Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 27, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
252331 5.8 警告 The Tor Project - Tor における匿名化のためのプロパティを無効にされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2011-2768 2011-12-27 10:54 2011-10-27 Show GitHub Exploit DB Packet Storm
252332 7.5 危険 PmWiki - PmWiki の PageListSort 関数における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2011-4453 2011-12-27 10:46 2011-11-11 Show GitHub Exploit DB Packet Storm
252333 - - The Support Incident Tracker Project - Support Incident Tracker に複数の脆弱性 - CVE-2011-3831
CVE-2011-3833
CVE-2011-5067
CVE-2011-5068
CVE-2011-5069
CVE-2011-5070
2011-12-27 09:42 2011-12-5 Show GitHub Exploit DB Packet Storm
252334 9.3 危険 Sielco Sistemi - Sielco Sistemi Winlog PRO および Winlog Lite におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2011-4037 2011-12-26 16:32 2011-12-22 Show GitHub Exploit DB Packet Storm
252335 5 警告 Moodle - Moodle の calendar/set.php における CRLF インジェクションの脆弱性 CWE-94
コード・インジェクション
CVE-2011-4203 2011-12-26 16:32 2011-12-22 Show GitHub Exploit DB Packet Storm
252336 4.3 警告 The phpMyAdmin Project - phpMyAdmin におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-4634 2011-12-26 16:31 2011-12-1 Show GitHub Exploit DB Packet Storm
252337 4.3 警告 The phpMyAdmin Project - phpMyAdmin の libraries/display_export.lib.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-4780 2011-12-26 16:30 2011-12-21 Show GitHub Exploit DB Packet Storm
252338 4.3 警告 The phpMyAdmin Project - phpMyAdmin の libraries/config/ConfigFile.class.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-4782 2011-12-26 16:29 2011-12-21 Show GitHub Exploit DB Packet Storm
252339 6.5 警告 WordPress.org - WordPress において任意の PHP コードが実行可能な脆弱性 CWE-94
コード・インジェクション
- 2011-12-26 14:27 2011-12-26 Show GitHub Exploit DB Packet Storm
252340 4.3 警告 WordPress.org - WordPress 日本語版におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
- 2011-12-26 12:01 2011-12-26 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 27, 2026, 4:52 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
274801 9.8 CRITICAL
Network
pivotal_software
cloudfoundry
cloud_foundry_elastic_runtime
cloud_foundry_uaa
cf-release
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact by leveraging failure to expire … CWE-640
 Weak Password Recovery Mechanism for Forgotten Password
CVE-2015-5172 2024-11-21 11:32 2017-10-25 Show GitHub Exploit DB Packet Storm
274802 9.8 CRITICAL
Network
pivotal_software
cloudfoundry
cloud_foundry_elastic_runtime
cloud_foundry_uaa
cf-release
The password change functionality in Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified im… CWE-613
 Insufficient Session Expiration
CVE-2015-5171 2024-11-21 11:32 2017-10-25 Show GitHub Exploit DB Packet Storm
274803 8.8 HIGH
Network
pivotal_software
cloudfoundry
cloud_foundry_elastic_runtime
cloud_foundry_uaa
cf-release
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow remote attackers to conduct cross-site request forgery (CSRF) attacks… CWE-352
 Origin Validation Error
CVE-2015-5170 2024-11-21 11:32 2017-10-25 Show GitHub Exploit DB Packet Storm
274804 5.4 MEDIUM
Network
axigen axigen_mail_server Cross-site scripting (XSS) vulnerability in actions.hsp in the Ajax WebMail interface in AXIGEN Mail Server before 9.0 allows remote attackers to inject arbitrary web script or HTML via an email atta… CWE-79
Cross-site Scripting
CVE-2015-5379 2024-11-21 11:32 2017-10-24 Show GitHub Exploit DB Packet Storm
274805 7.5 HIGH
Network
openslp
debian
openslp
debian_linux
Double free vulnerability in the SLPDKnownDAAdd function in slpd/slpd_knownda.c in OpenSLP 1.2.1 allows remote attackers to cause a denial of service (crash) via a crafted package. CWE-415
 Double Free
CVE-2015-5177 2024-11-21 11:32 2017-10-23 Show GitHub Exploit DB Packet Storm
274806 9.8 CRITICAL
Network
gsi-office winpat_portal SQL injection vulnerability in the login form in GSI WiNPAT Portal 3.2.0.1001 through 3.6.1.0 allows remote attackers to execute arbitrary SQL commands via the username field. CWE-89
SQL Injection
CVE-2015-5376 2024-11-21 11:32 2017-10-19 Show GitHub Exploit DB Packet Storm
274807 8.8 HIGH
Network
inboundnow wordpress_landing_pages The Landing Pages plugin before 1.9.2 for WordPress allows remote attackers to execute arbitrary code via the url parameter. CWE-74
Injection
CVE-2015-5227 2024-11-21 11:32 2017-10-19 Show GitHub Exploit DB Packet Storm
274808 7.2 HIGH
Network
pulpproject qpid The Qpid server on Red Hat Satellite 6 does not properly restrict message types, which allows remote authenticated users with administrative access on a managed content host to execute arbitrary code… CWE-502
 Deserialization of Untrusted Data
CVE-2015-5164 2024-11-21 11:32 2017-10-19 Show GitHub Exploit DB Packet Storm
274809 8.1 HIGH
Network
theforeman foreman The LDAP Authentication functionality in Foreman might allow remote attackers with knowledge of old passwords to gain access via vectors involving the password lifetime period in Active Directory. CWE-254
 7PK - Security Features
CVE-2015-5246 2024-11-21 11:32 2017-10-7 Show GitHub Exploit DB Packet Storm
274810 3.1 LOW
Network
wesnoth
fedoraproject
battle_for_wesnoth
fedora
The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp in Battle for Wesnoth before 1.12.4 and 1.13.x before 1.13.1, when a case-insens… CWE-200
Information Exposure
CVE-2015-5070 2024-11-21 11:32 2017-09-26 Show GitHub Exploit DB Packet Storm