Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 13, 2026, noon

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
223911 7.5 危険 VastHTML - WordPress 用 ForumPress WP Forum Server プラグインにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2012-6625 2014-01-21 16:09 2012-04-18 Show GitHub Exploit DB Packet Storm
223912 4.3 警告 Mightymess - WordPress 用 SoundCloud Is Gold プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-6624 2014-01-21 16:08 2012-05-15 Show GitHub Exploit DB Packet Storm
223913 7.5 危険 Brian Cabunac - b2ePMS の verify-user.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2012-6626 2014-01-21 14:52 2012-05-11 Show GitHub Exploit DB Packet Storm
223914 4.3 警告 Vessio - Vessio NetBill におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-6632 2014-01-21 14:26 2012-05-11 Show GitHub Exploit DB Packet Storm
223915 6.8 警告 Vessio - Vessio NetBill の accounts/admin/index.php におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2012-6631 2014-01-21 14:24 2012-05-11 Show GitHub Exploit DB Packet Storm
223916 7.5 危険 Google - Google Chrome の content/browser/web_contents/web_contents_view_aura.cc におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2013-6645 2014-01-20 18:05 2014-01-14 Show GitHub Exploit DB Packet Storm
223917 7.5 危険 Google - Google Chrome の Web Worker の実装におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2013-6646 2014-01-20 17:48 2014-01-14 Show GitHub Exploit DB Packet Storm
223918 7.5 危険 Google - Google Chrome におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2013-6644 2014-01-20 17:47 2014-01-14 Show GitHub Exploit DB Packet Storm
223919 7.5 危険 Google - Google Chrome の browser/ui/views/sync/one_click_signin_bubble_view.cc における任意の Google アカウントとの同期を誘発される脆弱性 CWE-287
不適切な認証
CVE-2013-6643 2014-01-20 17:47 2014-01-14 Show GitHub Exploit DB Packet Storm
223920 5 警告 Google - Android 上で稼働する Google Chrome におけるアドレスバーを偽装される脆弱性 CWE-noinfo
情報不足
CVE-2013-6642 2014-01-20 17:46 2014-01-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 13, 2026, 4:20 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
314361 - - - A flaw was found in pdfTeX. Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available, such as those with TeX Live installed. - CVE-2024-43426 2024-11-9 04:01 2024-11-7 Show GitHub Exploit DB Packet Storm
314362 - - - A flaw was found in Moodle. Additional restrictions are required to avoid a remote code execution risk in calculated question types. Note: This requires the capability to add/update questions. - CVE-2024-43425 2024-11-9 04:01 2024-11-7 Show GitHub Exploit DB Packet Storm
314363 6.4 MEDIUM
Network
- - The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Blog widget in all v… CWE-79
Cross-site Scripting
CVE-2024-8442 2024-11-9 04:01 2024-11-7 Show GitHub Exploit DB Packet Storm
314364 - - - Authenticated Gaia users can inject code or commands by global variables through special HTTP requests. A Security fix that mitigates this vulnerability is available. - CVE-2024-24914 2024-11-9 04:01 2024-11-7 Show GitHub Exploit DB Packet Storm
314365 - - - Rapid7 Velociraptor MSI Installer versions below 0.73.3 suffer from a vulnerability whereby it creates the installation directory with WRITE_DACL permission to the BUILTIN\\Users group. This allows l… - CVE-2024-10526 2024-11-9 04:01 2024-11-7 Show GitHub Exploit DB Packet Storm
314366 - - - Password Pusher is an open source application to communicate sensitive information over the web. A cross-site scripting (XSS) vulnerability was identified in the PasswordPusher application, affecting… CWE-79
Cross-site Scripting
CVE-2024-51989 2024-11-9 04:01 2024-11-8 Show GitHub Exploit DB Packet Storm
314367 - - - In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Avoid CPU lockups due fifo occupancy check loop Driver waits indefinitely for the fifo occupancy to go below a thre… - CVE-2024-50157 2024-11-9 04:01 2024-11-7 Show GitHub Exploit DB Packet Storm
314368 - - - Zohocorp ManageEngine EndPoint Central versions 11.3.2416.21 and below, 11.3.2428.9 and below are vulnerable to Arbitrary File Deletion in the agent installed machines. - CVE-2024-10203 2024-11-9 04:01 2024-11-7 Show GitHub Exploit DB Packet Storm
314369 7.5 HIGH
Network
- - A flaw was found in Undertow package. Using the FormAuthenticationMechanism, a malicious user could trigger a Denial of Service by sending crafted requests, leading the server to an OutofMemory error… - CVE-2023-1973 2024-11-9 04:01 2024-11-7 Show GitHub Exploit DB Packet Storm
314370 - - - A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in… - CVE-2023-1932 2024-11-9 04:01 2024-11-7 Show GitHub Exploit DB Packet Storm