Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 13, 2026, 12:06 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
240861 6.8 警告 Joomla!
emultisoft
- Joomla! 用 Online News Paper Manager コンポーネントにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-1950 2012-06-26 16:19 2010-05-19 Show GitHub Exploit DB Packet Storm
240862 7.5 危険 Joomla!
emultisoft
- Joomla! 用 Online News Paper Manager コンポーネントにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-1949 2012-06-26 16:19 2010-05-19 Show GitHub Exploit DB Packet Storm
240863 4.3 警告 アップル
マイクロソフト
- Apple Safari における重要な情報を取得され脆弱性 CWE-255
証明書・パスワード管理
CVE-2010-1940 2012-06-26 16:19 2010-05-14 Show GitHub Exploit DB Packet Storm
240864 7.5 危険 CubeCart Limited - CubeCart PHP Shopping cart の includes/content/cart.inc.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-1931 2012-06-26 16:19 2010-06-9 Show GitHub Exploit DB Packet Storm
240865 7.5 危険 29o3 cms - 29o3 CMS における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2010-1922 2012-06-26 16:19 2010-05-12 Show GitHub Exploit DB Packet Storm
240866 7.1 危険 DELL EMC (旧 EMC Corporation) - EMC Avamar におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2010-1919 2012-06-26 16:19 2010-05-28 Show GitHub Exploit DB Packet Storm
240867 7.5 危険 eFront Learning - eFront の ask_chat.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-1918 2012-06-26 16:19 2010-05-12 Show GitHub Exploit DB Packet Storm
240868 9.3 危険 コンソナ - Consona Live Assistance の SdcWebSecureBase インターフェースの pluginlicense.ini のデフォルト設定における ActiveX 実行に対する制限を回避される脆弱性 CWE-16
環境設定
CVE-2010-1913 2012-06-26 16:19 2010-05-12 Show GitHub Exploit DB Packet Storm
240869 9.3 危険 コンソナ - Consona Live Assistance の SdcWebSecureBase インターフェースにおける ActiveX 実行上で制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2010-1912 2012-06-26 16:19 2010-05-12 Show GitHub Exploit DB Packet Storm
240870 9.3 危険 コンソナ - Consona Live Assistance の SdcWebSecureBase インターフェースの site-locking 実装における任意のコードを実行される脆弱性 CWE-310
暗号の問題
CVE-2010-1911 2012-06-26 16:19 2010-04-16 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 13, 2026, 5:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
286061 - rubyonrails ruby_on_rails
rails
actionpack/lib/action_dispatch/http/request.rb in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 does not properly consider differences in parameter handling between the Active Record component and… CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-6417 2024-11-21 10:59 2013-12-7 Show GitHub Exploit DB Packet Storm
286062 - rubyonrails rails Cross-site scripting (XSS) vulnerability in the simple_format helper in actionpack/lib/action_view/helpers/text_helper.rb in Ruby on Rails 4.x before 4.0.2 allows remote attackers to inject arbitrary… CWE-79
Cross-site Scripting
CVE-2013-6416 2024-11-21 10:59 2013-12-7 Show GitHub Exploit DB Packet Storm
286063 - rubyonrails ruby_on_rails
rails
Cross-site scripting (XSS) vulnerability in the number_to_currency helper in actionpack/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 allows remote atta… CWE-79
Cross-site Scripting
CVE-2013-6415 2024-11-21 10:59 2013-12-7 Show GitHub Exploit DB Packet Storm
286064 - rubyonrails rails
ruby_on_rails
actionpack/lib/action_view/lookup_context.rb in Action View in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to cause a denial of service (memory consumption) via a hea… CWE-20
 Improper Input Validation 
CVE-2013-6414 2024-11-21 10:59 2013-12-7 Show GitHub Exploit DB Packet Storm
286065 - jamroom search_module Cross-site scripting (XSS) vulnerability in the Search module before 1.1.1 for Jamroom allows remote attackers to inject arbitrary web script or HTML via the search_string parameter to search/results… CWE-79
Cross-site Scripting
CVE-2013-6804 2024-11-21 10:59 2013-12-6 Show GitHub Exploit DB Packet Storm
286066 - chamilo chamilo_lms SQL injection vulnerability in the check_user_password function in main/auth/profile.php in Chamilo LMS 1.9.6 and earlier, when using the non-encrypted passwords mode set at installation, allows remo… CWE-89
SQL Injection
CVE-2013-6787 2024-11-21 10:59 2013-12-6 Show GitHub Exploit DB Packet Storm
286067 - ganglia ganglia-web Cross-site scripting (XSS) vulnerability in header.php in Ganglia Web 3.5.8 and 3.5.10 allows remote attackers to inject arbitrary web script or HTML via the host_regex parameter to the default URI, … CWE-79
Cross-site Scripting
CVE-2013-6395 2024-11-21 10:59 2013-12-6 Show GitHub Exploit DB Packet Storm
286068 - dokeos dokeos SQL injection vulnerability in Dokeos 2.2 RC2 and earlier allows remote attackers to execute arbitrary SQL commands via the language parameter to index.php. CWE-89
SQL Injection
CVE-2013-6341 2024-11-21 10:59 2013-12-6 Show GitHub Exploit DB Packet Storm
286069 - cybozu garoon Cross-site scripting (XSS) vulnerability in the Yahoo! User Interface Library in Cybozu Garoon before 3.7.2, when Internet Explorer 9 or 10 or Chrome is used, allows remote attackers to inject arbitr… CWE-79
Cross-site Scripting
CVE-2013-6916 2024-11-21 10:59 2013-12-5 Show GitHub Exploit DB Packet Storm
286070 - cybozu garoon Cross-site scripting (XSS) vulnerability in the system-administration component in Cybozu Garoon before 3.7.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified … CWE-79
Cross-site Scripting
CVE-2013-6915 2024-11-21 10:59 2013-12-5 Show GitHub Exploit DB Packet Storm