Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 3, 2026, 2:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
251111 4.3 警告 Horde - Horde IMP および Horde Groupware Webmail Edition の fetchmailprefs.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-3695 2012-03-27 18:42 2011-03-31 Show GitHub Exploit DB Packet Storm
251112 4.3 警告 Horde - Horde DIMP および Horde Groupware Webmail Edition におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-3693 2012-03-27 18:42 2011-04-4 Show GitHub Exploit DB Packet Storm
251113 6.8 警告 Horde - Horde Application Framework におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2010-3694 2012-03-27 18:42 2010-11-9 Show GitHub Exploit DB Packet Storm
251114 6.4 警告 Jasig - phpCAS の callback 関数におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2010-3692 2012-03-27 18:42 2010-10-7 Show GitHub Exploit DB Packet Storm
251115 3.3 注意 Jasig - phpCAS の PGTStorage/pgt-file.php における任意のファイルを上書きされる脆弱性 CWE-59
リンク解釈の問題
CVE-2010-3691 2012-03-27 18:42 2010-10-7 Show GitHub Exploit DB Packet Storm
251116 4.3 警告 Jasig - phpCAS におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-3690 2012-03-27 18:42 2010-10-7 Show GitHub Exploit DB Packet Storm
251117 7.5 危険 NetArt Media - NetArtMEDIA WebSiteAdmin の ADMIN/login.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2010-3688 2012-03-27 18:42 2010-09-29 Show GitHub Exploit DB Packet Storm
251118 5 警告 Alex Kellner
TYPO3 Association
- TYPO3 の powermail extension における検証を回避される脆弱性 CWE-noinfo
情報不足
CVE-2010-3687 2012-03-27 18:42 2010-09-22 Show GitHub Exploit DB Packet Storm
251119 2.1 注意 Synology Inc. - Synology Disk Station の FTP 認証モジュールにおける重要な情報を取得される脆弱性 CWE-255
証明書・パスワード管理
CVE-2010-3684 2012-03-27 18:42 2010-09-29 Show GitHub Exploit DB Packet Storm
251120 7.5 危険 wire plastic design - wpQuiz における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-3608 2012-03-27 18:42 2010-09-24 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 3, 2026, 4:18 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
257401 7.5 HIGH
Network
episerver episerver XML external entity (XXE) vulnerability in Episerver 7 patch 4 and earlier allows remote attackers to read arbitrary files via a crafted DTD in an XML request involving util/xmlrpc/Handler.ashx. CWE-611
XXE
CVE-2017-17762 2024-11-21 12:18 2018-08-30 Show GitHub Exploit DB Packet Storm
257402 4.3 MEDIUM
Network
pleasantsolutions pleasant_password_server Because of insufficient authorization checks it is possible for any authenticated user to change profile data of other users in Pleasant Password Server before 7.8.3. CWE-863
 Incorrect Authorization
CVE-2017-17708 2024-11-21 12:18 2018-07-31 Show GitHub Exploit DB Packet Storm
257403 8.1 HIGH
Network
pleasantsolutions pleasant_password_server Due to missing authorization checks, any authenticated user is able to list, upload, or delete attachments to password safe entries in Pleasant Password Server before 7.8.3. To perform those actions … CWE-862
 Missing Authorization
CVE-2017-17707 2024-11-21 12:18 2018-07-31 Show GitHub Exploit DB Packet Storm
257404 6.1 MEDIUM
Network
fortinet fortianalyzer_firmware
fortimanager_firmware
A Cross-site Scripting (XSS) vulnerability in Fortinet FortiManager 6.0.0, 5.6.4 and below versions, FortiAnalyzer 6.0.0, 5.6.4 and below versions allows inject Javascript code and HTML tags through … CWE-79
Cross-site Scripting
CVE-2017-17541 2024-11-21 12:18 2018-07-17 Show GitHub Exploit DB Packet Storm
257405 5.9 MEDIUM
Network
microsoft
horde
google
9folders
flipdogsolutions
r2mail2
apple
bloop
freron
kde
gnome
mozilla
ibm
emclient
postbox-inc
ritlabs
outlook
horde_imp
gmail
nine
maildroid
r2mail2
mail
airmail
mailmate
kmail
trojita
evolution
thunderbird
notes
emclient
postbox
the_bat
The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NVD-CWE-noinfo
CVE-2017-17689 2024-11-21 12:18 2018-05-17 Show GitHub Exploit DB Packet Storm
257406 5.9 MEDIUM
Network
microsoft
horde
flipdogsolutions
r2mail2
apple
bloop
freron
mozilla
emclient
postbox-inc
roundcube
outlook
horde_imp
maildroid
r2mail2
mail
airmail
mailmate
thunderbird
emclient
postbox
webmail
The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report that this is a probl… NVD-CWE-noinfo
CVE-2017-17688 2024-11-21 12:18 2018-05-17 Show GitHub Exploit DB Packet Storm
257407 9.8 CRITICAL
Network
fortinet fortiwlc The presence of a hardcoded account in Fortinet FortiWLC 8.3.3 allows attackers to gain unauthorized read/write access via a remote shell. CWE-798
 Use of Hard-coded Credentials
CVE-2017-17540 2024-11-21 12:18 2018-05-8 Show GitHub Exploit DB Packet Storm
257408 9.8 CRITICAL
Network
fortinet fortiwlc The presence of a hardcoded account in Fortinet FortiWLC 7.0.11 and earlier allows attackers to gain unauthorized read/write access via a remote shell. CWE-798
 Use of Hard-coded Credentials
CVE-2017-17539 2024-11-21 12:18 2018-05-8 Show GitHub Exploit DB Packet Storm
257409 7.5 HIGH
Network
fortinet forticlient
forticlient_sslvpn_client
Users' VPN authentication credentials are unsafely encrypted in Fortinet FortiClient for Windows 5.6.0 and below versions, FortiClient for Mac OSX 5.6.0 and below versions and FortiClient SSLVPN Clie… CWE-326
Inadequate Encryption Strength
CVE-2017-17543 2024-11-21 12:18 2018-04-27 Show GitHub Exploit DB Packet Storm
257410 8.8 HIGH
Network
foxitsoftware phantompdf
foxit_reader
In Foxit Reader before 9.1 and Foxit PhantomPDF before 9.1, a flaw exists within the parsing of the BITMAPINFOHEADER record in BMP files. The issue results from the lack of proper validation of the b… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2017-17557 2024-11-21 12:18 2018-04-25 Show GitHub Exploit DB Packet Storm