Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 24, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
224801 4.3 警告 WordPress.org
Fedora Project
Moxiecode Systems
- WordPress などの製品で使用される Moxiecode Plupload におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-0237 2013-07-9 18:48 2013-01-24 Show GitHub Exploit DB Packet Storm
224802 4.3 警告 WordPress.org - WordPress におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-0236 2013-07-9 18:47 2013-01-24 Show GitHub Exploit DB Packet Storm
224803 6.4 警告 WordPress.org - WordPress の XMLRPC API におけるイントラネットサーバへ HTTP リクエストを送信される脆弱性 CWE-Other
その他
CVE-2013-0235 2013-07-9 18:41 2013-01-24 Show GitHub Exploit DB Packet Storm
224804 2.9 注意 シマンテック - Symantec Security Information Manager アプライアンスの管理コンソールにおける重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2013-1615 2013-07-9 15:23 2013-07-1 Show GitHub Exploit DB Packet Storm
224805 4.3 警告 シマンテック - Symantec Security Information Manager アプライアンスの管理コンソールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-1614 2013-07-9 15:23 2013-07-1 Show GitHub Exploit DB Packet Storm
224806 4.7 警告 シマンテック - Symantec Security Information Manager アプライアンスの管理コンソールにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2013-1613 2013-07-9 15:22 2013-07-1 Show GitHub Exploit DB Packet Storm
224807 5.1 警告 フォーティネット - Fortinet FortiGate デバイス上で稼働する FortiOS におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2013-1414 2013-07-9 15:21 2013-07-8 Show GitHub Exploit DB Packet Storm
224808 4.3 警告 リアルネットワークス - RealNetworks RealPlayer におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2013-3299 2013-07-9 15:16 2013-07-6 Show GitHub Exploit DB Packet Storm
224809 7.1 危険 ヒューレット・パッカード - 複数の HP ルータおよびスイッチ製品における任意のコードを実行される脆弱性 CWE-noinfo
情報不足
CVE-2013-2341 2013-07-9 15:15 2013-06-27 Show GitHub Exploit DB Packet Storm
224810 10 危険 ヒューレット・パッカード - 複数の HP ルータおよびスイッチ製品における任意のコードを実行される脆弱性 CWE-noinfo
情報不足
CVE-2013-2340 2013-07-9 15:13 2013-06-27 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 24, 2026, 4:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
277871 - apple iphone_os
mac_os_x
CFURL in Apple iOS before 8.3 and Apple OS X before 10.10.3 does not properly validate URLs, which allows remote attackers to execute arbitrary code via a crafted web site. CWE-20
 Improper Input Validation 
CVE-2015-1088 2024-11-21 11:24 2015-04-10 Show GitHub Exploit DB Packet Storm
277872 - apple iphone_os Directory traversal vulnerability in Backup in Apple iOS before 8.3 allows attackers to read arbitrary files via a crafted relative path. CWE-22
Path Traversal
CVE-2015-1087 2024-11-21 11:24 2015-04-10 Show GitHub Exploit DB Packet Storm
277873 - apple tvos
iphone_os
The Audio Drivers subsystem in Apple iOS before 8.3 and Apple TV before 7.2 does not properly validate IOKit object metadata, which allows attackers to execute arbitrary code in a privileged context … CWE-20
 Improper Input Validation 
CVE-2015-1086 2024-11-21 11:24 2015-04-10 Show GitHub Exploit DB Packet Storm
277874 - apple iphone_os AppleKeyStore in Apple iOS before 8.3 does not properly restrict a certain passcode-confirmation interface, which makes it easier for attackers to verify correct passcode guesses via a crafted app. CWE-264
Permissions, Privileges, and Access Controls
CVE-2015-1085 2024-11-21 11:24 2015-04-10 Show GitHub Exploit DB Packet Storm
277875 - qualiteam x-cart X-Cart before 5.1.11 allows remote authenticated users to read or delete address data of arbitrary accounts via a modified (1) update or (2) remove request. CWE-264
Permissions, Privileges, and Access Controls
CVE-2015-0951 2024-11-21 11:24 2015-04-5 Show GitHub Exploit DB Packet Storm
277876 - qualiteam x-cart Cross-site scripting (XSS) vulnerability in admin.php in X-Cart 5.1.6 through 5.1.10 allows remote attackers to inject arbitrary web script or HTML via the substring parameter. CWE-79
Cross-site Scripting
CVE-2015-0950 2024-11-21 11:24 2015-04-5 Show GitHub Exploit DB Packet Storm
277877 - antlabs inngate_ig_3.10_g
inngate_ig_3.10_e
inngate_ig_3.00_e
inngate_ig_3.01_e
inngate_ig_3100
inngate_ig_3101
inngate_ig_3.02_e
The ANTlabs InnGate firmware on IG 3100, IG 3101, InnGate 3.00 E, InnGate 3.01 E, InnGate 3.02 E, InnGate 3.10 E, InnGate 3.01 G, and InnGate 3.10 G devices does not require authentication for rsync … CWE-264
Permissions, Privileges, and Access Controls
CVE-2015-0932 2024-11-21 11:24 2015-04-5 Show GitHub Exploit DB Packet Storm
277878 - inductiveautomation ignition Inductive Automation Ignition 7.7.2 uses MD5 password hashes, which makes it easier for context-dependent attackers to obtain access via a brute-force attack. CWE-255
Credentials Management
CVE-2015-0995 2024-11-21 11:24 2015-04-3 Show GitHub Exploit DB Packet Storm
277879 - inductiveautomation ignition Inductive Automation Ignition 7.7.2 allows remote authenticated users to bypass a brute-force protection mechanism by using different session ID values in a series of HTTP requests. CWE-254
 7PK - Security Features
CVE-2015-0994 2024-11-21 11:24 2015-04-3 Show GitHub Exploit DB Packet Storm
277880 - inductiveautomation ignition Inductive Automation Ignition 7.7.2 does not terminate a session upon a logout action, which allows remote attackers to bypass intended access restrictions by leveraging an unattended workstation. CWE-254
 7PK - Security Features
CVE-2015-0993 2024-11-21 11:24 2015-04-3 Show GitHub Exploit DB Packet Storm