Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 6, 2026, noon

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
218681 6.8 警告 XYZScripts - WordPress 用 Newsletter Manager プラグインにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2012-6629 2014-01-21 17:03 2012-05-15 Show GitHub Exploit DB Packet Storm
218682 4.3 警告 XYZScripts - WordPress 用 Newsletter Manager プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-6628 2014-01-21 17:03 2012-04-20 Show GitHub Exploit DB Packet Storm
218683 4.3 警告 XYZScripts - WordPress 用 Newsletter Manager プラグインの admin/test_mail.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-6627 2014-01-21 17:02 2012-05-15 Show GitHub Exploit DB Packet Storm
218684 4.3 警告 VastHTML - WordPress 用 ForumPress WP Forum Server プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-6623 2014-01-21 17:01 2012-07-14 Show GitHub Exploit DB Packet Storm
218685 4.3 警告 VastHTML - WordPress 用 ForumPress WP Forum Server プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-6622 2014-01-21 17:01 2012-04-18 Show GitHub Exploit DB Packet Storm
218686 7.5 危険 VastHTML - WordPress 用 ForumPress WP Forum Server プラグインにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2012-6625 2014-01-21 16:09 2012-04-18 Show GitHub Exploit DB Packet Storm
218687 4.3 警告 Mightymess - WordPress 用 SoundCloud Is Gold プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-6624 2014-01-21 16:08 2012-05-15 Show GitHub Exploit DB Packet Storm
218688 7.5 危険 Brian Cabunac - b2ePMS の verify-user.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2012-6626 2014-01-21 14:52 2012-05-11 Show GitHub Exploit DB Packet Storm
218689 4.3 警告 Vessio - Vessio NetBill におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-6632 2014-01-21 14:26 2012-05-11 Show GitHub Exploit DB Packet Storm
218690 6.8 警告 Vessio - Vessio NetBill の accounts/admin/index.php におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2012-6631 2014-01-21 14:24 2012-05-11 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 6, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
295151 - sitracker support_incident_tracker Multiple cross-site request forgery (CSRF) vulnerabilities in Support Incident Tracker (aka SiT!) 3.65 allow remote attackers to hijack the authentication of user for requests that delete a user via … CWE-352
 Origin Validation Error
CVE-2011-5068 2024-11-21 10:33 2012-01-29 Show GitHub Exploit DB Packet Storm
295152 - sitracker support_incident_tracker move_uploaded_file.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated users to obtain sensitive information via the file name, which reveals the installation path in an error… CWE-200
Information Exposure
CVE-2011-5067 2024-11-21 10:33 2012-01-29 Show GitHub Exploit DB Packet Storm
295153 - tencent qqpphoto The Tencent QQPhoto (com.tencent.qqphoto) application 0.97 for Android does not properly protect data, which allows remote attackers to read or modify contact information and a password hash via a cr… CWE-264
Permissions, Privileges, and Access Controls
CVE-2011-4867 2024-11-21 10:33 2012-01-25 Show GitHub Exploit DB Packet Storm
295154 - kaixin001 kaixin001 The Kaixin001 (com.kaixin001.activity) application 1.3.1 and 1.3.3 for Android does not properly protect data, which allows remote attackers to read or modify contact information and a cleartext pass… CWE-200
Information Exposure
CVE-2011-4866 2024-11-21 10:33 2012-01-25 Show GitHub Exploit DB Packet Storm
295155 - tencent microblogpad
wblog
The Tencent WBlog (com.tencent.WBlog) 3.3.1 and MicroBlogPad 1.4.0 applications for Android do not properly protect data, which allows remote attackers to read or modify message drafts and search key… CWE-264
Permissions, Privileges, and Access Controls
CVE-2011-4865 2024-11-21 10:33 2012-01-25 Show GitHub Exploit DB Packet Storm
295156 - tencent mobileqq The Tencent MobileQQ (com.tencent.mobileqq) application 2.2 for Android does not properly protect data, which allows remote attackers to read or modify messages and a friends list via a crafted appli… CWE-264
Permissions, Privileges, and Access Controls
CVE-2011-4864 2024-11-21 10:33 2012-01-25 Show GitHub Exploit DB Packet Storm
295157 - tencent qqpimsecure The Tencent QQPimSecure (com.tencent.qqpimsecure) application 3.0.2 for Android does not properly protect data, which allows remote attackers to read or modify SMS/MMS messages and a contact list via… CWE-264
Permissions, Privileges, and Access Controls
CVE-2011-4863 2024-11-21 10:33 2012-01-25 Show GitHub Exploit DB Packet Storm
295158 - atvise atvise Unspecified vulnerability in the server in Certec EDV atvise before 2.1 allows remote attackers to cause a denial of service (daemon crash) via crafted requests to TCP port 4840. NVD-CWE-noinfo
CVE-2011-4873 2024-11-21 10:33 2012-01-20 Show GitHub Exploit DB Packet Storm
295159 - ibm websphere_application_server The SibRaRecoverableSiXaResource class in the Default Messaging Component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41 does not properly handle a Service Integration Bus (SIB) dump o… CWE-200
Information Exposure
CVE-2011-5066 2024-11-21 10:33 2012-01-15 Show GitHub Exploit DB Packet Storm
295160 - ibm websphere_application_server Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41 allows remote attackers to inject arbitrary web script or HTML via vectors related to web messag… CWE-79
Cross-site Scripting
CVE-2011-5065 2024-11-21 10:33 2012-01-15 Show GitHub Exploit DB Packet Storm