Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 14, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
218931 4 警告 ownCloud - ownCloud の lib/migrate.php におけるユーザのアカウントに任意のファイルをインポートされる脆弱性 CWE-noinfo
情報不足
CVE-2013-1851 2014-03-19 13:44 2013-03-11 Show GitHub Exploit DB Packet Storm
218932 6.5 警告 ownCloud - ownCloud の apps/contacts/ の import.php および ajax/uploadimport.php における任意の PHP コードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2013-1850 2014-03-19 13:43 2013-03-11 Show GitHub Exploit DB Packet Storm
218933 3.5 注意 ownCloud - ownCloud におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-1822 2014-03-19 13:42 2013-03-11 Show GitHub Exploit DB Packet Storm
218934 6.8 警告 ownCloud - ownCloud の apps/calendar/ajax/settings/settimezone におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2013-0301 2014-03-19 13:41 2013-02-17 Show GitHub Exploit DB Packet Storm
218935 6.8 警告 ownCloud - ownCloud におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2013-0300 2014-03-19 13:40 2013-02-17 Show GitHub Exploit DB Packet Storm
218936 6.8 警告 ownCloud - ownCloud におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2013-0299 2014-03-19 13:39 2013-02-17 Show GitHub Exploit DB Packet Storm
218937 3.5 注意 ownCloud - ownCloud の settings.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-0307 2014-03-19 13:38 2013-02-17 Show GitHub Exploit DB Packet Storm
218938 4.3 警告 ownCloud - ownCloud におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-0298 2014-03-19 13:37 2013-02-17 Show GitHub Exploit DB Packet Storm
218939 3.5 注意 ownCloud - ownCloud におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-0297 2014-03-19 13:34 2013-02-17 Show GitHub Exploit DB Packet Storm
218940 10 危険 Mozilla Foundation - 複数の Mozilla 製品のエディタコンポーネントのテーブル編集ユーザインターフェースにおける任意のコードを実行される脆弱性 CWE-399
リソース管理の問題
CVE-2013-5618 2014-03-19 11:22 2013-12-10 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 14, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
292151 - moneybookers
oscommerce
moneybookers
oscommerce
The MoneyBookers module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows m… CWE-20
 Improper Input Validation 
CVE-2012-5794 2024-11-21 10:45 2012-11-5 Show GitHub Exploit DB Packet Storm
292152 - oscommerce
harald_ponce_de_leon
oscommerce
authorize.net
The Authorize.Net module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows … CWE-20
 Improper Input Validation 
CVE-2012-5793 2024-11-21 10:45 2012-11-5 Show GitHub Exploit DB Packet Storm
292153 - oscommerce
sagepay
oscommerce
sage_pay_direct_module
The Sage Pay Direct module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allow… CWE-20
 Improper Input Validation 
CVE-2012-5792 2024-11-21 10:45 2012-11-5 Show GitHub Exploit DB Packet Storm
292154 - paypal invoicing PayPal Invoicing does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle atta… CWE-20
 Improper Input Validation 
CVE-2012-5791 2024-11-21 10:45 2012-11-5 Show GitHub Exploit DB Packet Storm
292155 - paypal payments_standard PayPal Payments Standard PHP Library 20120427 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which … CWE-20
 Improper Input Validation 
CVE-2012-5790 2024-11-21 10:45 2012-11-5 Show GitHub Exploit DB Packet Storm
292156 - paypal payments_standard PayPal Payments Standard PHP Library before 20120427 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate,… CWE-20
 Improper Input Validation 
CVE-2012-5789 2024-11-21 10:45 2012-11-5 Show GitHub Exploit DB Packet Storm
292157 - paypal ipn The PayPal IPN utility does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middl… CWE-20
 Improper Input Validation 
CVE-2012-5788 2024-11-21 10:45 2012-11-5 Show GitHub Exploit DB Packet Storm
292158 - paypal merchant_sdk The PayPal merchant SDK does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-midd… CWE-20
 Improper Input Validation 
CVE-2012-5787 2024-11-21 10:45 2012-11-5 Show GitHub Exploit DB Packet Storm
292159 - apache cxf The wsdl_first_https sample code in distribution/src/main/release/samples/wsdl_first_https/src/main/ in Apache CXF before 2.7.0 does not verify that the server hostname matches a domain name in the s… CWE-20
 Improper Input Validation 
CVE-2012-5786 2024-11-21 10:45 2012-11-5 Show GitHub Exploit DB Packet Storm
292160 - apache axis2 Apache Axis2/Java 1.6.2 and earlier does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man… CWE-20
 Improper Input Validation 
CVE-2012-5785 2024-11-21 10:45 2012-11-5 Show GitHub Exploit DB Packet Storm