Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 12, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
240831 6.8 警告 xt:Commerce
bluegate
- xt:Commerce 用の Direct URL モジュールの bluegate_seo.inc.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-1359 2012-06-26 16:19 2010-04-13 Show GitHub Exploit DB Packet Storm
240832 5 警告 cookex
Joomla!
- Joomla! の Cookex Agency ckforms コンポーネントにおけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2010-1345 2012-06-26 16:19 2010-04-9 Show GitHub Exploit DB Packet Storm
240833 7.5 危険 cookex
Joomla!
- Joomla! の Cookex Agency ckforms コンポーネントにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-1344 2012-06-26 16:19 2010-04-9 Show GitHub Exploit DB Packet Storm
240834 7.5 危険 bjsintay - SiteX における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-1343 2012-06-26 16:19 2010-04-9 Show GitHub Exploit DB Packet Storm
240835 6.8 警告 directnews - Direct News における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2010-1342 2012-06-26 16:19 2010-04-9 Show GitHub Exploit DB Packet Storm
240836 5 警告 ermenegildo fiorito - Irmin CMS におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2010-1309 2012-06-26 16:19 2010-04-8 Show GitHub Exploit DB Packet Storm
240837 5 警告 decryptweb
Joomla!
- Joomla! の dwgraphs コンポーネントの dwgraphs.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2010-1302 2012-06-26 16:19 2010-04-7 Show GitHub Exploit DB Packet Storm
240838 7.5 危険 The Cacti Group - Cacti の templates_export.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-1431 2012-06-26 16:19 2009-06-28 Show GitHub Exploit DB Packet Storm
240839 5.1 警告 dynpg - DynPG CMS における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2010-1299 2012-06-26 16:19 2010-04-7 Show GitHub Exploit DB Packet Storm
240840 4.3 警告 bbsxp - BBSXP 2008 SP2 におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-1276 2012-06-26 16:19 2010-04-6 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 13, 2026, 5:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
286221 - codeaurora android-msm The Qualcomm Innovation Center (QuIC) init scripts in Code Aurora Forum (CAF) releases of Android 4.1.x through 4.4.x allow local users to modify file metadata via a symlink attack on a file accessed… CWE-59
Link Following
CVE-2013-6124 2024-11-21 10:58 2014-08-31 Show GitHub Exploit DB Packet Storm
286222 - hp service_manager Cross-site scripting (XSS) vulnerability in the Mobility Web Client and Service Request Catalog (SRC) components in HP Service Manager (SM) 7.21 and 9.x before 9.34 allows remote attackers to inject … CWE-79
Cross-site Scripting
CVE-2013-6222 2024-11-21 10:58 2014-08-24 Show GitHub Exploit DB Packet Storm
286223 - ibm power_760_firmware
power_770
power_780
power_795
power_ese
power_740_firmware
power_710
power_720
power_730
power_740
power_770_firmware
power_750
power_760
pow…
Unspecified vulnerability on IBM Power 7 Systems 740 before 740.70 01Ax740_121, 760 before 760.40 Ax760_078, and 770 before 770.30 01Ax770_062 allows local users to gain Service Processor privileges … NVD-CWE-noinfo
CVE-2013-6306 2024-11-21 10:58 2014-08-23 Show GitHub Exploit DB Packet Storm
286224 - yealink sip-t38g cgi-bin/cgiServer.exx in Yealink VoIP Phone SIP-T38G allows remote authenticated users to execute arbitrary commands by calling the system method in the body of a request, as demonstrated by running … CWE-78
OS Command 
CVE-2013-5758 2024-11-21 10:58 2014-08-4 Show GitHub Exploit DB Packet Storm
286225 - yealink sip-t38g Absolute path traversal vulnerability in Yealink VoIP Phone SIP-T38G allows remote authenticated users to read arbitrary files via a full pathname in the dumpConfigFile function in the command parame… CWE-22
Path Traversal
CVE-2013-5757 2024-11-21 10:58 2014-08-4 Show GitHub Exploit DB Packet Storm
286226 - yealink sip-t38g Directory traversal vulnerability in Yealink VoIP Phone SIP-T38G allows remote authenticated users to read arbitrary files via a .. (dot dot) in the page parameter to cgi-bin/cgiServer.exx. CWE-22
Path Traversal
CVE-2013-5756 2024-11-21 10:58 2014-08-4 Show GitHub Exploit DB Packet Storm
286227 - oracle mojarra Oracle Mojarra 2.2.x before 2.2.6 and 2.1.x before 2.1.28 does not perform appropriate encoding when a (1) <h:outputText> tag or (2) EL expression is used after a scriptor style block, which allows r… CWE-79
Cross-site Scripting
CVE-2013-5855 2024-11-21 10:58 2014-07-17 Show GitHub Exploit DB Packet Storm
286228 - yealink sip-t38g config/.htpasswd in Yealink IP Phone SIP-T38G has a hardcoded password of (1) user (s7C9Cx.rLsWFA) for the user account, (2) admin (uoCbM.VEiKQto) for the admin account, and (3) var (jhl3iZAe./qXM) f… CWE-255
Credentials Management
CVE-2013-5755 2024-11-21 10:58 2014-07-16 Show GitHub Exploit DB Packet Storm
286229 - dahuasecurity dvr_firmware Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive information including user credentials, change user passwords, clear log files, and perfo… CWE-287
Improper Authentication
CVE-2013-6117 2024-11-21 10:58 2014-07-12 Show GitHub Exploit DB Packet Storm
286230 - ibm marketing_platform SQL injection vulnerability in IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. CWE-89
SQL Injection
CVE-2013-6311 2024-11-21 10:58 2014-06-28 Show GitHub Exploit DB Packet Storm