Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 30, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
224631 4 警告 Open-Xchange - Open-Xchange Server におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2013-1645 2013-09-6 16:14 2013-03-13 Show GitHub Exploit DB Packet Storm
224632 3.5 注意 Open-Xchange - Open-Xchange App Suite および Server におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-5698 2013-09-6 16:11 2013-06-3 Show GitHub Exploit DB Packet Storm
224633 3.5 注意 Open-Xchange - Open-Xchange App Suite における他のユーザの電子メールの認証情報を取得される脆弱性 CWE-255
証明書・パスワード管理
CVE-2013-4790 2013-09-6 16:03 2013-07-31 Show GitHub Exploit DB Packet Storm
224634 4.3 警告 Open-Xchange - Open-Xchange App Suite および Server におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-3106 2013-09-6 15:03 2013-06-3 Show GitHub Exploit DB Packet Storm
224635 4.3 警告 Open-Xchange - Open-Xchange App Suite および Server におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-2583 2013-09-6 14:54 2013-04-17 Show GitHub Exploit DB Packet Storm
224636 5 警告 Open-Xchange - Open-Xchange App Suite および Server のリダイレクトサーブレットにおける CRLF インジェクションの脆弱性 CWE-94
コード・インジェクション
CVE-2013-2582 2013-09-6 14:47 2013-04-17 Show GitHub Exploit DB Packet Storm
224637 5.8 警告 DELL EMC (旧 EMC Corporation) - EMC RSA Archer GRC におけるオープンリダイレクトの脆弱性 CWE-20
不適切な入力確認
CVE-2013-3277 2013-09-6 12:06 2013-09-3 Show GitHub Exploit DB Packet Storm
224638 6.8 警告 シスコシステムズ - Cisco Global Site Selector の Web フレームワークにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2013-5471 2013-09-6 11:49 2013-09-4 Show GitHub Exploit DB Packet Storm
224639 6.8 警告 ShareThis - WordPress 用 ShareThis プラグインにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2013-3479 2013-09-6 11:44 2013-08-27 Show GitHub Exploit DB Packet Storm
224640 4.3 警告 シスコシステムズ - Cisco Prime NCS および Cisco WCS にクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-5990 2013-09-5 19:40 2013-09-3 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 30, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
313441 - - - A vulnerability was found in OpenSight Software FlashFXP 5.4.0.3970. It has been classified as critical. Affected is an unknown function in the library libcrypto-1_1.dll of the file FlashFXP.exe. The… CWE-427
 Uncontrolled Search Path Element
CVE-2024-10068 2024-10-18 21:52 2024-10-17 Show GitHub Exploit DB Packet Storm
313442 7.2 HIGH
Network
- - The SendPulse Free Web Push plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.3.6 due to incorrect use of the wp_kses_allowed_html function. Th… CWE-79
Cross-site Scripting
CVE-2024-9184 2024-10-18 21:52 2024-10-17 Show GitHub Exploit DB Packet Storm
313443 6.4 MEDIUM
Network
- - The Fonto – Custom Web Fonts Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.2.1 due to insufficient input sanit… CWE-79
Cross-site Scripting
CVE-2024-8920 2024-10-18 21:52 2024-10-17 Show GitHub Exploit DB Packet Storm
313444 - - - Stored cross-site scripting (XSS) vulnerability on enrollment invitation page. The following products are affected: Acronis Cyber Files (Windows) before build 9.0.0x24. CWE-79
Cross-site Scripting
CVE-2024-49392 2024-10-18 21:52 2024-10-17 Show GitHub Exploit DB Packet Storm
313445 - - - Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Files (Windows) before build 9.0.0x24. CWE-427
 Uncontrolled Search Path Element
CVE-2024-49391 2024-10-18 21:52 2024-10-17 Show GitHub Exploit DB Packet Storm
313446 - - - Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Files (Windows) before build 9.0.0x24. CWE-427
 Uncontrolled Search Path Element
CVE-2024-49390 2024-10-18 21:52 2024-10-17 Show GitHub Exploit DB Packet Storm
313447 - - - Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Files (Windows) before build 9.0.0x24. CWE-276
Incorrect Default Permissions 
CVE-2024-49389 2024-10-18 21:52 2024-10-17 Show GitHub Exploit DB Packet Storm
313448 - - - Sensitive information disclosure due to spell-jacking. The following products are affected: Acronis Cyber Files (Windows) before build 9.0.0x24. CWE-359
 Exposure of Private Personal Information to an Unauthorized Actor
CVE-2024-49386 2024-10-18 21:52 2024-10-17 Show GitHub Exploit DB Packet Storm
313449 - - - A vulnerability in the .sdd file allows an attacker to read default passwords stored in plain text within the code. By exploiting these plaintext credentials, an attacker can log into affected SICK p… - CVE-2024-10025 2024-10-18 21:52 2024-10-17 Show GitHub Exploit DB Packet Storm
313450 6.1 MEDIUM
Network
- - The WP Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wppa-tab' parameter in all versions up to, and including, 8.8.05.003 due to insufficient input sa… CWE-79
Cross-site Scripting
CVE-2024-9951 2024-10-18 21:52 2024-10-17 Show GitHub Exploit DB Packet Storm