Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 6, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
251201 4.3 警告 IBM - IBM LMC の HTTP-AS におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-4590 2012-03-27 18:42 2010-12-22 Show GitHub Exploit DB Packet Storm
251202 4.3 警告 IBM - IBM ENOVIA 6 におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-4589 2012-03-27 18:42 2010-12-22 Show GitHub Exploit DB Packet Storm
251203 10 危険 IBM - IBM Rational ClearQuest における .ocx ファイルに関する処理に不備がある脆弱性 CWE-noinfo
情報不足
CVE-2010-4601 2012-03-27 18:42 2009-11-2 Show GitHub Exploit DB Packet Storm
251204 4.3 警告 Mozilla Foundation - Bugzilla の chart.cgi における CRLF インジェクションの脆弱性 CWE-94
コード・インジェクション
CVE-2010-4572 2012-03-27 18:42 2011-01-28 Show GitHub Exploit DB Packet Storm
251205 4.3 警告 Mozilla Foundation - Bugzilla の duplicate-detection 機能におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-4570 2012-03-27 18:42 2011-01-28 Show GitHub Exploit DB Packet Storm
251206 4.3 警告 Mozilla Foundation - Bugzilla におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-4569 2012-03-27 18:42 2011-01-28 Show GitHub Exploit DB Packet Storm
251207 7.5 危険 Mozilla Foundation - Bugzilla における任意のアカウントにアクセスされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2010-4568 2012-03-27 18:42 2011-01-28 Show GitHub Exploit DB Packet Storm
251208 4.3 警告 Mozilla Foundation - Bugzilla におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-4567 2012-03-27 18:42 2011-01-28 Show GitHub Exploit DB Packet Storm
251209 4.3 警告 SquirrelMail Project - SquirrelMail におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-4555 2012-03-27 18:42 2011-07-11 Show GitHub Exploit DB Packet Storm
251210 4.3 警告 SquirrelMail Project - SquirrelMail の functions/page_header.php におけるクリックジャック攻撃を誘発する脆弱性 CWE-20
不適切な入力確認
CVE-2010-4554 2012-03-27 18:42 2011-07-12 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 6, 2026, 4:18 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
247241 8.8 HIGH
Network
wstmall wstmall WSTMall v1.9.1_170316 has CSRF via the index.php?m=Admin&c=Users&a=edit URI to add a user account. CWE-352
 Origin Validation Error
CVE-2018-13010 2024-11-21 12:46 2018-06-29 Show GitHub Exploit DB Packet Storm
247242 9.8 CRITICAL
Network
gopro gpmf-parser An issue was discovered in gpmf-parser 1.1.2. There is a heap-based buffer over-read in GPMF_parser.c in the function GPMF_Next, related to certain checks for GPMF_KEY_END and nest_level (conditional… CWE-125
Out-of-bounds Read
CVE-2018-13009 2024-11-21 12:46 2018-06-29 Show GitHub Exploit DB Packet Storm
247243 9.8 CRITICAL
Network
gopro gpmf-parser An issue was discovered in gpmf-parser 1.1.2. There is a heap-based buffer over-read in GPMF_parser.c in the function GPMF_Next, related to certain checks for a positive nest_level. CWE-125
Out-of-bounds Read
CVE-2018-13008 2024-11-21 12:46 2018-06-29 Show GitHub Exploit DB Packet Storm
247244 9.8 CRITICAL
Network
gopro gpmf-parser An issue was discovered in gpmf-parser 1.1.2. There is a heap-based buffer over-read in GPMF_parser.c in the function GPMF_Next, related to certain checks for GPMF_KEY_END and nest_level (not conditi… CWE-125
Out-of-bounds Read
CVE-2018-13007 2024-11-21 12:46 2018-06-29 Show GitHub Exploit DB Packet Storm
247245 9.8 CRITICAL
Network
debian
gpac
canonical
debian_linux
gpac
ubuntu_linux
An issue was discovered in MP4Box in GPAC 0.7.1. There is a heap-based buffer over-read in the isomedia/box_dump.c function hdlr_dump. CWE-125
Out-of-bounds Read
CVE-2018-13006 2024-11-21 12:46 2018-06-29 Show GitHub Exploit DB Packet Storm
247246 9.8 CRITICAL
Network
debian
gpac
canonical
debian_linux
gpac
ubuntu_linux
An issue was discovered in MP4Box in GPAC 0.7.1. The function urn_Read in isomedia/box_code_base.c has a heap-based buffer over-read. CWE-125
Out-of-bounds Read
CVE-2018-13005 2024-11-21 12:46 2018-06-29 Show GitHub Exploit DB Packet Storm
247247 6.1 MEDIUM
Network
opentsdb opentsdb An issue was discovered in OpenTSDB 2.3.0. There is XSS in parameter 'type' to the /suggest URI. CWE-79
Cross-site Scripting
CVE-2018-13003 2024-11-21 12:46 2018-06-29 Show GitHub Exploit DB Packet Storm
247248 6.1 MEDIUM
Network
sandoba cp\ An XSS issue was discovered in Sandoba CP:Shop v2016.1. The vulnerability is located in the `admin.php` file of the `./cpshop/` module. Remote attackers are able to inject their own script codes to t… CWE-79
Cross-site Scripting
CVE-2018-13001 2024-11-21 12:46 2018-06-29 Show GitHub Exploit DB Packet Storm
247249 7.5 HIGH
Network
zohocorp manageengine_desktop_central Incorrect Access Control in AgentTrayIconServlet in Zoho ManageEngine Desktop Central 10.0.255 allows attackers to delete certain files on the web server without login by sending a specially crafted … CWE-20
 Improper Input Validation 
CVE-2018-12999 2024-11-21 12:46 2018-06-29 Show GitHub Exploit DB Packet Storm
247250 6.1 MEDIUM
Network
zohocorp manageengine_applications_manager A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager before 13 (Build 13800) allows remote attackers to inject arbitrary web script or HTML via the parameter… CWE-79
Cross-site Scripting
CVE-2018-12996 2024-11-21 12:46 2018-06-29 Show GitHub Exploit DB Packet Storm