Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 22, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
241341 4 警告 マカフィー - McAfee Email and Web Security および McAfee Email Gateway における任意のファイルを読まれる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-4585 2012-08-24 11:35 2012-03-13 Show GitHub Exploit DB Packet Storm
241342 3.5 注意 マカフィー - McAfee Email and Web Security および McAfee Email Gateway における重要な情報を取得される脆弱性 CWE-310
暗号の問題
CVE-2012-4584 2012-08-24 11:35 2012-03-13 Show GitHub Exploit DB Packet Storm
241343 4 警告 マカフィー - McAfee Email and Web Security および McAfee Email Gateway におけるセッショントークンを取得される脆弱性 CWE-200
情報漏えい
CVE-2012-4583 2012-08-24 11:34 2012-03-13 Show GitHub Exploit DB Packet Storm
241344 4.9 警告 マカフィー - McAfee Email and Web Security および McAfee Email Gateway における任意の管理者アカウントのパスワードをリセットされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-4582 2012-08-24 11:32 2012-03-13 Show GitHub Exploit DB Packet Storm
241345 6.8 警告 マカフィー - McAfee Email and Web Security および McAfee Email Gateway におけるセッションをハイジャックされる脆弱性 CWE-287
不適切な認証
CVE-2012-4581 2012-08-24 11:24 2012-03-13 Show GitHub Exploit DB Packet Storm
241346 4.3 警告 マカフィー - McAfee Email and Web Security および McAfee Email Gateway におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-4580 2012-08-24 11:21 2012-03-13 Show GitHub Exploit DB Packet Storm
241347 3.5 注意 CuteSoft Components - Cute Editor にクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-2985 2012-08-24 09:55 2012-08-17 Show GitHub Exploit DB Packet Storm
241348 7.1 危険 T-Mobile
AT&T
サムスン
Sprint
HTC Corporation
- Samsung および HTC 製 Android 端末に情報漏えいの脆弱性 CWE-255
証明書・パスワード管理
CVE-2012-2980 2012-08-24 09:54 2012-08-17 Show GitHub Exploit DB Packet Storm
241349 5 警告 マカフィー - McAfee SaaS Endpoint Protection における電子メールメッセージを中継される脆弱性 CWE-Other
その他
CVE-2011-5101 2012-08-23 16:46 2012-01-17 Show GitHub Exploit DB Packet Storm
241350 7.5 危険 マカフィー - McAfee Firewall Reporter の Web インターフェイスにおけるアクセス権を取得される脆弱性 CWE-287
不適切な認証
CVE-2011-5100 2012-08-23 16:42 2012-08-22 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 22, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
286021 6.1 MEDIUM
Network
keplerproject cgilua The session.lua library in CGILua 5.1.x uses the same ID for each session, which allows remote attackers to hijack arbitrary sessions. NOTE: this vulnerability was SPLIT from CVE-2014-2875. CWE-384
 Session Fixation
CVE-2014-10399 2024-11-21 11:03 2020-02-7 Show GitHub Exploit DB Packet Storm
286022 6.1 MEDIUM
Network
bssys rbs_bs-client._retail_client Multiple cross-site scripting (XSS) vulnerabilities in bsi.dll in Bank Soft Systems (BSS) RBS BS-Client. Private Client (aka RBS BS-Client. Retail Client) 2.5, 2.4, and earlier allow remote attackers… CWE-79
Cross-site Scripting
CVE-2014-10398 2024-11-21 11:03 2020-01-4 Show GitHub Exploit DB Packet Storm
286023 6.1 MEDIUM
Network
ideagen q-pulse Cross-site scripting (XSS) vulnerability in ui/common/managedlistdialog.aspx in Gael Q-Pulse 0.6 and earlier. CWE-79
Cross-site Scripting
CVE-2014-1238 2024-11-21 11:03 2019-11-23 Show GitHub Exploit DB Packet Storm
286024 8.8 HIGH
Network
projoom smart_flash_header views/upload.php in the ProJoom Smart Flash Header (NovaSFH) component 3.0.2 and earlier for Joomla! allows remote attackers to upload and execute arbitrary files via a crafted (1) dest parameter and… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2014-1214 2024-11-21 11:03 2019-11-14 Show GitHub Exploit DB Packet Storm
286025 7.5 HIGH
Network
para antioch The Antioch theme through 2014-09-07 for WordPress allows arbitrary file downloads via the file parameter to lib/scripts/download.php. CWE-22
Path Traversal
CVE-2014-10397 2024-11-21 11:03 2019-09-21 Show GitHub Exploit DB Packet Storm
286026 7.5 HIGH
Network
organizedthemes epic The epic theme through 2014-09-07 for WordPress allows arbitrary file downloads via the file parameter to includes/download.php. CWE-22
Path Traversal
CVE-2014-10396 2024-11-21 11:03 2019-09-21 Show GitHub Exploit DB Packet Storm
286027 6.1 MEDIUM
Network
codepeople polls_cp The cp-polls plugin before 1.0.1 for WordPress has XSS in the votes list. CWE-79
Cross-site Scripting
CVE-2014-10395 2024-11-21 11:03 2019-08-27 Show GitHub Exploit DB Packet Storm
286028 6.1 MEDIUM
Network
cformsii_project cformsii The cforms2 plugin before 10.5 for WordPress has XSS. CWE-79
Cross-site Scripting
CVE-2014-10393 2024-11-21 11:03 2019-08-23 Show GitHub Exploit DB Packet Storm
286029 6.1 MEDIUM
Network
3cx live_chat The wp-live-chat-support plugin before 4.1.0 for WordPress has JavaScript injections. CWE-74
Injection
CVE-2014-10386 2024-11-21 11:03 2019-08-23 Show GitHub Exploit DB Packet Storm
286030 4.3 MEDIUM
Network
pippinsplugins featured_comments The feature-comments plugin before 1.2.5 for WordPress has CSRF for featuring or burying a comment. CWE-352
 Origin Validation Error
CVE-2014-10382 2024-11-21 11:03 2019-08-23 Show GitHub Exploit DB Packet Storm