Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 19, 2026, 12:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
224831 10 危険 Zimbra - Zimbra Collaboration Server におけるクリティカルな影響を受ける脆弱性 CWE-noinfo
情報不足
CVE-2013-7217 2013-12-27 11:55 2013-12-12 Show GitHub Exploit DB Packet Storm
224832 5.2 警告 Xen プロジェクト - Xen の XEN_DOMCTL_getmemlist hypercall におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2013-4553 2013-12-27 11:31 2013-11-26 Show GitHub Exploit DB Packet Storm
224833 5 警告 FFmpeg - FFmpeg の libavcodec/h264.c におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2013-4358 2013-12-27 11:26 2013-09-16 Show GitHub Exploit DB Packet Storm
224834 2.6 注意 FFmpeg - FFmpeg の libavformat/utils.c の av_probe_input_buffer 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2012-6618 2013-12-27 11:25 2012-12-5 Show GitHub Exploit DB Packet Storm
224835 4.3 警告 FFmpeg - FFmpeg の ffserver.c の prepare_sdp_description 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-DesignError
CVE-2012-6617 2013-12-27 11:24 2012-12-10 Show GitHub Exploit DB Packet Storm
224836 5 警告 FFmpeg - FFmpeg の libavcodec/movtextdec.c の mov_text_decode_frame 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2012-6616 2013-12-27 11:24 2012-12-31 Show GitHub Exploit DB Packet Storm
224837 4.3 警告 FFmpeg - FFmpeg の libavcodec/ass_split.c の ff_ass_split_override_codes 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2012-6615 2013-12-27 11:23 2012-12-30 Show GitHub Exploit DB Packet Storm
224838 9.3 危険 Rackspace - XenServer 用 Rackspace Openstack Windows Guest Agent の Updater における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2013-6795 2013-12-27 11:14 2013-10-17 Show GitHub Exploit DB Packet Storm
224839 4.3 警告 Drupal - Drupal の Color モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-6388 2013-12-27 11:01 2013-11-20 Show GitHub Exploit DB Packet Storm
224840 2.1 注意 Drupal - Drupal の Image モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-6387 2013-12-27 11:00 2013-11-20 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 19, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
200661 6.1 MEDIUM
Network
nttdocomo wi-fi_station_sh-52a_firmware Cross-site scripting vulnerability in Wi-Fi STATION SH-52A (38JP_1_11G, 38JP_1_11J, 38JP_1_11K, 38JP_1_11L, 38JP_1_26F, 38JP_1_26G, 38JP_1_26J, 38JP_2_03B, and 38JP_2_03C) allows a remote unauthentic… CWE-79
Cross-site Scripting
CVE-2021-20847 2024-11-21 14:47 2021-12-1 Show GitHub Exploit DB Packet Storm
200662 9.8 CRITICAL
Network
alfasado powercms PowerCMS XMLRPC API of PowerCMS 5.19 and earlier, PowerCMS 4.49 and earlier, PowerCMS 3.295 and earlier, and PowerCMS 2 Series (End-of-Life, EOL) allows a remote attacker to execute an arbitrary OS c… CWE-78
OS Command 
CVE-2021-20850 2024-11-21 14:47 2021-11-25 Show GitHub Exploit DB Packet Storm
200663 6.1 MEDIUM
Network
rwtxt_project rwtxt Cross-site scripting vulnerability in rwtxt versions prior to v1.8.6 allows a remote attacker to inject an arbitrary script via unspecified vectors. CWE-79
Cross-site Scripting
CVE-2021-20848 2024-11-21 14:47 2021-11-25 Show GitHub Exploit DB Packet Storm
200664 8.8 HIGH
Network
delitestudio push_notifications_for_wordpress Cross-site request forgery (CSRF) vulnerability in Push Notifications for WordPress (Lite) versions prior to 6.0.1 allows a remote attacker to hijack the authentication of an administrator and conduc… CWE-352
 Origin Validation Error
CVE-2021-20846 2024-11-21 14:47 2021-11-25 Show GitHub Exploit DB Packet Storm
200665 8.8 HIGH
Network
xml-sitemaps unlimited_sitemap_generator Cross-site request forgery (CSRF) vulnerability in Unlimited Sitemap Generator versions prior to v8.2 allows a remote attacker to hijack the authentication of an administrator and conduct arbitrary o… CWE-352
 Origin Validation Error
CVE-2021-20845 2024-11-21 14:47 2021-11-25 Show GitHub Exploit DB Packet Storm
200666 5.7 MEDIUM
Network
yamaha
ntt-west
rtx830_firmware
nvr510_firmware
nvr700w_firmware
rtx1210_firmware
biz_box_rtx830_firmware
biz_box_nvr510_firmware
biz_box_nvr700w_firmware
biz_box_rtx1210_firmware
Improper neutralization of HTTP request headers for scripting syntax vulnerability in the Web GUI of RTX830 Rev.15.02.17 and earlier, NVR510 Rev.15.01.18 and earlier, NVR700W Rev.15.00.19 and earlier… CWE-116
 Improper Encoding or Escaping of Output
CVE-2021-20844 2024-11-21 14:47 2021-11-25 Show GitHub Exploit DB Packet Storm
200667 5.4 MEDIUM
Network
yamaha
ntt-west
rtx830_firmware
nvr510_firmware
nvr700w_firmware
rtx1210_firmware
biz_box_rtx830_firmware
biz_box_nvr510_firmware
biz_box_nvr700w_firmware
biz_box_rtx1210_firmware
Cross-site script inclusion vulnerability in the Web GUI of RTX830 Rev.15.02.17 and earlier, NVR510 Rev.15.01.18 and earlier, NVR700W Rev.15.00.19 and earlier, and RTX1210 Rev.14.01.38 and earlier al… CWE-829
 Inclusion of Functionality from Untrusted Control Sphere
CVE-2021-20843 2024-11-21 14:47 2021-11-25 Show GitHub Exploit DB Packet Storm
200668 6.5 MEDIUM
Network
ec-cube ec-cube Cross-site request forgery (CSRF) vulnerability in EC-CUBE 2 series 2.11.0 to 2.17.1 allows a remote attacker to hijack the authentication of Administrator and delete Administrator via a specially cr… CWE-352
 Origin Validation Error
CVE-2021-20842 2024-11-21 14:47 2021-11-25 Show GitHub Exploit DB Packet Storm
200669 6.5 MEDIUM
Network
ec-cube ec-cube Improper access control in Management screen of EC-CUBE 2 series 2.11.2 to 2.17.1 allows a remote authenticated attacker to bypass access restriction and to alter System settings via unspecified vect… NVD-CWE-Other
CVE-2021-20841 2024-11-21 14:47 2021-11-25 Show GitHub Exploit DB Packet Storm
200670 6.1 MEDIUM
Network
saasproject booking_package Cross-site scripting vulnerability in Booking Package - Appointment Booking Calendar System versions prior to 1.5.11 allows a remote attacker to inject an arbitrary script via unspecified vectors. CWE-79
Cross-site Scripting
CVE-2021-20840 2024-11-21 14:47 2021-11-25 Show GitHub Exploit DB Packet Storm