Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 13, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
217851 5.8 警告 サイボウズ - サイボウズ リモートサービスマネージャーにおけるセッション固定の脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-1984 2014-04-28 17:58 2014-04-18 Show GitHub Exploit DB Packet Storm
217852 4.3 警告 Ushahidi - Ushahidi Platform におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-2025 2014-04-28 17:51 2013-05-1 Show GitHub Exploit DB Packet Storm
217853 3.5 注意 Episerver - Ektron CMS の content.aspx におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-2729 2014-04-28 17:42 2014-04-16 Show GitHub Exploit DB Packet Storm
217854 9.3 危険 Power Software - Power Software の WinArchiver におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2013-5660 2014-04-28 17:13 2013-04-29 Show GitHub Exploit DB Packet Storm
217855 4.3 警告 JoomlaBoat.com - Joomla! 用 YouTube Gallery コンポーネントにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-5956 2014-04-28 16:17 2013-09-27 Show GitHub Exploit DB Packet Storm
217856 6.8 警告 OpenX - OpenX におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2013-5954 2014-04-28 16:04 2013-09-27 Show GitHub Exploit DB Packet Storm
217857 4.3 警告 Moxiecode Systems AB - TinyMCE の bbcode プラグインにおけるクロスサイトスクリプティング攻撃を実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-4230 2014-04-28 15:49 2012-08-9 Show GitHub Exploit DB Packet Storm
217858 9.3 危険 3S-Smart Software Solutions
SoftMotion3D
Festo
- Festo Modular controllers CECX-X-C1 および CECX-X-M1 における設定を変更される脆弱性 CWE-287
不適切な認証
CVE-2014-0769 2014-04-28 15:40 2014-04-24 Show GitHub Exploit DB Packet Storm
217859 9.3 危険 3S-Smart Software Solutions
SoftMotion3D
Festo
- Festo Modular controllers CECX-X-C1 および CECX-X-M1 における任意のコードを実行される脆弱性 CWE-287
不適切な認証
CVE-2014-0760 2014-04-28 15:40 2014-04-24 Show GitHub Exploit DB Packet Storm
217860 4.3 警告 Open-Xchange - Open-Xchange AppSuite におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-2393 2014-04-28 15:07 2014-04-8 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 13, 2026, 5:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
296531 - clausmuus spitfire Cross-site scripting (XSS) vulnerability in Spitfire CMS 1.0.436 allows remote attackers to inject arbitrary web script or HTML via a cms_username cookie. CWE-79
Cross-site Scripting
CVE-2011-5303 2024-11-21 10:34 2015-01-1 Show GitHub Exploit DB Packet Storm
296532 - kubelabs phpdug Cross-site request forgery (CSRF) vulnerability in adm/admin_edit.php in PHPDug 2.0.0 allows remote attackers to hijack the authentication of administrators for requests that modify credentials. CWE-352
 Origin Validation Error
CVE-2011-5302 2024-11-21 10:34 2015-01-1 Show GitHub Exploit DB Packet Storm
296533 - kubelabs phpdug Multiple cross-site scripting (XSS) vulnerabilities in PHPDug 2.0.0 allow remote attackers to inject arbitrary web script or HTML via (1) the story_url parameter to add_story.php, (2) the email param… CWE-79
Cross-site Scripting
CVE-2011-5301 2024-11-21 10:34 2015-01-1 Show GitHub Exploit DB Packet Storm
296534 - pommo pommo-ardvark Cross-site request forgery (CSRF) vulnerability in admin/setup/config/users.php in poMMo Aardvark PR16.1 allows remote attackers to hijack the authentication of administrators for requests that modif… CWE-352
 Origin Validation Error
CVE-2011-5300 2024-11-21 10:34 2015-01-1 Show GitHub Exploit DB Packet Storm
296535 - pommo pommo-ardvark Multiple cross-site scripting (XSS) vulnerabilities in poMMo Aardvark PR16.1 allow remote attackers to inject arbitrary web script or HTML via (1) the referer parameter to index.php, (2) the site_nam… CWE-79
Cross-site Scripting
CVE-2011-5299 2024-11-21 10:34 2015-01-1 Show GitHub Exploit DB Packet Storm
296536 - viralheat argyle_social Multiple cross-site request forgery (CSRF) vulnerabilities in Argyle Social 2011-04-26 allow remote attackers to hijack the authentication of administrators for requests that (1) modify credentials v… CWE-352
 Origin Validation Error
CVE-2011-5298 2024-11-21 10:34 2015-01-1 Show GitHub Exploit DB Packet Storm
296537 - ttfreeware tigertoms_chat_room Multiple cross-site scripting (XSS) vulnerabilities in TTChat 1.0.4 allow remote attackers to inject arbitrary web script or HTML via (1) the msg parameter to default.php or (2) the username paramete… CWE-79
Cross-site Scripting
CVE-2011-5297 2024-11-21 10:34 2015-01-1 Show GitHub Exploit DB Packet Storm
296538 - tuttophp happy_chat Cross-site scripting (XSS) vulnerability in profilo.php in Happy Chat 1.0 allows remote attackers to inject arbitrary web script or HTML via the nick parameter. CWE-79
Cross-site Scripting
CVE-2011-5296 2024-11-21 10:34 2015-01-1 Show GitHub Exploit DB Packet Storm
296539 - gogago gogago_youtube_video_converter Buffer overflow in the Download method in a certain ActiveX control in MDIEEx.dll in Gogago YouTube Video Converter 1.1.6 allows remote attackers to execute arbitrary code via a long argument. CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2011-5295 2024-11-21 10:34 2015-01-1 Show GitHub Exploit DB Packet Storm
296540 - kofax kofax_e-transactions_sender_sendbox The SaveMessage method in the LEADeMail.LEADSmtp.20 ActiveX control in LTCML14n.dll 14.0.0.34 in Kofax e-Transactions Sender Sendbox 2.5.0.933 allows remote attackers to write to arbitrary files via … CWE-264
Permissions, Privileges, and Access Controls
CVE-2011-5294 2024-11-21 10:34 2015-01-1 Show GitHub Exploit DB Packet Storm