Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 13, 2026, 12:06 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
217491 6.8 警告 Zemanta - WordPress 用 Search Everything プラグインにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2014-3843 2014-05-26 15:32 2014-05-7 Show GitHub Exploit DB Packet Storm
217492 4.3 警告 iMember360 - WordPress 用 iMember360 プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-3842 2014-05-26 15:32 2014-04-24 Show GitHub Exploit DB Packet Storm
217493 4.3 警告 Tech Banker - WordPress 用 Contact Bank プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-3841 2014-05-26 15:31 2014-05-12 Show GitHub Exploit DB Packet Storm
217494 6.5 警告 DOTonPAPER - WordPress 用 Booking System プラグインの dopbs-backend-forms.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2014-3210 2014-05-26 15:31 2014-05-21 Show GitHub Exploit DB Packet Storm
217495 6.8 警告 Mail On Update Project - WordPress 用 Mail On Update プラグインにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2013-2107 2014-05-26 15:28 2013-05-16 Show GitHub Exploit DB Packet Storm
217496 7.5 危険 MicroP project - MicroP におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2010-5299 2014-05-26 15:10 2010-08-23 Show GitHub Exploit DB Packet Storm
217497 7.5 危険 エマソン - Emerson DeltaV におけるアクセス制限を回避される脆弱性 CWE-255
証明書・パスワード管理
CVE-2014-2350 2014-05-26 14:52 2014-05-22 Show GitHub Exploit DB Packet Storm
217498 4.6 警告 エマソン - Emerson DeltaV における設定ファイルを変更される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-2349 2014-05-26 14:51 2014-05-22 Show GitHub Exploit DB Packet Storm
217499 2.1 注意 Canonical
gdm-guest-session project
- Ubuntu で使用される gdm-guest-session の gdm/guest-session-cleanup.sh における任意のファイルを削除される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-6648 2014-05-26 14:50 2012-03-13 Show GitHub Exploit DB Packet Storm
217500 2.1 注意 Robert Ancell
Canonical
- Ubuntu で使用される Light Display Manager の debian/guest-account における任意のファイルを削除される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-0943 2014-05-26 14:50 2012-03-13 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 13, 2026, 5:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
296541 - threediffy threedify_designer The cmdSave method in the ThreeDify.ThreeDifyDesigner.1 ActiveX control in ActiveSolid.dll in ThreeDify Designer 5.0.2 allows remote attackers to write to arbitrary files via a pathname in the argume… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2011-5293 2024-11-21 10:34 2015-01-1 Show GitHub Exploit DB Packet Storm
296542 - easewe_software easewe_ftp_ocx_activex_control The EaseWeFtp.FtpLibrary ActiveX control in EaseWeFtp.ocx in Easewe FTP OCX 4.5.0.9 does not restrict access to certain methods, which allows remote attackers to execute arbitrary files via a pathnam… CWE-264
Permissions, Privileges, and Access Controls
CVE-2011-5292 2024-11-21 10:34 2015-01-1 Show GitHub Exploit DB Packet Storm
296543 - ashampoo_gmbh_\&_co. ashampoo_3d_cad_professional_3 The SaveData method in the Cygnicon.ViewControl.1 ActiveX control in CyViewer.ocx in Ashampoo 3D CAD Professional 3.x before 3.0.2 allows remote attackers to write to arbitrary files via a pathname i… CWE-264
Permissions, Privileges, and Access Controls
CVE-2011-5291 2024-11-21 10:34 2015-01-1 Show GitHub Exploit DB Packet Storm
296544 - idrive_inc idrive_online_backup The SaveToFile method in the UniBasicPack.UniTextBox ActiveX control in UniBasic100_EDA1811C.ocx in IDrive Online Backup 3.4.0 allows remote attackers to write to arbitrary files via a pathname in th… CWE-264
Permissions, Privileges, and Access Controls
CVE-2011-5290 2024-11-21 10:34 2015-01-1 Show GitHub Exploit DB Packet Storm
296545 - diego_uscanga atube_catcher The SaveDecrypted method in the ChilkatCrypt2.ChilkatOmaDrm.1 ActiveX control in ChilkatCrypt2.dll in aTube Catcher 2.3.570 allows remote attackers to write to arbitrary files via a pathname in the a… CWE-264
Permissions, Privileges, and Access Controls
CVE-2011-5289 2024-11-21 10:34 2015-01-1 Show GitHub Exploit DB Packet Storm
296546 - threedify threedify_designer Multiple buffer overflows in the ThreeDify.ThreeDifyDesigner.1 ActiveX control in ActiveSolid.dll in ThreeDify Designer 5.0.2 allow remote attackers to execute arbitrary code via a long argument to t… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2011-5288 2024-11-21 10:34 2015-01-1 Show GitHub Exploit DB Packet Storm
296547 - hesk hesk Multiple cross-site scripting (XSS) vulnerabilities in HESK before 2.4.1 allow remote attackers to inject arbitrary web script or HTML via the (1) hesk_settings[tmp_title] or (2) hesklang[ENCODING] p… CWE-79
Cross-site Scripting
CVE-2011-5287 2024-11-21 10:34 2015-01-1 Show GitHub Exploit DB Packet Storm
296548 - social_slider_project social_slider SQL injection vulnerability in social-slider-2/ajax.php in the Social Slider plugin before 7.4.2 for WordPress allows remote attackers to execute arbitrary SQL commands via the rA array parameter. CWE-89
SQL Injection
CVE-2011-5286 2024-11-21 10:34 2015-01-1 Show GitHub Exploit DB Packet Storm
296549 - bugfree bugfree Multiple cross-site scripting (XSS) vulnerabilities in BugFree 2.1.3 allow remote attackers to inject arbitrary web script or HTML via (1) the ActionType parameter to Bug.php, the ReportMode paramete… CWE-79
Cross-site Scripting
CVE-2011-5285 2024-11-21 10:34 2015-01-1 Show GitHub Exploit DB Packet Storm
296550 - smoothwall smoothwall Cross-site request forgery (CSRF) vulnerability in the web management interface in httpd/cgi-bin/shutdown.cgi in Smoothwall Express 3.1 and 3.0 SP3 and earlier allows remote attackers to hijack the a… CWE-352
 Origin Validation Error
CVE-2011-5284 2024-11-21 10:34 2015-01-1 Show GitHub Exploit DB Packet Storm