Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 1, 2026, 4:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
225051 7.5 危険 Appnitro Software - Machform の view.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2013-4948 2013-07-31 15:27 2013-07-2 Show GitHub Exploit DB Packet Storm
225052 7.5 危険 Sawmill - Sawmill のデータベースのページの更新および作成における脆弱性 CWE-noinfo
情報不足
CVE-2013-4947 2013-07-31 15:18 2013-07-9 Show GitHub Exploit DB Packet Storm
225053 4.3 警告 BMC Software - BMC Service Desk Express におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-4946 2013-07-31 15:11 2013-06-12 Show GitHub Exploit DB Packet Storm
225054 7.5 危険 BMC Software - BMC Service Desk Express における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2013-4945 2013-07-31 15:08 2013-06-12 Show GitHub Exploit DB Packet Storm
225055 2.1 注意 Drupal Indonesia - Drupal 用 TinyBox モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-4140 2013-07-31 14:44 2013-07-10 Show GitHub Exploit DB Packet Storm
225056 2.6 注意 BuddyDev.com - WordPress 用 BuddyPress Extended Friendship Request プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-4944 2013-07-31 14:36 2013-07-2 Show GitHub Exploit DB Packet Storm
225057 4.3 警告 OpenX - OpenX Source におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-3515 2013-07-31 14:08 2013-05-8 Show GitHub Exploit DB Packet Storm
225058 4.3 警告 Monkey Project - Monkey HTTP Daemon の Directory Listing プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-2181 2013-07-31 13:55 2013-06-14 Show GitHub Exploit DB Packet Storm
225059 9.3 危険 キングソフト株式会社 - Kingsoft Spreadsheets 2012 におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2013-0723 2013-07-31 13:47 2013-07-29 Show GitHub Exploit DB Packet Storm
225060 5 警告 ヒューレット・パッカード
レッドハット
- 複数の Red Hat JBoss 製品の JBossWS Native におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2011-1483 2013-07-30 17:40 2011-04-4 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 1, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
211571 8.8 HIGH
Network
dbhcms_project dbhcms DBHcms v1.2.0 has no CSRF protection mechanism,as demonstrated by CSRF for index.php?dbhcms_pid=-70 can add a user. CWE-352
 Origin Validation Error
CVE-2020-19889 2024-11-21 14:09 2020-08-25 Show GitHub Exploit DB Packet Storm
211572 5.9 MEDIUM
Network
dbhcms_project dbhcms DBHcms v1.2.0 has an unauthorized operation vulnerability because there's no access control at line 175 of dbhcms\page.php for empty cache operation. This vulnerability can be exploited to empty a ta… CWE-287
Improper Authentication
CVE-2020-19888 2024-11-21 14:09 2020-08-25 Show GitHub Exploit DB Packet Storm
211573 4.8 MEDIUM
Network
dbhcms_project dbhcms DBHcms v1.2.0 has a stored XSS vulnerability as there is no htmlspecialchars function for '$_POST['pageparam_insert_description']' variable in dbhcms\mod\mod.page.edit.php line 227, A remote authenti… CWE-79
Cross-site Scripting
CVE-2020-19887 2024-11-21 14:09 2020-08-25 Show GitHub Exploit DB Packet Storm
211574 8.1 HIGH
Network
dbhcms_project dbhcms DBHcms v1.2.0 has no CSRF protection mechanism,as demonstrated by CSRF for an /index.php?dbhcms_pid=-80&deletemenu=9 can delete any menu. CWE-352
 Origin Validation Error
CVE-2020-19886 2024-11-21 14:09 2020-08-25 Show GitHub Exploit DB Packet Storm
211575 4.8 MEDIUM
Network
dbhcms_project dbhcms DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function for '$_POST['pageparam_insert_name']' variable in dbhcms\mod\mod.page.edit.php line 227, A remote authenticated w… CWE-79
Cross-site Scripting
CVE-2020-19885 2024-11-21 14:09 2020-08-25 Show GitHub Exploit DB Packet Storm
211576 4.8 MEDIUM
Network
dbhcms_project dbhcms DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function in dbhcms\mod\mod.domain.edit.php line 119. CWE-79
Cross-site Scripting
CVE-2020-19884 2024-11-21 14:09 2020-08-25 Show GitHub Exploit DB Packet Storm
211577 4.8 MEDIUM
Network
dbhcms_project dbhcms DBHcms v1.2.0 has a stored xss vulnerability as there is no security filter in dbhcms\mod\mod.users.view.php line 57 for user_login, A remote authenticated with admin user can exploit this vulnerabil… CWE-79
Cross-site Scripting
CVE-2020-19883 2024-11-21 14:09 2020-08-25 Show GitHub Exploit DB Packet Storm
211578 4.8 MEDIUM
Network
dbhcms_project dbhcms DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function for 'menu_description' variable in dbhcms\mod\mod.menus.edit.php line 83 and in dbhcms\mod\mod.menus.view.php lin… CWE-79
Cross-site Scripting
CVE-2020-19882 2024-11-21 14:09 2020-08-25 Show GitHub Exploit DB Packet Storm
211579 4.8 MEDIUM
Network
dbhcms_project dbhcms DBHcms v1.2.0 has a reflected xss vulnerability as there is no security filter in dbhcms\mod\mod.selector.php line 108 for $_GET['return_name'] parameter, A remote authenticated with admin user can e… CWE-79
Cross-site Scripting
CVE-2020-19881 2024-11-21 14:09 2020-08-25 Show GitHub Exploit DB Packet Storm
211580 6.1 MEDIUM
Network
dbhcms_project dbhcms DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function form 'Name' in dbhcms\types.php, A remote unauthenticated attacker can exploit this vulnerability to hijack other… CWE-79
Cross-site Scripting
CVE-2020-19880 2024-11-21 14:09 2020-08-25 Show GitHub Exploit DB Packet Storm