Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 16, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
225061 5.1 警告 Drupal - Drupal の form API における任意のコードを実行するようなアプリケーション固有の影響を誘発される脆弱性 CWE-94
コード・インジェクション
CVE-2013-6385 2013-12-10 15:12 2013-11-20 Show GitHub Exploit DB Packet Storm
225062 6.8 警告 Steven Jones - Drupal 用 Context モジュールの plugins/context_reaction_block.inc 内の _json_decode 関数における任意の PHP コードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2013-4446 2013-12-10 15:12 2013-10-16 Show GitHub Exploit DB Packet Storm
225063 4.9 警告 Steven Jones - Drupal 用 Context モジュールの json レンダリング機能におけるブロックのアクセストークンを推測される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-4445 2013-12-10 15:11 2013-10-16 Show GitHub Exploit DB Packet Storm
225064 4.3 警告 Sven Fuchs - Ruby 用 i18n gem の exceptions.rb におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-4492 2013-12-10 12:38 2013-12-3 Show GitHub Exploit DB Packet Storm
225065 4.3 警告 Ruby on Rails project - Ruby on Rails の actionpack/lib/action_view/helpers/text_helper.rb におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-6416 2013-12-10 12:29 2013-12-3 Show GitHub Exploit DB Packet Storm
225066 7.2 危険 Novell - SUSE horde5 パッケージにおける権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-1090 2013-12-9 18:21 2013-12-4 Show GitHub Exploit DB Packet Storm
225067 4.3 警告 The Jamroom Network - Jamroom 用 Search モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-6804 2013-12-9 18:08 2013-11-13 Show GitHub Exploit DB Packet Storm
225068 4.3 警告 Ganglia - Ganglia Web の header.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-6395 2013-12-9 17:50 2013-11-22 Show GitHub Exploit DB Packet Storm
225069 4.3 警告 Claroline Consortium - Claroline におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-6267 2013-12-9 15:54 2013-11-25 Show GitHub Exploit DB Packet Storm
225070 7.5 危険 Dokeos - Dokeos における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2013-6341 2013-12-9 14:29 2013-11-27 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 16, 2026, 4:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
210921 7.8 HIGH
Local
capasystems capainstaller CapaSystems CapaInstaller before 6.0.101 does not properly assign, modify, or check privileges for an actor who attempts to edit registry values, allowing an attacker to escalate privileges. NVD-CWE-noinfo
CVE-2020-27977 2024-11-21 14:22 2020-11-10 Show GitHub Exploit DB Packet Storm
210922 6.1 MEDIUM
Network
mitel shoretel_firmware The conferencing component on Mitel ShoreTel 19.46.1802.0 devices could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack (via the PATH_INFO to index.php) due… CWE-79
Cross-site Scripting
CVE-2020-28351 2024-11-21 14:22 2020-11-9 Show GitHub Exploit DB Packet Storm
210923 6.5 MEDIUM
Network
chirpstack network_server An inaccurate frame deduplication process in ChirpStack Network Server 3.9.0 allows a malicious gateway to perform uplink Denial of Service via malformed frequency attributes in CollectAndCallOnceCol… CWE-20
 Improper Input Validation 
CVE-2020-28349 2024-11-21 14:22 2020-11-9 Show GitHub Exploit DB Packet Storm
210924 9.8 CRITICAL
Network
tp-link ac1750_firmware tdpServer on TP-Link Archer A7 AC1750 devices before 201029 allows remote attackers to execute arbitrary code via the slave_mac parameter. NOTE: this issue exists because of an incomplete fix for CVE… CWE-78
OS Command 
CVE-2020-28347 2024-11-21 14:22 2020-11-9 Show GitHub Exploit DB Packet Storm
210925 7.5 HIGH
Network
google android An issue was discovered on LG mobile devices with Android OS 10 software. The Wi-Fi subsystem may crash because of the lack of a NULL parameter check. The LG ID is LVE-SMP-200025 (November 2020). CWE-476
 NULL Pointer Dereference
CVE-2020-28345 2024-11-21 14:22 2020-11-8 Show GitHub Exploit DB Packet Storm
210926 7.5 HIGH
Network
google android An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. System services may crash because of the lack of a NULL parameter check. The LG ID is LVE-SMP-200024 (Nove… CWE-476
 NULL Pointer Dereference
CVE-2020-28344 2024-11-21 14:22 2020-11-8 Show GitHub Exploit DB Packet Storm
210927 7.8 HIGH
Local
google android An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (Exynos 980, 9820, and 9830 chipsets) software. The NPU driver allows attackers to execute arbitrary code because of unintend… CWE-787
 Out-of-bounds Write
CVE-2020-28343 2024-11-21 14:22 2020-11-8 Show GitHub Exploit DB Packet Storm
210928 7.8 HIGH
Local
google android An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (China / India) software. The S Secure application allows attackers to bypass authentication for a locked Gallery application… NVD-CWE-Other
CVE-2020-28342 2024-11-21 14:22 2020-11-8 Show GitHub Exploit DB Packet Storm
210929 7.8 HIGH
Local
google android An issue was discovered on Samsung mobile devices with Q(10.0) (Exynos990 chipsets) software. The S3K250AF Secure Element CC EAL 5+ chip allows attackers to execute arbitrary code and obtain sensitiv… CWE-120
Classic Buffer Overflow
CVE-2020-28341 2024-11-21 14:22 2020-11-8 Show GitHub Exploit DB Packet Storm
210930 9.8 CRITICAL
Network
google android An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), Q(10.0), and R(11.0) software. Attackers can bypass Factory Reset Protection (FRP) via Secure Folder. The Samsung ID is SVE-2020… NVD-CWE-noinfo
CVE-2020-28340 2024-11-21 14:22 2020-11-8 Show GitHub Exploit DB Packet Storm