Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 23, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
222051 4.3 警告 ZeenShare project - WordPress 用 ZeenShare プラグインの redirect_to_zeenshare.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-4606 2014-07-7 18:26 2014-01-11 Show GitHub Exploit DB Packet Storm
222052 4.3 警告 Smackcoders - WordPress 用 WP Ultimate Email Marketer プラグインの contact/edit.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-4600 2014-07-7 18:26 2014-04-25 Show GitHub Exploit DB Packet Storm
222053 4.3 警告 RuslanY Blog - WordPress 用 WP Silverlight Media Player プラグインの uploader.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-4589 2014-07-7 18:26 2014-04-25 Show GitHub Exploit DB Packet Storm
222054 4.3 警告 techteam internet services - WordPress 用 WP-Business Directory プラグインの forms/search.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-4599 2014-07-7 18:26 2014-04-25 Show GitHub Exploit DB Packet Storm
222055 4.3 警告 swicks - WordPress 用 WooCommerce SagePay Direct Payment Gateway プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-4549 2014-07-7 18:26 2014-04-25 Show GitHub Exploit DB Packet Storm
222056 4.3 警告 Rezgo project - WordPress 用 Rezgo プラグインの book_ajax.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-4546 2014-07-7 18:26 2014-05-28 Show GitHub Exploit DB Packet Storm
222057 4.3 警告 wp-tmkm-amazon project - WordPress 用 wp-tmkm-amazon プラグインの wp-tmkm-amazon-search.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-4598 2014-07-7 18:26 2014-06-12 Show GitHub Exploit DB Packet Storm
222058 4.3 警告 Shaon - WordPress 用 Hot Files: File Sharing and Download Manager プラグインの tpls/editmedia.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-4588 2014-07-7 18:26 2014-04-25 Show GitHub Exploit DB Packet Storm
222059 4.3 警告 SVN Labs Softwares. - WordPress 用 HTML5 Video Player with Playlist プラグインの videoplayer/autoplay.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-4534 2014-07-7 18:26 2014-04-25 Show GitHub Exploit DB Packet Storm
222060 4.3 警告 SnapApp - WordPress 用 SnapApp プラグインの js/button-snapapp.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-4596 2014-07-7 18:26 2014-04-25 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 24, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
268001 8.6 HIGH
Network
ibm websphere_cast_iron_solution IBM WebSphere Cast Iron Solution 7.0.0 and 7.5.0.0 is vulnerable to External Service Interaction attack, caused by improper validation of user-supplied input. A remote attacker could exploit this vul… CWE-20
 Improper Input Validation 
CVE-2016-9692 2024-11-21 12:01 2017-05-6 Show GitHub Exploit DB Packet Storm
268002 8.6 HIGH
Network
ibm websphere_cast_iron_solution IBM WebSphere Cast Iron Solution 7.0.0 and 7.5.0.0 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could explo… CWE-611
XXE
CVE-2016-9691 2024-11-21 12:01 2017-05-6 Show GitHub Exploit DB Packet Storm
268003 8.1 HIGH
Network
ibm rational_rhapsody_design_manager
rational_quality_manager
rational_engineering_lifecycle_manager
rational_software_architect_design_manager
rational_collaborative_lifecycle_management
IBM Jazz Foundation is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose… CWE-611
XXE
CVE-2016-9707 2024-11-21 12:01 2017-04-1 Show GitHub Exploit DB Packet Storm
268004 4.7 MEDIUM
Network
brave browser Brave Browser iOS before 1.2.18 and Brave Browser Android 1.9.56 and earlier suffer from Full Address Bar Spoofing, allowing attackers to trick a victim by displaying a malicious page for legitimate … CWE-79
Cross-site Scripting
CVE-2016-9473 2024-11-21 12:01 2017-03-28 Show GitHub Exploit DB Packet Storm
268005 5.4 MEDIUM
Network
revive-adserver revive_adserver Revive Adserver before 3.2.5 and 4.0.0 suffers from Reflected XSS. The Revive Adserver web installer scripts were vulnerable to a reflected XSS attack via the dbHost, dbUser, and possibly other param… CWE-79
Cross-site Scripting
CVE-2016-9472 2024-11-21 12:01 2017-03-28 Show GitHub Exploit DB Packet Storm
268006 9.0 CRITICAL
Network
revive-adserver revive_adserver Revive Adserver before 3.2.5 and 4.0.0 suffers from Reflected File Download. `www/delivery/asyncspc.php` was vulnerable to the fairly new Reflected File Download (RFD) web attack vector that enables … CWE-254
 7PK - Security Features
CVE-2016-9470 2024-11-21 12:01 2017-03-28 Show GitHub Exploit DB Packet Storm
268007 5.3 MEDIUM
Network
owncloud
nextcloud
owncloud
nextcloud_server
Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the dav app. The exception message displayed on the DAV endpoints contained partiall… CWE-284
Improper Access Control
CVE-2016-9468 2024-11-21 12:01 2017-03-28 Show GitHub Exploit DB Packet Storm
268008 3.1 LOW
Network
revive-adserver revive_adserver Revive Adserver before 3.2.5 and 4.0.0 suffers from Special Element Injection. Usernames weren't properly sanitised when creating users on a Revive Adserver instance. Especially, control characters w… NVD-CWE-Other
CVE-2016-9471 2024-11-21 12:01 2017-03-28 Show GitHub Exploit DB Packet Storm
268009 8.2 HIGH
Network
gitlab gitlab Multiple versions of GitLab expose a dangerous method to any authenticated user that could lead to the deletion of all Issue and MergeRequest objects on a GitLab instance. For GitLab instances with p… CWE-264
Permissions, Privileges, and Access Controls
CVE-2016-9469 2024-11-21 12:01 2017-03-28 Show GitHub Exploit DB Packet Storm
268010 5.3 MEDIUM
Network
owncloud
nextcloud
owncloud
nextcloud_server
Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the files app. The location bar in the files app was not verifying the passed parame… CWE-284
Improper Access Control
CVE-2016-9467 2024-11-21 12:01 2017-03-28 Show GitHub Exploit DB Packet Storm