Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 14, 2026, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
219971 10 危険 GateHouse
Harris
Thuraya Telecommunications
Hughes Network Systems
日本無線株式会社
Inmarsat plc.
- 複数の衛星通信端末のファームウェアにおける任意のコードを実行される脆弱性 CWE-287
CWE-Other
CVE-2013-6035 2014-02-5 17:50 2013-10-4 Show GitHub Exploit DB Packet Storm
219972 10 危険 GateHouse
Harris
Thuraya Telecommunications
Hughes Network Systems
日本無線株式会社
Inmarsat plc.
- 複数の衛星通信端末のファームウェアにおける不特定のログインアクセス権を取得される脆弱性 CWE-255
CWE-Other
CVE-2013-6034 2014-02-5 17:49 2013-10-4 Show GitHub Exploit DB Packet Storm
219973 3.5 注意 Lexmark - Lexmark の複数のプリンタ製品におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-6033 2014-02-5 17:05 2013-10-4 Show GitHub Exploit DB Packet Storm
219974 10 危険 Lexmark - Lexmark の複数のプリンタ製品の cgi-bin/postpf/cgi-bin/dynamic/config/config.html における Password Protect の管理パスワードを削除される脆弱性 CWE-20
CWE-Other
CVE-2013-6032 2014-02-5 17:00 2013-10-4 Show GitHub Exploit DB Packet Storm
219975 4 警告 IBM - IBM General Parallel File System におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2014-0834 2014-02-5 16:12 2014-01-31 Show GitHub Exploit DB Packet Storm
219976 6.8 警告 IBM - IBM InfoSphere Master Data Management - Collaborative Edition および InfoSphere Master Data Management Server for Product Information Management におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2013-5427 2014-02-5 16:11 2013-08-22 Show GitHub Exploit DB Packet Storm
219977 9.3 危険 ZTE - ZTE ZXV10 W300 に認証情報がハードコードされている問題 CWE-255
CWE-Other
CVE-2014-0329 2014-02-5 15:50 2014-02-3 Show GitHub Exploit DB Packet Storm
219978 4.9 警告 クアルコム
Android for MSM
- MSM デバイス用 Qualcomm Innovation Center Android コントリビューションなどで使用される Linux Kernel 用 MSM カメラドライバにおける重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2013-4739 2014-02-5 11:54 2013-10-15 Show GitHub Exploit DB Packet Storm
219979 7.2 危険 クアルコム
Android for MSM
- MSM デバイス用 Qualcomm Innovation Center Android コントリビューションなどで使用される Linux Kernel 用 MSM カメラドライバにおけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2013-4738 2014-02-5 11:53 2013-10-15 Show GitHub Exploit DB Packet Storm
219980 8.5 危険 ISC, Inc.
アップル
VMware
- ISC BIND にサービス運用妨害 (DoS) の脆弱性 CWE-189
数値処理の問題
CVE-2012-1667 2014-02-4 18:13 2012-06-5 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 15, 2026, 4:28 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1571 6.4 MEDIUM
Network
- - AccessPress Social Icons 1.8.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by entering JavaScript payloads into the 'icon titl… Update CWE-79
Cross-site Scripting
CVE-2021-47910 2026-05-12 23:24 2026-05-10 Show GitHub Exploit DB Packet Storm
1572 6.4 MEDIUM
Network
- - Slider by Soliloquy 2.6.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the title parameter. Attackers can add JavaScrip… Update CWE-79
Cross-site Scripting
CVE-2021-47922 2026-05-12 23:24 2026-05-10 Show GitHub Exploit DB Packet Storm
1573 9.8 CRITICAL
Network
- - OpenCart 3.0.3.8 contains a session fixation vulnerability that allows attackers to hijack user sessions by injecting arbitrary values into the OCSESSID cookie. Attackers can set malicious OCSESSID c… Update CWE-290
 Authentication Bypass by Spoofing
CVE-2021-47923 2026-05-12 23:24 2026-05-10 Show GitHub Exploit DB Packet Storm
1574 6.4 MEDIUM
Network
- - Ultimate Product Catalog 5.8.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the price parameter. Attackers can submit P… Update CWE-79
Cross-site Scripting
CVE-2021-47924 2026-05-12 23:24 2026-05-10 Show GitHub Exploit DB Packet Storm
1575 6.4 MEDIUM
Network
- - CMDBuild 3.3.2 contains multiple stored cross-site scripting vulnerabilities that allow authenticated attackers to inject arbitrary web script or HTML via crafted input in card creation and file uplo… Update CWE-79
Cross-site Scripting
CVE-2021-47925 2026-05-12 23:24 2026-05-10 Show GitHub Exploit DB Packet Storm
1576 6.4 MEDIUM
Network
- - Contact Form to Email 1.3.24 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by creating forms with script tags in the form name f… Update CWE-79
Cross-site Scripting
CVE-2021-47926 2026-05-12 23:24 2026-05-10 Show GitHub Exploit DB Packet Storm
1577 6.4 MEDIUM
Network
- - WordPress Plugin WP Symposium Pro 2021.10 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by exploiting insufficient sanitization … Update CWE-79
Cross-site Scripting
CVE-2021-47927 2026-05-12 23:24 2026-05-10 Show GitHub Exploit DB Packet Storm
1578 8.2 HIGH
Network
- - Opencart TMD Vendor System 3.x contains a blind SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through the product_id paramete… Update CWE-89
SQL Injection
CVE-2021-47928 2026-05-12 23:24 2026-05-10 Show GitHub Exploit DB Packet Storm
1579 9.8 CRITICAL
Network
- - WordPress TheCartPress 1.5.3.6 contains an unauthenticated privilege escalation vulnerability that allows attackers to create administrator accounts by submitting crafted requests to the AJAX handler… Update CWE-862
 Missing Authorization
CVE-2021-47932 2026-05-12 23:24 2026-05-10 Show GitHub Exploit DB Packet Storm
1580 9.8 CRITICAL
Network
- - WordPress MStore API 2.0.6 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to the REST API endpoint. Attackers… Update CWE-306
Missing Authentication for Critical Function
CVE-2021-47933 2026-05-12 23:24 2026-05-10 Show GitHub Exploit DB Packet Storm