Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 16, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228571 2.1 注意 Devsaran - Drupal 用 Business Theme におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-1783 2013-04-1 14:54 2013-02-27 Show GitHub Exploit DB Packet Storm
228572 2.1 注意 Devsaran - Drupal 用 Responsive Blog Theme におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-1782 2013-04-1 14:53 2013-02-27 Show GitHub Exploit DB Packet Storm
228573 2.1 注意 Devsaran - Drupal 用 Professional Theme におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-1781 2013-04-1 14:52 2013-02-27 Show GitHub Exploit DB Packet Storm
228574 2.1 注意 Devsaran - Drupal 用 Best Responsive テーマにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-1780 2013-04-1 14:51 2013-02-27 Show GitHub Exploit DB Packet Storm
228575 2.1 注意 Devsaran - Drupal 用 Fresh Theme におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-1779 2013-04-1 14:46 2013-02-27 Show GitHub Exploit DB Packet Storm
228576 2.1 注意 Devsaran - Drupal 用 Creative Theme におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-1778 2013-04-1 14:42 2013-02-27 Show GitHub Exploit DB Packet Storm
228577 4.3 警告 Varnish Http Accelerator Integration Project - Drupal 用 Varnish モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-0325 2013-04-1 14:41 2013-02-20 Show GitHub Exploit DB Packet Storm
228578 2.1 注意 Tomasbarej - Drupal 用 Menu Reference モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-0324 2013-04-1 14:40 2013-02-20 Show GitHub Exploit DB Packet Storm
228579 4.3 警告 Kristof De Jaeger - Drupal 用 Display Suite モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-0323 2013-04-1 14:39 2013-02-20 Show GitHub Exploit DB Packet Storm
228580 4.3 警告 Ubercart - Drupal 用 Ubercart モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-0322 2013-04-1 14:38 2013-02-20 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 17, 2026, 4:19 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
194081 5.4 MEDIUM
Network
remoteclinic remote_clinic Cross Site Scripting (XSS) in Remote Clinic v2.0 via the Full Name field on register-patient.php. CWE-79
Cross-site Scripting
CVE-2021-30030 2024-11-21 15:03 2021-04-13 Show GitHub Exploit DB Packet Storm
194082 6.1 MEDIUM
Network
wikimedia parsoid An issue was discovered in Wikimedia Parsoid before 0.11.1 and 0.12.x before 0.12.2. An attacker can send crafted wikitext that Utils/WTUtils.php will transform by using a <meta> tag, bypassing sanit… CWE-79
Cross-site Scripting
CVE-2021-30458 2024-11-21 15:03 2021-04-9 Show GitHub Exploit DB Packet Storm
194083 4.3 MEDIUM
Network
mediawiki
debian
fedoraproject
mediawiki
debian_linux
fedora
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Users can bypass intended restrictions on deleting pages in certain "fast double move" situations. MovePag… NVD-CWE-noinfo
CVE-2021-30159 2024-11-21 15:03 2021-04-9 Show GitHub Exploit DB Packet Storm
194084 4.3 MEDIUM
Network
mediawiki
fedoraproject
mediawiki
fedora
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Special:Contributions can leak that a "hidden" user exists. CWE-200
Information Exposure
CVE-2021-30156 2024-11-21 15:03 2021-04-9 Show GitHub Exploit DB Packet Storm
194085 4.3 MEDIUM
Network
mediawiki
debian
fedoraproject
mediawiki
debian_linux
fedora
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. ContentModelChange does not check if a user has correct permissions to create and set the content model of… CWE-862
 Missing Authorization
CVE-2021-30155 2024-11-21 15:03 2021-04-9 Show GitHub Exploit DB Packet Storm
194086 4.3 MEDIUM
Network
mediawiki
debian
fedoraproject
mediawiki
debian_linux
fedora
An issue was discovered in MediaWiki before 1.31.13 and 1.32.x through 1.35.x before 1.35.2. When using the MediaWiki API to "protect" a page, a user is currently able to protect to a higher level th… CWE-269
 Improper Privilege Management
CVE-2021-30152 2024-11-21 15:03 2021-04-9 Show GitHub Exploit DB Packet Storm
194087 7.8 HIGH
Local
vestacp control_panel VestaCP through 0.9.8-24 allows attackers to gain privileges by creating symlinks to files for which they lack permissions. After reading the RKEY value from user.conf under the /usr/local/vesta/data… CWE-59
Link Following
CVE-2021-30463 2024-11-21 15:03 2021-04-8 Show GitHub Exploit DB Packet Storm
194088 7.2 HIGH
Network
vestacp vesta_control_panel VestaCP through 0.9.8-24 allows the admin user to escalate privileges to root because the Sudo configuration does not require a password to run /usr/local/vesta/bin scripts. CWE-306
Missing Authentication for Critical Function
CVE-2021-30462 2024-11-21 15:03 2021-04-8 Show GitHub Exploit DB Packet Storm
194089 6.5 MEDIUM
Network
web-school enterprise_resource_planning Web-School ERP V 5.0 contains a cross-site request forgery (CSRF) vulnerability that allows a remote attacker to create a voucher payment request through module/accounting/voucher/create. The applica… CWE-352
 Origin Validation Error
CVE-2021-30114 2024-11-21 15:03 2021-04-8 Show GitHub Exploit DB Packet Storm
194090 6.1 MEDIUM
Network
web-school enterprise_resource_planning A blind XSS vulnerability exists in Web-School ERP V 5.0 via (Add Events) in event name and description fields. An attacker can inject a JavaScript code that will be stored in the page. If any visito… CWE-79
Cross-site Scripting
CVE-2021-30113 2024-11-21 15:03 2021-04-8 Show GitHub Exploit DB Packet Storm