Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 20, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
224631 4.3 警告 Conceptronic - Conceptronic C54APM アクセスポイントにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-1407 2014-01-15 10:11 2014-01-7 Show GitHub Exploit DB Packet Storm
224632 4.3 警告 Conceptronic - Conceptronic C54APM アクセスポイントの goform/formWlSiteSurvey における CRLF インジェクションの脆弱性 CWE-20
不適切な入力確認
CVE-2014-1406 2014-01-15 10:09 2014-01-7 Show GitHub Exploit DB Packet Storm
224633 5.8 警告 Conceptronic - Conceptronic C54APM アクセスポイントにおけるオープンリダイレクトの脆弱性 CWE-20
不適切な入力確認
CVE-2014-1405 2014-01-15 10:08 2014-01-7 Show GitHub Exploit DB Packet Storm
224634 3.5 注意 MantisBT Group - MantisBT の account_sponsor_page.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-4460 2014-01-15 10:00 2013-10-19 Show GitHub Exploit DB Packet Storm
224635 6.4 警告 Jethro Carr - Amberdms Billing System におけるアクセス権を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2010-5291 2014-01-14 18:45 2010-03-8 Show GitHub Exploit DB Packet Storm
224636 1.9 注意 Jethro Carr - Amberdms Billing System における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2010-5292 2014-01-14 18:43 2010-03-8 Show GitHub Exploit DB Packet Storm
224637 7.4 危険 シマンテック - Symantec Endpoint Protection および Endpoint Protection Small Business Edition における権限を取得される脆弱性 CWE-287
不適切な認証
CVE-2013-5009 2014-01-14 18:39 2014-01-9 Show GitHub Exploit DB Packet Storm
224638 4.6 警告 シマンテック - Symantec Endpoint Protection および Endpoint Protection Small Business Edition におけるポリシー制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-5010 2014-01-14 18:35 2014-01-9 Show GitHub Exploit DB Packet Storm
224639 7.2 危険 シマンテック - Symantec Endpoint Protection および Endpoint Protection Small Business Edition における権限を取得される脆弱性 CWE-22
パス・トラバーサル
CVE-2013-5011 2014-01-14 18:32 2014-01-9 Show GitHub Exploit DB Packet Storm
224640 4.3 警告 MyBB Group - MyBB の inc/class_parser.php 内の mycode_parse_video 関数におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-7288 2014-01-14 18:07 2013-12-3 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 20, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
198811 6.1 MEDIUM
Network
open-xchange open-xchange_appsuite OX App Suite through 7.10.4 allows XSS via an appointment in which the location contains JavaScript code. CWE-79
Cross-site Scripting
CVE-2021-23935 2024-11-21 14:52 2021-01-13 Show GitHub Exploit DB Packet Storm
198812 6.1 MEDIUM
Network
open-xchange open-xchange_appsuite OX App Suite through 7.10.4 allows XSS via a contact whose name contains JavaScript code. CWE-79
Cross-site Scripting
CVE-2021-23934 2024-11-21 14:52 2021-01-13 Show GitHub Exploit DB Packet Storm
198813 6.1 MEDIUM
Network
open-xchange open-xchange_appsuite OX App Suite through 7.10.4 allows XSS via JavaScript in a Note referenced by a mail:// URL. CWE-79
Cross-site Scripting
CVE-2021-23933 2024-11-21 14:52 2021-01-13 Show GitHub Exploit DB Packet Storm
198814 6.1 MEDIUM
Network
open-xchange open-xchange_appsuite OX App Suite through 7.10.4 allows XSS via an inline image with a crafted filename. CWE-79
Cross-site Scripting
CVE-2021-23932 2024-11-21 14:52 2021-01-13 Show GitHub Exploit DB Packet Storm
198815 6.1 MEDIUM
Network
open-xchange open-xchange_appsuite OX App Suite through 7.10.4 allows XSS via an inline binary file. CWE-79
Cross-site Scripting
CVE-2021-23931 2024-11-21 14:52 2021-01-13 Show GitHub Exploit DB Packet Storm
198816 6.1 MEDIUM
Network
open-xchange open-xchange_appsuite OX App Suite through 7.10.4 allows XSS via use of the conversion API for a distributedFile. CWE-79
Cross-site Scripting
CVE-2021-23930 2024-11-21 14:52 2021-01-13 Show GitHub Exploit DB Packet Storm
198817 6.1 MEDIUM
Network
open-xchange open-xchange_appsuite OX App Suite through 7.10.4 allows XSS via a crafted Content-Disposition header in an uploaded HTML document to an ajax/share/<share-token>?delivery=view URI. CWE-79
Cross-site Scripting
CVE-2021-23929 2024-11-21 14:52 2021-01-13 Show GitHub Exploit DB Packet Storm
198818 6.1 MEDIUM
Network
open-xchange open-xchange_appsuite OX App Suite through 7.10.3 allows XSS via the ajax/apps/manifests query string. CWE-79
Cross-site Scripting
CVE-2021-23928 2024-11-21 14:52 2021-01-13 Show GitHub Exploit DB Packet Storm
198819 6.4 MEDIUM
Network
open-xchange open-xchange_appsuite OX App Suite through 7.10.4 allows SSRF via a URL with an @ character in an appsuite/api/oauth/proxy PUT request. CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2021-23927 2024-11-21 14:52 2021-01-13 Show GitHub Exploit DB Packet Storm
198820 9.1 CRITICAL
Network
ivanti avalanche An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack. NVD-CWE-noinfo
CVE-2021-22962 2024-11-21 14:51 2023-12-20 Show GitHub Exploit DB Packet Storm