Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 9, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
220401 5.5 警告 シスコシステムズ - Cisco Unified Communications Manager の Real Time Monitoring Tool の実装における任意のファイルを読まれる脆弱性 CWE-20
不適切な入力確認
CVE-2014-3292 2014-06-11 17:10 2014-06-10 Show GitHub Exploit DB Packet Storm
220402 4 警告 シスコシステムズ - Cisco Unified Communications Domain Manager の Java インターフェースにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2014-3287 2014-06-11 17:09 2014-06-9 Show GitHub Exploit DB Packet Storm
220403 4.3 警告 シスコシステムズ - Cisco AsyncOS 製品にクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-3289 2014-06-11 16:37 2014-06-10 Show GitHub Exploit DB Packet Storm
220404 6 警告 (複数のベンダ) - 複数製品の UEFI ファームウェアの実装に脆弱性 - CVE-2014-2961 2014-06-11 16:19 2014-06-9 Show GitHub Exploit DB Packet Storm
220405 4.3 警告 Misery Project - Drupal 用 Misery モジュールにおけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2013-4599 2014-06-11 15:55 2013-11-13 Show GitHub Exploit DB Packet Storm
220406 4 警告 Rik de Boer - Drupal 用 Revisioning モジュールにおける重要な情報を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-4597 2014-06-11 15:54 2013-11-13 Show GitHub Exploit DB Packet Storm
220407 5 警告 Gordon Heydon - Drupal 用 Secure Pages モジュールにおける重要な情報を取得される脆弱性 CWE-310
暗号の問題
CVE-2013-4595 2014-06-11 15:54 2013-11-6 Show GitHub Exploit DB Packet Storm
220408 4 警告 Marc Ferran - Drupal 用 Autocomplete Widgets for Text and Number Fields モジュールにおける重要なフィールドの値を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-1973 2014-06-11 15:53 2013-04-17 Show GitHub Exploit DB Packet Storm
220409 4.3 警告 Jojo Open Source Content Management System - Jojo CMS の plugins/jojo_core/forgot_password.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-3082 2014-06-11 15:32 2013-05-7 Show GitHub Exploit DB Packet Storm
220410 7.5 危険 Jojo Open Source Content Management System - Jojo CMS の plugins/jojo_core/classes/Jojo.php の checkEmailFormat 関数における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2013-3081 2014-06-11 15:32 2013-05-7 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 9, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
292451 - dhtmlx dhtmlxspreadsheet Cross-site scripting (XSS) vulnerability in codebase/spreadsheet.php in the Spreadsheet (dhtmlxSpreadsheet) plugin 2.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via… CWE-79
Cross-site Scripting
CVE-2013-6281 2024-11-21 10:58 2013-10-25 Show GitHub Exploit DB Packet Storm
292452 - linksalpha social_sharing_toolkit_plugin Cross-site scripting (XSS) vulnerability in Social Sharing Toolkit plugin before 2.1.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. CWE-79
Cross-site Scripting
CVE-2013-6280 2024-11-21 10:58 2013-10-25 Show GitHub Exploit DB Packet Storm
292453 - dell quest_one_password_manager The Dell Quest One Password Manager, possibly 5.0, allows remote attackers to bypass CAPTCHA protections and obtain sensitive information (user's full name) by sending a login request with a valid do… CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-6246 2024-11-21 10:58 2013-10-24 Show GitHub Exploit DB Packet Storm
292454 - sybase adaptive_server_enterprise Unspecified vulnerability in SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3. 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 allows remote authenticated users to … NVD-CWE-noinfo
CVE-2013-6245 2024-11-21 10:58 2013-10-24 Show GitHub Exploit DB Packet Storm
292455 - sap netweaver The Live Update webdynpro application (webdynpro/dispatcher/sap.com/tc~slm~ui_lup/LUP) in SAP NetWeaver 7.31 and earlier allows remote attackers to read arbitrary files and directories via an XML doc… NVD-CWE-noinfo
CVE-2013-6244 2024-11-21 10:58 2013-10-24 Show GitHub Exploit DB Packet Storm
292456 - landing_pages_project landing_pages_plugin SQL injection vulnerability in the Landing Pages plugin 1.2.3, before 20131009, and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the "post" parameter to index.p… CWE-89
SQL Injection
CVE-2013-6243 2024-11-21 10:58 2013-10-24 Show GitHub Exploit DB Packet Storm
292457 - vmware vcenter_server Session fixation vulnerability in the vSphere Web Client Server in VMware vCenter Server 5.0 before Update 3 allows remote attackers to hijack web sessions and gain privileges via unspecified vectors. CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-5971 2024-11-21 10:58 2013-10-21 Show GitHub Exploit DB Packet Storm
292458 - vmware esx
esxi
hostd-vmdb in VMware ESXi 4.0 through 5.0 and ESX 4.0 through 4.1 allows remote attackers to cause a denial of service (hostd-vmdb service outage) by modifying management traffic. CWE-20
 Improper Input Validation 
CVE-2013-5970 2024-11-21 10:58 2013-10-21 Show GitHub Exploit DB Packet Storm
292459 - vbulletin vbulletin The install/upgrade.php scripts in vBulletin 4.1 and 5 allow remote attackers to create administrative accounts via the customerid, htmldata[password], htmldata[confirmpassword], and htmldata[email] … CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-6129 2024-11-21 10:58 2013-10-19 Show GitHub Exploit DB Packet Storm
292460 - dlink dir-100 Stack-based buffer overflow in the RuntimeDiagnosticPing function in /bin/webs on D-Link DIR-100 routers might allow remote authenticated administrators to execute arbitrary commands via a long set/r… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2013-6027 2024-11-21 10:58 2013-10-19 Show GitHub Exploit DB Packet Storm