Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 12, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228461 4.3 警告 IBM - 複数の IBM 製品におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-3328 2013-02-21 18:23 2012-02-15 Show GitHub Exploit DB Packet Storm
228462 4.3 警告 IBM - 複数の IBM 製品におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-3327 2013-02-21 18:22 2012-02-15 Show GitHub Exploit DB Packet Storm
228463 3.5 注意 IBM - 複数の IBM 製品におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-3322 2013-02-21 18:21 2012-02-15 Show GitHub Exploit DB Packet Storm
228464 6.5 警告 IBM - IBM SmartCloud Control Desk におけるアクセス制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-3321 2013-02-21 18:21 2012-02-15 Show GitHub Exploit DB Packet Storm
228465 3.5 注意 IBM - 複数の IBM 製品の TPAE におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-3316 2013-02-21 18:20 2012-02-15 Show GitHub Exploit DB Packet Storm
228466 7.5 危険 IBM - IBM SAN Volume Controller および Storwize の管理 GUI における認証を回避される脆弱性 CWE-287
不適切な認証
CVE-2012-6354 2013-02-21 18:20 2013-02-5 Show GitHub Exploit DB Packet Storm
228467 5 警告 シスコシステムズ - Cisco Unity Connection におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2013-1129 2013-02-21 16:41 2013-02-15 Show GitHub Exploit DB Packet Storm
228468 6.8 警告 シスコシステムズ - 複数の Cisco 製品のコマンドラインインターフェイスにおける root 権限を取得される脆弱性 CWE-20
不適切な入力確認
CVE-2013-1125 2013-02-21 16:40 2013-02-15 Show GitHub Exploit DB Packet Storm
228469 2.6 注意 コンクリートファイブ - concrete5 におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-5181 2013-02-20 16:01 2012-12-21 Show GitHub Exploit DB Packet Storm
228470 7.2 危険 マイクロソフト - Microsoft Windows のカーネルモードドライバ内の win32k.sys における権限昇格の脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-0008 2013-02-20 14:31 2013-01-8 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 12, 2026, 4:20 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
194241 7.5 HIGH
Network
invoiceplane invoiceplane In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download. Allowing an attacker to directory traversal and download files suppose to be private with… CWE-552
 Files or Directories Accessible to External Parties
CVE-2021-29024 2024-11-21 15:00 2021-05-18 Show GitHub Exploit DB Packet Storm
194242 5.3 MEDIUM
Network
invoiceplane invoiceplane InvoicePlane 1.5.11 doesn't have any rate-limiting for password reset and the reset token is generated using a weak mechanism that is predictable. CWE-307
mproper Restriction of Excessive Authentication Attempts
CVE-2021-29023 2024-11-21 15:00 2021-05-18 Show GitHub Exploit DB Packet Storm
194243 4.3 MEDIUM
Network
liferay dxp
liferay_portal
The Data Engine module in Liferay Portal 7.3.0 through 7.3.5, and Liferay DXP 7.3 before fix pack 1 does not check permissions in DataDefinitionResourceImpl.getSiteDataDefinitionByContentTypeByDataDe… CWE-276
Incorrect Default Permissions 
CVE-2021-29052 2024-11-21 15:00 2021-05-17 Show GitHub Exploit DB Packet Storm
194244 6.1 MEDIUM
Network
liferay dxp
liferay_portal
Cross-site scripting (XSS) vulnerability in the Asset module's Asset Publisher app in Liferay Portal 7.2.1 through 7.3.5, and Liferay DXP 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before… CWE-79
Cross-site Scripting
CVE-2021-29051 2024-11-21 15:00 2021-05-17 Show GitHub Exploit DB Packet Storm
194245 6.1 MEDIUM
Network
liferay dxp
liferay_portal
Cross-site scripting (XSS) vulnerability in the Layout module's page administration page in Liferay Portal 7.3.4, 7.3.5 and Liferay DXP 7.2 before fix pack 11 and 7.3 before fix pack 1 allows remote … CWE-79
Cross-site Scripting
CVE-2021-29048 2024-11-21 15:00 2021-05-17 Show GitHub Exploit DB Packet Storm
194246 8.8 HIGH
Network
liferay dxp
liferay_portal
Multiple SQL injection vulnerabilities in Liferay Portal 7.3.5 and Liferay DXP 7.3 before fix pack 1 allow remote authenticated users to execute arbitrary SQL commands via the classPKField parameter … CWE-89
SQL Injection
CVE-2021-29053 2024-11-21 15:00 2021-05-17 Show GitHub Exploit DB Packet Storm
194247 6.1 MEDIUM
Network
liferay dxp
liferay_portal
Cross-site scripting (XSS) vulnerability in the Asset module's category selector input field in Liferay Portal 7.3.5 and Liferay DXP 7.3 before fix pack 1, allows remote attackers to inject arbitrary… CWE-79
Cross-site Scripting
CVE-2021-29046 2024-11-21 15:00 2021-05-17 Show GitHub Exploit DB Packet Storm
194248 6.1 MEDIUM
Network
liferay dxp
liferay_portal
Cross-site scripting (XSS) vulnerability in the Redirect module's redirection administration page in Liferay Portal 7.3.2 through 7.3.5, and Liferay DXP 7.3 before fix pack 1 allows remote attackers … CWE-79
Cross-site Scripting
CVE-2021-29045 2024-11-21 15:00 2021-05-17 Show GitHub Exploit DB Packet Storm
194249 6.1 MEDIUM
Network
liferay dxp
liferay_portal
Cross-site scripting (XSS) vulnerability in the Site module's membership request administration pages in Liferay Portal 7.0.0 through 7.3.5, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pac… CWE-79
Cross-site Scripting
CVE-2021-29044 2024-11-21 15:00 2021-05-17 Show GitHub Exploit DB Packet Storm
194250 5.9 MEDIUM
Network
liferay dxp
liferay_portal
The Portal Store module in Liferay Portal 7.0.0 through 7.3.5, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pack 1 does not obfuscate the … CWE-522
 Insufficiently Protected Credentials
CVE-2021-29043 2024-11-21 15:00 2021-05-17 Show GitHub Exploit DB Packet Storm