|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":June 30, 2026, 10 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 224821 | 5 | 警告 | Plone Foundation | - | Plone のオブジェクト管理の実装における重要な情報を取得される脆弱性 |
CWE-264
認可・権限・アクセス制御 |
CVE-2013-4196 | 2014-03-13 14:44 | 2013-06-18 | Show | GitHub Exploit DB Packet Storm |
| 224822 | 5.8 | 警告 | Plone Foundation | - | Plone の複数の PY ファイルにおけるオープンリダイレクトの脆弱性 |
CWE-20
不適切な入力確認 |
CVE-2013-4195 | 2014-03-13 14:44 | 2013-06-18 | Show | GitHub Exploit DB Packet Storm |
| 224823 | 4.3 | 警告 | Plone Foundation | - | Plone の WYSIWYG コンポーネントにおける重要な情報を取得される脆弱性 |
CWE-200
情報漏えい |
CVE-2013-4194 | 2014-03-13 14:43 | 2013-06-18 | Show | GitHub Exploit DB Packet Storm |
| 224824 | 4.3 | 警告 | Plone Foundation | - | Plone の typeswidget.py におけるフォーム上のフィールドを非表示にされる脆弱性 |
CWE-264
認可・権限・アクセス制御 |
CVE-2013-4193 | 2014-03-13 14:43 | 2013-06-18 | Show | GitHub Exploit DB Packet Storm |
| 224825 | 4 | 警告 | Plone Foundation | - | Plone の sendto.py における電子メールを偽装される脆弱性 |
CWE-20
不適切な入力確認 |
CVE-2013-4192 | 2014-03-13 14:43 | 2013-06-18 | Show | GitHub Exploit DB Packet Storm |
| 224826 | 5.8 | 警告 | Plone Foundation | - | Plone の zip.py における重要な情報を取得される脆弱性 |
CWE-264
認可・権限・アクセス制御 |
CVE-2013-4191 | 2014-03-13 14:42 | 2013-06-18 | Show | GitHub Exploit DB Packet Storm |
| 224827 | 4.3 | 警告 | Plone Foundation | - | Plone の複数の PY ファイルにおけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2013-4190 | 2014-03-13 14:42 | 2013-06-18 | Show | GitHub Exploit DB Packet Storm |
| 224828 | 6.5 | 警告 | Plone Foundation | - | Plone の複数の PY ファイルにおけるサブツリー上のノードにアクセスされる脆弱性 |
CWE-noinfo
情報不足 |
CVE-2013-4189 | 2014-03-13 14:42 | 2013-06-18 | Show | GitHub Exploit DB Packet Storm |
| 224829 | 4.3 | 警告 | Plone Foundation | - | Plone の traverser.py におけるサービス運用妨害 (DoS) の脆弱性 |
CWE-399
リソース管理の問題 |
CVE-2013-4188 | 2014-03-13 14:41 | 2013-06-18 | Show | GitHub Exploit DB Packet Storm |
| 224830 | 5.4 | 警告 | マイクロソフト | - | 複数の Microsoft Windows 製品の Security Account Manager Remote プロトコルの実装におけるアカウントロックアウトポリシーを回避される脆弱性 |
CWE-20 CWE-264 |
CVE-2014-0317 | 2014-03-13 14:40 | 2014-03-11 | Show | GitHub Exploit DB Packet Storm |
Update Date:June 30, 2026, 4:22 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 1001 | 4.3 |
MEDIUM
Network |
- | - | Subscriber Broken Access Control in MasterStudy LMS <= 3.7.30 versions. |
CWE-862
Missing Authorization |
CVE-2026-57640 | 2026-06-27 01:16 | 2026-06-27 | Show | GitHub Exploit DB Packet Storm |
| 1002 | 4.3 |
MEDIUM
Network |
- | - | Contributor Insecure Direct Object References (IDOR) in PPWP <= 1.9.19 versions. |
CWE-639
Authorization Bypass Through User-Controlled Key |
CVE-2026-57634 | 2026-06-27 01:16 | 2026-06-27 | Show | GitHub Exploit DB Packet Storm |
| 1003 | 5.3 |
MEDIUM
Network |
- | - | Unauthenticated Sensitive Data Exposure in WCBoost – Products Compare <= 1.1.0 versions. |
CWE-497
Exposure of Sensitive System Information to an Unauthorized Control Sphere |
CVE-2026-57633 | 2026-06-27 01:16 | 2026-06-27 | Show | GitHub Exploit DB Packet Storm |
| 1004 | 7.6 |
HIGH
Network |
- | - | Administrator SQL Injection in WP All Import <= 4.0.1 versions. |
CWE-89
SQL Injection |
CVE-2026-57628 | 2026-06-27 01:16 | 2026-06-27 | Show | GitHub Exploit DB Packet Storm |
| 1005 | 4.9 |
MEDIUM
Network |
- | - | Subscriber Server Side Request Forgery (SSRF) in Kirki <= 6.0.11 versions. |
CWE-918
Server-Side Request Forgery (SSRF) |
CVE-2026-57627 | 2026-06-27 01:16 | 2026-06-27 | Show | GitHub Exploit DB Packet Storm |
| 1006 | 4.3 |
MEDIUM
Network |
- | - | Contributor Broken Access Control in SEOPress PRO <= 9.1.1 versions. |
CWE-862
Missing Authorization |
CVE-2026-57430 | 2026-06-27 01:16 | 2026-06-27 | Show | GitHub Exploit DB Packet Storm |
| 1007 | 7.1 |
HIGH
Network |
- | - | Unauthenticated Cross Site Scripting (XSS) in NanoMag <= 1.8 versions. |
CWE-79
Cross-site Scripting |
CVE-2026-57325 | 2026-06-27 01:16 | 2026-06-27 | Show | GitHub Exploit DB Packet Storm |
| 1008 | 7.1 |
HIGH
Network |
- | - | Unauthenticated Cross Site Scripting (XSS) in FOX <= 1.4.8 versions. |
CWE-79
Cross-site Scripting |
CVE-2026-57319 | 2026-06-27 01:16 | 2026-06-27 | Show | GitHub Exploit DB Packet Storm |
| 1009 | 6.5 |
MEDIUM
Network |
- | - | Subscriber Sensitive Data Exposure in Site Reviews <= 8.0.11 versions. |
CWE-201
Insertion of Sensitive Information Into Sent Data |
CVE-2026-57318 | 2026-06-27 01:16 | 2026-06-27 | Show | GitHub Exploit DB Packet Storm |
| 1010 | 6.5 |
MEDIUM
Network |
- | - | Subscriber Cross Site Scripting (XSS) in SureCart <= 4.2.2 versions. |
CWE-79
Cross-site Scripting |
CVE-2026-57313 | 2026-06-27 01:16 | 2026-06-27 | Show | GitHub Exploit DB Packet Storm |