949 - danny_morris lazy_seo Unrestricted file upload vulnerability in lazyseo.php in the Lazy SEO plugin 1.1.9 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a PHP file, then accessing it via a… NVD-CWE-Other
CVE-2013-5961 2024-11-21 10:58 2013-10-1 Show GitHub Exploit DB Packet Storm
290950 - adcisolutions node_view_permissions The Node View Permissions module 7.x-1.x before 7.x-1.2 for Drupal does not properly implement the hook_query_alter function, which might allow remote attackers to obtain sensitive information by rea… CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-5965 2024-11-21 10:58 2013-10-1 Show GitHub Exploit DB Packet Storm