Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 31, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
218841 4.3 警告 Stranger Studios - WordPress 用 SS Downloads プラグインの templates/download.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-4554 2014-07-7 18:26 2014-05-28 Show GitHub Exploit DB Packet Storm
218842 4.3 警告 ZeenShare project - WordPress 用 ZeenShare プラグインの redirect_to_zeenshare.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-4606 2014-07-7 18:26 2014-01-11 Show GitHub Exploit DB Packet Storm
218843 4.3 警告 Smackcoders - WordPress 用 WP Ultimate Email Marketer プラグインの contact/edit.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-4600 2014-07-7 18:26 2014-04-25 Show GitHub Exploit DB Packet Storm
218844 4.3 警告 RuslanY Blog - WordPress 用 WP Silverlight Media Player プラグインの uploader.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-4589 2014-07-7 18:26 2014-04-25 Show GitHub Exploit DB Packet Storm
218845 4.3 警告 techteam internet services - WordPress 用 WP-Business Directory プラグインの forms/search.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-4599 2014-07-7 18:26 2014-04-25 Show GitHub Exploit DB Packet Storm
218846 4.3 警告 swicks - WordPress 用 WooCommerce SagePay Direct Payment Gateway プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-4549 2014-07-7 18:26 2014-04-25 Show GitHub Exploit DB Packet Storm
218847 4.3 警告 Rezgo project - WordPress 用 Rezgo プラグインの book_ajax.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-4546 2014-07-7 18:26 2014-05-28 Show GitHub Exploit DB Packet Storm
218848 4.3 警告 wp-tmkm-amazon project - WordPress 用 wp-tmkm-amazon プラグインの wp-tmkm-amazon-search.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-4598 2014-07-7 18:26 2014-06-12 Show GitHub Exploit DB Packet Storm
218849 4.3 警告 Shaon - WordPress 用 Hot Files: File Sharing and Download Manager プラグインの tpls/editmedia.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-4588 2014-07-7 18:26 2014-04-25 Show GitHub Exploit DB Packet Storm
218850 4.3 警告 SVN Labs Softwares. - WordPress 用 HTML5 Video Player with Playlist プラグインの videoplayer/autoplay.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-4534 2014-07-7 18:26 2014-04-25 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 31, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
296921 - xen xen Xen 3.4 through 4.2, and possibly earlier versions, allows local guest OS administrators to cause a denial of service (Xen infinite loop and physical CPU consumption) by setting a VCPU with an "inapp… CWE-399
 Resource Management Errors
CVE-2012-4535 2024-11-21 10:43 2012-11-22 Show GitHub Exploit DB Packet Storm
296922 - mcrypt mcrypt Stack-based buffer overflow in mcrypt 2.6.8 and earlier allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long file name. NOTE: it … CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2012-4527 2024-11-21 10:43 2012-11-22 Show GitHub Exploit DB Packet Storm
296923 - uninett radsecproxy The DTLS support in radsecproxy before 1.6.2 does not properly verify certificates when there are configuration blocks with CA settings that are unrelated to the block being used for verifying the ce… CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-4566 2024-11-21 10:43 2012-11-20 Show GitHub Exploit DB Packet Storm
296924 - google web_toolkit Cross-site scripting (XSS) vulnerability in Google Web Toolkit (GWT) 2.4 Beta and release candidates before 2.4.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vector… CWE-79
Cross-site Scripting
CVE-2012-4563 2024-11-21 10:43 2012-11-20 Show GitHub Exploit DB Packet Storm
296925 - uninett radsecproxy radsecproxy before 1.6.1 does not properly verify certificates when there are configuration blocks with CA settings that are unrelated to the block being used for verifying the certificate chain, whi… CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-4523 2024-11-21 10:43 2012-11-20 Show GitHub Exploit DB Packet Storm
296926 - cups-pk-helper_project cups-pk-helper cups-pk-helper before 0.2.3 does not properly wrap the (1) cupsGetFile and (2) cupsPutFile function calls, which allows user-assisted remote attackers to read or overwrite sensitive files using CUPS … CWE-264
Permissions, Privileges, and Access Controls
CVE-2012-4510 2024-11-21 10:43 2012-11-20 Show GitHub Exploit DB Packet Storm
296927 - matomo matomo Cross-site scripting (XSS) vulnerability in Piwik before 1.9 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. CWE-79
Cross-site Scripting
CVE-2012-4541 2024-11-21 10:43 2012-11-19 Show GitHub Exploit DB Packet Storm
296928 - viewvc
debian
viewvc
debian_linux
Cross-site scripting (XSS) vulnerability in the "extra" details in the DiffSource._get_row function in lib/viewvc.py in ViewVC 1.0.x before 1.0.13 and 1.1.x before 1.1.16 allows remote authenticated … CWE-79
Cross-site Scripting
CVE-2012-4533 2024-11-21 10:43 2012-11-19 Show GitHub Exploit DB Packet Storm
296929 - steve_j_baker plib Stack-based buffer overflow in the error function in ssg/ssgParser.cxx in PLIB 1.8.5 allows remote attackers to execute arbitrary code via a crafted 3d model file that triggers a long error message, … CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2012-4552 2024-11-21 10:43 2012-11-19 Show GitHub Exploit DB Packet Storm
296930 - djangoproject django The django.http.HttpRequest.get_host function in Django 1.3.x before 1.3.4 and 1.4.x before 1.4.2 allows remote attackers to generate and display arbitrary URLs via crafted username and password Host… CWE-20
 Improper Input Validation 
CVE-2012-4520 2024-11-21 10:43 2012-11-19 Show GitHub Exploit DB Packet Storm