Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 12, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
224211 6.5 警告 サイボウズ - サイボウズ ガルーンにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2013-6929 2014-01-7 19:20 2013-12-25 Show GitHub Exploit DB Packet Storm
224212 5 警告 WesternDeal - WordPress 用 Advanced Dewplayer プラグインの download-file.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2013-7240 2014-01-7 18:50 2013-12-30 Show GitHub Exploit DB Packet Storm
224213 4.3 警告 Ad-minister Project - WordPress 用 Ad-minister プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-6993 2014-01-7 18:49 2013-12-26 Show GitHub Exploit DB Packet Storm
224214 6.8 警告 AskApache - WordPress 用 AskApache Firefox Adsense プラグインの askapache-firefox-adsense.php におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2013-6992 2014-01-7 18:49 2013-12-26 Show GitHub Exploit DB Packet Storm
224215 4.3 警告 OKAMOTO Wataru - WordPress 用 WP-Cron Dashboard プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-6991 2014-01-7 18:49 2013-12-26 Show GitHub Exploit DB Packet Storm
224216 8.5 危険 IBM - IBM i および zSeries サーバ上で稼働する z/OS の OSPF の実装におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2013-5385 2014-01-7 17:35 2013-08-1 Show GitHub Exploit DB Packet Storm
224217 4.3 警告 Codiad - Codiad におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-7257 2014-01-7 17:22 2013-12-20 Show GitHub Exploit DB Packet Storm
224218 6.8 警告 Opsview - Opsview におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2013-7256 2014-01-7 17:13 2013-12-23 Show GitHub Exploit DB Packet Storm
224219 5.8 警告 Opsview - Opsview におけるオープンリダイレクトの脆弱性 CWE-20
不適切な入力確認
CVE-2013-7255 2014-01-7 17:12 2013-12-23 Show GitHub Exploit DB Packet Storm
224220 4.3 警告 Opsview - Opsview におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-7254 2014-01-7 17:12 2013-12-23 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 12, 2026, 4:20 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
199701 9.8 CRITICAL
Network
alfasado powercms PowerCMS XMLRPC API of PowerCMS 5.19 and earlier, PowerCMS 4.49 and earlier, PowerCMS 3.295 and earlier, and PowerCMS 2 Series (End-of-Life, EOL) allows a remote attacker to execute an arbitrary OS c… CWE-78
OS Command 
CVE-2021-20850 2024-11-21 14:47 2021-11-25 Show GitHub Exploit DB Packet Storm
199702 6.1 MEDIUM
Network
rwtxt_project rwtxt Cross-site scripting vulnerability in rwtxt versions prior to v1.8.6 allows a remote attacker to inject an arbitrary script via unspecified vectors. CWE-79
Cross-site Scripting
CVE-2021-20848 2024-11-21 14:47 2021-11-25 Show GitHub Exploit DB Packet Storm
199703 8.8 HIGH
Network
delitestudio push_notifications_for_wordpress Cross-site request forgery (CSRF) vulnerability in Push Notifications for WordPress (Lite) versions prior to 6.0.1 allows a remote attacker to hijack the authentication of an administrator and conduc… CWE-352
 Origin Validation Error
CVE-2021-20846 2024-11-21 14:47 2021-11-25 Show GitHub Exploit DB Packet Storm
199704 8.8 HIGH
Network
xml-sitemaps unlimited_sitemap_generator Cross-site request forgery (CSRF) vulnerability in Unlimited Sitemap Generator versions prior to v8.2 allows a remote attacker to hijack the authentication of an administrator and conduct arbitrary o… CWE-352
 Origin Validation Error
CVE-2021-20845 2024-11-21 14:47 2021-11-25 Show GitHub Exploit DB Packet Storm
199705 5.7 MEDIUM
Network
yamaha
ntt-west
rtx830_firmware
nvr510_firmware
nvr700w_firmware
rtx1210_firmware
biz_box_rtx830_firmware
biz_box_nvr510_firmware
biz_box_nvr700w_firmware
biz_box_rtx1210_firmware
Improper neutralization of HTTP request headers for scripting syntax vulnerability in the Web GUI of RTX830 Rev.15.02.17 and earlier, NVR510 Rev.15.01.18 and earlier, NVR700W Rev.15.00.19 and earlier… CWE-116
 Improper Encoding or Escaping of Output
CVE-2021-20844 2024-11-21 14:47 2021-11-25 Show GitHub Exploit DB Packet Storm
199706 5.4 MEDIUM
Network
yamaha
ntt-west
rtx830_firmware
nvr510_firmware
nvr700w_firmware
rtx1210_firmware
biz_box_rtx830_firmware
biz_box_nvr510_firmware
biz_box_nvr700w_firmware
biz_box_rtx1210_firmware
Cross-site script inclusion vulnerability in the Web GUI of RTX830 Rev.15.02.17 and earlier, NVR510 Rev.15.01.18 and earlier, NVR700W Rev.15.00.19 and earlier, and RTX1210 Rev.14.01.38 and earlier al… CWE-829
 Inclusion of Functionality from Untrusted Control Sphere
CVE-2021-20843 2024-11-21 14:47 2021-11-25 Show GitHub Exploit DB Packet Storm
199707 6.5 MEDIUM
Network
ec-cube ec-cube Cross-site request forgery (CSRF) vulnerability in EC-CUBE 2 series 2.11.0 to 2.17.1 allows a remote attacker to hijack the authentication of Administrator and delete Administrator via a specially cr… CWE-352
 Origin Validation Error
CVE-2021-20842 2024-11-21 14:47 2021-11-25 Show GitHub Exploit DB Packet Storm
199708 6.5 MEDIUM
Network
ec-cube ec-cube Improper access control in Management screen of EC-CUBE 2 series 2.11.2 to 2.17.1 allows a remote authenticated attacker to bypass access restriction and to alter System settings via unspecified vect… NVD-CWE-Other
CVE-2021-20841 2024-11-21 14:47 2021-11-25 Show GitHub Exploit DB Packet Storm
199709 6.1 MEDIUM
Network
saasproject booking_package Cross-site scripting vulnerability in Booking Package - Appointment Booking Calendar System versions prior to 1.5.11 allows a remote attacker to inject an arbitrary script via unspecified vectors. CWE-79
Cross-site Scripting
CVE-2021-20840 2024-11-21 14:47 2021-11-25 Show GitHub Exploit DB Packet Storm
199710 7.5 HIGH
Network
mercari mercari Improper authorization in handler for custom URL scheme vulnerability in Android App 'Mercari (Merpay) - Marketplace and Mobile Payments App' (Japan version) versions prior to 4.49.1 allows a remote … CWE-862
 Missing Authorization
CVE-2021-20835 2024-11-21 14:47 2021-11-25 Show GitHub Exploit DB Packet Storm