Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 17, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228651 4.3 警告 Splunk - Splunk Web におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-2766 2013-04-12 11:04 2013-03-25 Show GitHub Exploit DB Packet Storm
228652 5 警告 Puppet - Puppet Labs の Puppet Enterprise におけるコンソールアクセスを取得される脆弱性 CWE-310
暗号の問題
CVE-2013-2716 2013-04-12 11:03 2013-03-28 Show GitHub Exploit DB Packet Storm
228653 7.5 危険 Digineo - Ruby 用 Thumbshooter gem の lib/thumbshooter.rb における任意のコマンドを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2013-1898 2013-04-11 19:42 2013-03-25 Show GitHub Exploit DB Packet Storm
228654 7.5 危険 Dan Kubb - Ruby 用 extlib gem におけるオブジェクトインジェクション攻撃を実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-1802 2013-04-11 19:41 2013-01-14 Show GitHub Exploit DB Packet Storm
228655 7.5 危険 John Nunemaker - Ruby 用 httparty gem におけるオブジェクトインジェクション攻撃を実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-1801 2013-04-11 19:41 2013-01-14 Show GitHub Exploit DB Packet Storm
228656 7.5 危険 John Nunemaker - Ruby 用 crack gem におけるオブジェクトインジェクション攻撃を実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-1800 2013-04-11 19:40 2013-01-14 Show GitHub Exploit DB Packet Storm
228657 7.5 危険 Daniel Harrington - Ruby 用 nori gem におけるオブジェクトインジェクション攻撃を実行される脆弱性 CWE-20
不適切な入力確認
CVE-2013-0285 2013-04-11 19:39 2013-01-14 Show GitHub Exploit DB Packet Storm
228658 5 警告 New Relic - Ruby Agent における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2013-0284 2013-04-11 19:38 2013-02-13 Show GitHub Exploit DB Packet Storm
228659 6.8 警告 Michael Bleigh and Intridea, Inc. - Ruby 用 omniauth-oauth2 gem におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2012-6134 2013-04-11 19:37 2013-02-25 Show GitHub Exploit DB Packet Storm
228660 5.8 警告 Apache Software Foundation - Apache Maven のデフォルト設定におけるサーバになりすまされる脆弱性 CWE-16
環境設定
CVE-2013-0253 2013-04-11 17:36 2013-04-2 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 17, 2026, 4:19 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
275251 6.1 MEDIUM
Network
flippercode wp_google_map The wp-google-map-plugin plugin before 3.1.2 for WordPress has XSS. CWE-79
Cross-site Scripting
CVE-2016-10878 2024-11-21 11:44 2019-08-13 Show GitHub Exploit DB Packet Storm
275252 6.1 MEDIUM
Network
wp_editor_project wp_editor The wp-editor plugin before 1.2.6.3 for WordPress has multiple XSS issues. CWE-79
Cross-site Scripting
CVE-2016-10877 2024-11-21 11:44 2019-08-13 Show GitHub Exploit DB Packet Storm
275253 8.8 HIGH
Network
wpseeds wp_database_backup The wp-database-backup plugin before 4.3.1 for WordPress has CSRF. CWE-352
 Origin Validation Error
CVE-2016-10876 2024-11-21 11:44 2019-08-13 Show GitHub Exploit DB Packet Storm
275254 6.1 MEDIUM
Network
wpseeds wp_database_backup The wp-database-backup plugin before 4.3.1 for WordPress has XSS. CWE-79
Cross-site Scripting
CVE-2016-10875 2024-11-21 11:44 2019-08-13 Show GitHub Exploit DB Packet Storm
275255 8.8 HIGH
Network
wpseeds wp_database_backup The wp-database-backup plugin before 4.3.3 for WordPress has CSRF. CWE-352
 Origin Validation Error
CVE-2016-10874 2024-11-21 11:44 2019-08-13 Show GitHub Exploit DB Packet Storm
275256 6.1 MEDIUM
Network
wpseeds wp_database_backup The wp-database-backup plugin before 4.3.3 for WordPress has XSS. CWE-79
Cross-site Scripting
CVE-2016-10873 2024-11-21 11:44 2019-08-13 Show GitHub Exploit DB Packet Storm
275257 6.1 MEDIUM
Network
23systems lightbox_plus_colorbox The Lightbox Plus Colorbox plugin through 2.7.2 for WordPress has cross-site request forgery (CSRF) via wp-admin/admin.php?page=lightboxplus, as demonstrated by resultant width XSS. CWE-352
 Origin Validation Error
CVE-2016-10865 2024-11-21 11:44 2019-08-9 Show GitHub Exploit DB Packet Storm
275258 8.8 HIGH
Network
edimax ew-7438rpn_mini_firmware
7237rpd_firmware
Edimax Wi-Fi Extender devices allow goform/formwlencryptvxd CSRF with resultant PSK key disclosure. CWE-352
 Origin Validation Error
CVE-2016-10863 2024-11-21 11:44 2019-08-9 Show GitHub Exploit DB Packet Storm
275259 8.8 HIGH
Network
neetcables airstream_nas_firmware Neet AirStream NAS1.1 devices have a password of ifconfig for the root account. This cannot be changed via the configuration page. CWE-352
 Origin Validation Error
CVE-2016-10862 2024-11-21 11:44 2019-08-9 Show GitHub Exploit DB Packet Storm
275260 5.2 MEDIUM
Adjacent
netgear ex7000_firmware NETGEAR EX7000 V1.0.0.42_1.0.94 devices allow XSS via the SSID. CWE-79
Cross-site Scripting
CVE-2016-10864 2024-11-21 11:44 2019-08-8 Show GitHub Exploit DB Packet Storm