Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 1, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
243091 4.3 警告 2bits
Drupal
- Drupal の Currency Exchange モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-1074 2012-06-26 16:19 2009-01-6 Show GitHub Exploit DB Packet Storm
243092 4.3 警告 chris wederka
TYPO3 Association
- TYPO3 の tgm_newsletter 拡張におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-1025 2012-06-26 16:19 2010-03-19 Show GitHub Exploit DB Packet Storm
243093 7.5 危険 chris wederka
TYPO3 Association
- TYPO3 の tgm_newsletter 拡張における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-1024 2012-06-26 16:19 2010-03-19 Show GitHub Exploit DB Packet Storm
243094 4.3 警告 georg ringer, patrick gaumond
TYPO3 Association
- TYPO3 の taskcenter_recent 拡張 におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-1023 2012-06-26 16:19 2010-03-19 Show GitHub Exploit DB Packet Storm
243095 4.3 警告 christian hennecke
TYPO3 Association
- TYPO3 の chsellector 拡張におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-1008 2012-06-26 16:19 2010-03-19 Show GitHub Exploit DB Packet Storm
243096 5 警告 TYPO3 Association
chi hoang
- TYPO3 の Power Extension Manager 拡張における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2010-1007 2012-06-26 16:19 2010-03-19 Show GitHub Exploit DB Packet Storm
243097 6.8 警告 eFront Learning - eFront の www/editor/tiny_mce/langs/language.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2010-1003 2012-06-26 16:19 2010-03-19 Show GitHub Exploit DB Packet Storm
243098 7.1 危険 Free Download Manager.ORG - FDM におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2010-0999 2012-06-26 16:19 2010-05-17 Show GitHub Exploit DB Packet Storm
243099 10 危険 Free Download Manager.ORG - FDM におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2010-0998 2012-06-26 16:19 2010-05-17 Show GitHub Exploit DB Packet Storm
243100 3.5 注意 e107.org - e107 の 107_plugins/content/content_manager.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-0997 2012-06-26 16:19 2010-04-20 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 1, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
268221 9.8 CRITICAL
Network
ktools photostore SQL injection vulnerability in the mgr.login.php file in Ktools.net Photostore before 4.7.5 allows remote attackers to execute arbitrary SQL commands via the email parameter in a recover_login action. CWE-89
SQL Injection
CVE-2016-4337 2024-11-21 11:51 2017-04-13 Show GitHub Exploit DB Packet Storm
268222 6.1 MEDIUM
Network
jivesoftware jive Jive before 2016.3.1 has an open redirect from the external-link.jspa page. CWE-601
Open Redirect
CVE-2016-4334 2024-11-21 11:51 2017-04-10 Show GitHub Exploit DB Packet Storm
268223 4.3 MEDIUM
Network
atlassian bitbucket Atlassian Bitbucket Server before 4.7.1 allows remote attackers to read the first line of an arbitrary file via a directory traversal attack on the pull requests resource. CWE-22
Path Traversal
CVE-2016-4320 2024-11-21 11:51 2017-04-10 Show GitHub Exploit DB Packet Storm
268224 8.8 HIGH
Network
atlassian jira Atlassian JIRA Server before 7.1.9 has CSRF in auditing/settings. CWE-352
 Origin Validation Error
CVE-2016-4319 2024-11-21 11:51 2017-04-10 Show GitHub Exploit DB Packet Storm
268225 4.8 MEDIUM
Network
atlassian jira Atlassian JIRA Server before 7.1.9 has XSS in project/ViewDefaultProjectRoleActors.jspa via a role name. CWE-79
Cross-site Scripting
CVE-2016-4318 2024-11-21 11:51 2017-04-10 Show GitHub Exploit DB Packet Storm
268226 5.4 MEDIUM
Network
atlassian confluence Atlassian Confluence Server before 5.9.11 has XSS on the viewmyprofile.action page. CWE-79
Cross-site Scripting
CVE-2016-4317 2024-11-21 11:51 2017-04-10 Show GitHub Exploit DB Packet Storm
268227 4.9 MEDIUM
Network
plone plone Chameleon (five.pt) in Plone 5.0rc1 through 5.1a1 allows remote authenticated users to bypass Restricted Python by leveraging permissions to create or edit templates. CWE-264
Permissions, Privileges, and Access Controls
CVE-2016-4043 2024-11-21 11:51 2017-02-25 Show GitHub Exploit DB Packet Storm
268228 5.3 MEDIUM
Network
plone plone Plone 3.3 through 5.1a1 allows remote attackers to obtain information about the ID of sensitive content via unspecified vectors. CWE-200
Information Exposure
CVE-2016-4042 2024-11-21 11:51 2017-02-25 Show GitHub Exploit DB Packet Storm
268229 7.3 HIGH
Network
plone plone Plone 4.0 through 5.1a1 does not have security declarations for Dexterity content-related WebDAV requests, which allows remote attackers to gain webdav access via unspecified vectors. CWE-264
Permissions, Privileges, and Access Controls
CVE-2016-4041 2024-11-21 11:51 2017-02-25 Show GitHub Exploit DB Packet Storm
268230 6.1 MEDIUM
Network
wso2 enablement_server_for_java Cross-site scripting (XSS) vulnerability in WSO2 SOA Enablement Server for Java/6.6 build SSJ-6.6-20090827-1616 and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH… CWE-79
Cross-site Scripting
CVE-2016-4327 2024-11-21 11:51 2017-02-17 Show GitHub Exploit DB Packet Storm