Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 20, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
225301 7.1 危険 Puppet
Canonical
- Puppet における任意のコードを実行される脆弱性 CWE-noinfo
情報不足
CVE-2013-1653 2013-04-23 17:14 2013-03-12 Show GitHub Exploit DB Packet Storm
225302 7.8 危険 シスコシステムズ - Cisco IOS の VRF-aware NAT 機能におけるサービス運用妨害 (メモリ消費) の脆弱性 CWE-362
競合状態
CVE-2013-1142 2013-04-23 17:13 2013-03-27 Show GitHub Exploit DB Packet Storm
225303 6.4 警告 Ruby on Rails project - Ruby on Rails の Active Record コンポーネントにおけるデータ型インジェクション攻撃を実行される脆弱性 CWE-20
不適切な入力確認
CVE-2013-3221 2013-04-23 17:12 2013-04-22 Show GitHub Exploit DB Packet Storm
225304 4.9 警告 Linux - Linux Kernel の net/vmw_vsock/af_vsock.c における重要な情報を取得される脆弱性 CWE-200
CWE-DesignError
CVE-2013-3237 2013-04-23 16:32 2013-04-7 Show GitHub Exploit DB Packet Storm
225305 4.9 警告 Linux - Linux Kernel の net/vmw_vsock/vmci_transport.c における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2013-3236 2013-04-23 16:32 2013-04-7 Show GitHub Exploit DB Packet Storm
225306 10 危険 日立 - Hitachi IT Operations Director におけるバッファオーバーフローの脆弱性 CWE-noinfo
情報不足
- 2013-04-23 15:12 2013-04-19 Show GitHub Exploit DB Packet Storm
225307 10 危険 Opera Software ASA - Opera における脆弱性 CWE-noinfo
情報不足
CVE-2013-3211 2013-04-23 15:08 2013-04-4 Show GitHub Exploit DB Packet Storm
225308 5 警告 Opera Software ASA - Opera における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2013-3210 2013-04-23 15:07 2013-04-4 Show GitHub Exploit DB Packet Storm
225309 4.9 警告 Puppet
Canonical
- Puppet における任意のカタログを読まれる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-1652 2013-04-23 13:54 2013-03-12 Show GitHub Exploit DB Packet Storm
225310 6.8 警告 Lester Chan - WordPress 用 WP-DownloadManager プラグインにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2013-2697 2013-04-23 12:23 2013-04-5 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 20, 2026, 4:14 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
211821 5.5 MEDIUM
Local
gitlab gitlab A vulnerability in the internal Kubernetes agent api in GitLab CE/EE version 13.3 and above allows unauthorized access to private projects. Affected versions are: >=13.4, <13.4.5,>=13.3, <13.3.9,>=13… NVD-CWE-noinfo
CVE-2020-13358 2024-11-21 14:01 2020-11-17 Show GitHub Exploit DB Packet Storm
211822 4.3 MEDIUM
Network
gitlab gitlab A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 12.6. The container registry name check could cause exponential number of backtracks for certain user supplied value… CWE-400
 Uncontrolled Resource Consumption
CVE-2020-13354 2024-11-21 14:01 2020-11-17 Show GitHub Exploit DB Packet Storm
211823 3.2 LOW
Local
gitlab gitaly When importing repos via URL, one time use git credentials were persisted beyond the expected time window in Gitaly 1.79.0 or above. CWE-613
 Insufficient Session Expiration
CVE-2020-13353 2024-11-21 14:01 2020-11-17 Show GitHub Exploit DB Packet Storm
211824 5.3 MEDIUM
Network
gitlab gitlab Private group info is leaked leaked in GitLab CE/EE version 10.2 and above, when the project is moved from private to public group. Affected versions are: >=10.2, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.… NVD-CWE-noinfo
CVE-2020-13352 2024-11-21 14:01 2020-11-17 Show GitHub Exploit DB Packet Storm
211825 5.4 MEDIUM
Network
ivanti endpoint_manager Ivanti Endpoint Manager through 2020.1.1 allows XSS via /LDMS/frm_splitfrm.aspx, /LDMS/licensecheck.aspx, /LDMS/frm_splitcollapse.aspx, /LDMS/alert_log.aspx, /LDMS/ServerList.aspx, /LDMS/frm_coremain… CWE-79
Cross-site Scripting
CVE-2020-13773 2024-11-21 14:01 2020-11-17 Show GitHub Exploit DB Packet Storm
211826 5.3 MEDIUM
Network
ivanti endpoint_manager In /ldclient/ldprov.cgi in Ivanti Endpoint Manager through 2020.1.1, an attacker is able to disclose information about the server operating system, local pathnames, and environment variables with no … NVD-CWE-noinfo
CVE-2020-13772 2024-11-21 14:01 2020-11-17 Show GitHub Exploit DB Packet Storm
211827 8.8 HIGH
Network
ivanti endpoint_manager LDMS/alert_log.aspx in Ivanti Endpoint Manager through 2020.1 allows SQL Injection via a /remotecontrolauth/api/device request. CWE-89
SQL Injection
CVE-2020-13769 2024-11-21 14:01 2020-11-17 Show GitHub Exploit DB Packet Storm
211828 9.8 CRITICAL
Network
rconfig rconfig lib/crud/userprocess.php in rConfig 3.9.x before 3.9.7 has an authentication bypass, leading to administrator account creation. This issue has been fixed in 3.9.7. CWE-269
 Improper Privilege Management
CVE-2020-13638 2024-11-21 14:01 2020-11-14 Show GitHub Exploit DB Packet Storm
211829 9.9 CRITICAL
Network
ivanti endpoint_manager An unrestricted file-upload issue in EditLaunchPadDialog.aspx in Ivanti Endpoint Manager 2019.1 and 2020.1 allows an authenticated attacker to gain remote code execution by uploading a malicious aspx… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2020-13774 2024-11-21 14:01 2020-11-13 Show GitHub Exploit DB Packet Storm
211830 7.8 HIGH
Local
ivanti endpoint_manager Various components in Ivanti Endpoint Manager through 2020.1.1 rely on Windows search order when loading a (nonexistent) library file, allowing (under certain conditions) one to gain code execution (… CWE-427
 Uncontrolled Search Path Element
CVE-2020-13771 2024-11-21 14:01 2020-11-13 Show GitHub Exploit DB Packet Storm