Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 25, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
225021 5 警告 IBM - IBM Sterling B2B Integrator および Sterling File Gateway における Cookie をキャプチャされる脆弱性 CWE-310
暗号の問題
CVE-2012-5936 2013-07-4 14:49 2013-03-11 Show GitHub Exploit DB Packet Storm
225022 6.5 警告 IBM - IBM Sterling B2B Integrator および Sterling File Gateway における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2012-5766 2013-07-4 14:47 2012-06-11 Show GitHub Exploit DB Packet Storm
225023 4.6 警告 IBM - Windows 以外のプラットフォームで稼働する IBM WebSphere MQ におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2013-3028 2013-07-4 14:43 2013-06-26 Show GitHub Exploit DB Packet Storm
225024 10 危険 ヒューレット・パッカード - HP LeftHand Virtual SAN Appliance hydra Software における任意のコードを実行される脆弱性 CWE-noinfo
情報不足
CVE-2013-2343 2013-07-4 14:36 2013-06-27 Show GitHub Exploit DB Packet Storm
225025 4.3 警告 Messaging - TYPO3 用 UserTask Center、Messaging エクステンションにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-4749 2013-07-3 17:55 2013-01-28 Show GitHub Exploit DB Packet Storm
225026 7.5 危険 Georg Ringer - TYPO3 用 News system エクステンションにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2013-4748 2013-07-3 17:55 2013-01-11 Show GitHub Exploit DB Packet Storm
225027 4.3 警告 Kasper Skarhoj - TYPO3 用 Accessible browse results for indexed search エクステンションにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-4747 2013-07-3 17:54 2013-06-3 Show GitHub Exploit DB Packet Storm
225028 4.3 警告 Kurt Gusbeth - TYPO3 用 My quiz and poll エクステンションにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-4746 2013-07-3 17:53 2013-02-19 Show GitHub Exploit DB Packet Storm
225029 4.3 警告 Kurt Gusbeth - TYPO3 用 myquizpoll エクステンションにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2013-4745 2013-07-3 17:52 2008-06-7 Show GitHub Exploit DB Packet Storm
225030 4.3 警告 Sebastian Bergmann - TYPO3 用 PHPUnit エクステンションにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-4744 2013-07-3 17:52 2013-01-11 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 26, 2026, 4:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
211851 5.5 MEDIUM
Local
mi miui The application in the mobile phone can read the SNO information of the device, Xiaomi 10 MIUI < 2020.01.15. NVD-CWE-noinfo
CVE-2020-14103 2024-11-21 14:02 2021-04-9 Show GitHub Exploit DB Packet Storm
211852 8.1 HIGH
Network
mi ax3600_firmware A RACE CONDITION on XQBACKUP causes a decompression path error on Xiaomi router AX3600 with ROM version =1.0.50. CWE-362
Race Condition
CVE-2020-14104 2024-11-21 14:02 2021-04-9 Show GitHub Exploit DB Packet Storm
211853 7.5 HIGH
Network
mi ax1800_firmware
rm1800_firmware
On Xiaomi router AX1800 rom version < 1.0.336 and RM1800 root version < 1.0.26, the encryption scheme for a user's backup files uses hard-coded keys, which can expose sensitive information such as a … CWE-798
 Use of Hard-coded Credentials
CVE-2020-14099 2024-11-21 14:02 2021-04-9 Show GitHub Exploit DB Packet Storm
211854 9.8 CRITICAL
Network
soplanning soplanning SOPlanning before 1.47 has Incorrect Access Control because certain secret key information, and the related authentication algorithm, is public. The key for admin is hardcoded in the installation cod… CWE-798
 Use of Hard-coded Credentials
CVE-2020-13963 2024-11-21 14:02 2021-03-22 Show GitHub Exploit DB Packet Storm
211855 7.5 HIGH
Network
apache ambari In Apache Ambari versions 2.6.2.2 and earlier, malicious users can construct file names for directory traversal and traverse to other directories to download files. CWE-22
Path Traversal
CVE-2020-13924 2024-11-21 14:02 2021-03-17 Show GitHub Exploit DB Packet Storm
211856 6.1 MEDIUM
Network
apache
debian
velocity_tools
debian_linux
The default error page for VelocityView in Apache Velocity Tools prior to 3.1 reflects back the vm file that was entered as part of the URL. An attacker can set an XSS payload file as this vm file in… CWE-79
Cross-site Scripting
CVE-2020-13959 2024-11-21 14:02 2021-03-10 Show GitHub Exploit DB Packet Storm
211857 8.8 HIGH
Network
apache
debian
oracle
velocity_engine
wss4j
debian_linux
retail_order_broker
banking_platform
communications_network_integrity
banking_enterprise_default_management
banking_party_management
utiliti…
An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This appl… NVD-CWE-noinfo
CVE-2020-13936 2024-11-21 14:02 2021-03-10 Show GitHub Exploit DB Packet Storm
211858 7.5 HIGH
Network
apache
oracle
thrift
hive
communications_cloud_native_core_network_slice_selection_function
communications_cloud_native_core_policy
In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. CWE-400
 Uncontrolled Resource Consumption
CVE-2020-13949 2024-11-21 14:02 2021-02-13 Show GitHub Exploit DB Packet Storm
211859 6.1 MEDIUM
Network
apache
oracle
activemq
communications_session_route_manager
communications_session_report_manager
An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the message.jsp page of Apache ActiveMQ versions 5.15.12 through 5.16.0. CWE-79
Cross-site Scripting
CVE-2020-13947 2024-11-21 14:02 2021-02-9 Show GitHub Exploit DB Packet Storm
211860 5.9 MEDIUM
Network
fedoraproject fedora A flaw was found in the default configuration of dnsmasq, as shipped with Fedora versions prior to 31 and in all versions Red Hat Enterprise Linux, where it listens on any interface and accepts queri… NVD-CWE-Other
CVE-2020-14312 2024-11-21 14:02 2021-02-6 Show GitHub Exploit DB Packet Storm