Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 17, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
224511 6.8 警告 Crunchify - WordPress 用 FourSquare Checkins プラグインにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2013-2709 2013-04-30 17:54 2013-04-22 Show GitHub Exploit DB Packet Storm
224512 6.8 警告 Crunchify - WordPress 用 All in One Webmaster プラグインにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2013-2696 2013-04-30 17:52 2013-04-22 Show GitHub Exploit DB Packet Storm
224513 5 警告 Blink Web Effects - WordPress 用 Social Media Widget プラグインにおける任意のファイルのアップロードを強制される脆弱性 CWE-noinfo
情報不足
CVE-2013-1949 2013-04-30 17:51 2013-04-9 Show GitHub Exploit DB Packet Storm
224514 10 危険 Rob Westgeest - Ruby 用 md2pdf gem の converter.rb における任意のコマンドを実行される脆弱性 CWE-noinfo
情報不足
CVE-2013-1948 2013-04-30 17:51 2013-04-10 Show GitHub Exploit DB Packet Storm
224515 9.3 危険 Kelly D. Redding - Ruby 用 kelredd-pruview gem における任意のコマンドを実行される脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2013-1947 2013-04-30 17:50 2013-04-4 Show GitHub Exploit DB Packet Storm
224516 9.3 危険 karteek-docsplit - Ruby 用 Karteek Docsplit gem における任意のコマンドを実行される脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2013-1933 2013-04-30 17:49 2013-04-1 Show GitHub Exploit DB Packet Storm
224517 6.8 警告 Novell
plataformatec
- Ruby 用 Devise gem における不正な結果が返される脆弱性 CWE-399
リソース管理の問題
CVE-2013-0233 2013-04-30 17:48 2013-01-28 Show GitHub Exploit DB Packet Storm
224518 7.5 危険 Grape
Erik Michaels-Ober
- Grape などの製品で使用される Ruby 用 multi_xml gem におけるオブジェクトインジェクション攻撃を誘発される脆弱性 CWE-20
不適切な入力確認
CVE-2013-0175 2013-04-30 17:43 2013-01-10 Show GitHub Exploit DB Packet Storm
224519 5 警告 Ruby-lang.org - Ruby における safe-level の制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-4466 2013-04-30 17:29 2012-10-3 Show GitHub Exploit DB Packet Storm
224520 5 警告 Ruby-lang.org - Ruby における safe-level の制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-4464 2013-04-30 17:25 2012-10-3 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 18, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
277871 - moodle moodle calendar/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote authenticated users to obtain sensitive calendar-event information via a… CWE-200
Information Exposure
CVE-2015-0215 2024-11-21 11:22 2015-06-2 Show GitHub Exploit DB Packet Storm
277872 - moodle moodle message/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote authenticated users to bypass a messaging-disabled setting via a web-serv… CWE-264
Permissions, Privileges, and Access Controls
CVE-2015-0214 2024-11-21 11:22 2015-06-2 Show GitHub Exploit DB Packet Storm
277873 - moodle moodle Multiple cross-site request forgery (CSRF) vulnerabilities in (1) editcategories.html and (2) editcategories.php in the Glossary module in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4… CWE-352
 Origin Validation Error
CVE-2015-0213 2024-11-21 11:22 2015-06-2 Show GitHub Exploit DB Packet Storm
277874 - moodle moodle Cross-site scripting (XSS) vulnerability in course/pending.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote authenticated users to inject arbi… CWE-79
Cross-site Scripting
CVE-2015-0212 2024-11-21 11:22 2015-06-2 Show GitHub Exploit DB Packet Storm
277875 - moodle moodle mod/lti/ajax.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 does not consider the moodle/course:manageactivities and mod/lti:addinstance capabilities befo… CWE-200
Information Exposure
CVE-2015-0211 2024-11-21 11:22 2015-06-2 Show GitHub Exploit DB Packet Storm
277876 - ibm business_process_manager
websphere
Cross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, and 8.5.x through 8.5.5.0 and WebSphere Lombardi Edition (WLE) 7.2.x throu… CWE-79
Cross-site Scripting
CVE-2015-0193 2024-11-21 11:22 2015-05-31 Show GitHub Exploit DB Packet Storm
277877 - ibm rational_requirements_composer
rational_doors_next_generation
IBM Rational Requirements Composer 3.0 through 3.0.1.6 and 4.0 through 4.0.7 and Rational DOORS Next Generation (RDNG) 4.0 through 4.0.7 and 5.0 through 5.0.2, when LTPA single sign on is used with W… NVD-CWE-Other
CVE-2015-0121 2024-11-21 11:22 2015-05-31 Show GitHub Exploit DB Packet Storm
277878 - ibm websphere_commerce IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x before 7.0.0.8 IF2 allows local users to obtain sensitive database information via unspecified vectors. CWE-200
Information Exposure
CVE-2015-0200 2024-11-21 11:22 2015-05-30 Show GitHub Exploit DB Packet Storm
277879 - ibm infosphere_information_server The Connector Migration Tool in IBM InfoSphere Information Server 8.1 through 11.3 allows remote authenticated users to bypass intended restrictions on job creation and modification via unspecified v… CWE-284
Improper Access Control
CVE-2015-0180 2024-11-21 11:22 2015-05-25 Show GitHub Exploit DB Packet Storm
277880 - ibm security_siteprotector_system Directory traversal vulnerability in IBM Security SiteProtector System 3.0 before 3.0.0.7, 3.1 before 3.1.0.4, and 3.1.1 before 3.1.1.2 allows remote authenticated users to write to arbitrary files v… CWE-22
Path Traversal
CVE-2015-0171 2024-11-21 11:22 2015-05-25 Show GitHub Exploit DB Packet Storm