Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 2, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
225461 4.3 警告 Alejandro Garza - Drupal 用 Apache Solr Autocomplete モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-6573 2013-06-27 16:32 2012-08-29 Show GitHub Exploit DB Packet Storm
225462 7.2 危険 Mozilla Foundation - Windows 上で稼働する Mozilla Firefox の Mozilla Maintenance Service における権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-1700 2013-06-27 16:20 2013-06-25 Show GitHub Exploit DB Packet Storm
225463 2.1 注意 Linux - Linux Kernel におけるキーストロークのタイミングに関する重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2013-0160 2013-06-27 16:20 2013-02-18 Show GitHub Exploit DB Packet Storm
225464 6.5 警告 フォーティネット - Fortinet FortiGate デバイス上で稼働する FortiOS における任意のユーザのレコードを読まれる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-4604 2013-06-27 13:35 2013-06-13 Show GitHub Exploit DB Packet Storm
225465 9.3 危険 ジャストシステム - 一太郎シリーズにおいて任意のコードが実行される脆弱性 CWE-noinfo
情報不足
CVE-2013-3644 2013-06-26 14:48 2013-06-18 Show GitHub Exploit DB Packet Storm
225466 10 危険 Korenix Technology - Korenix Jetport およびその他の製品で使用されるファームウェアにおける管理アクセス権を取得される脆弱性 CWE-255
証明書・パスワード管理
CVE-2012-4577 2013-06-26 14:38 2012-08-21 Show GitHub Exploit DB Packet Storm
225467 9.3 危険 Sielco Sistemi - Sielco Sistemi Winlog の RunTime.exe におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2012-3815 2013-06-26 14:36 2012-06-27 Show GitHub Exploit DB Packet Storm
225468 10 危険 デジタル - Pro-face WinGP PC ランタイムおよび Pro-Server EX におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2012-3797 2013-06-26 14:33 2012-06-11 Show GitHub Exploit DB Packet Storm
225469 5 警告 デジタル - Pro-face WinGP PC ランタイムおよび Pro-Server EX における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2012-3796 2013-06-26 14:32 2012-06-11 Show GitHub Exploit DB Packet Storm
225470 5 警告 デジタル - Pro-face WinGP PC ランタイムおよび Pro-Server EX におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2012-3795 2013-06-26 14:30 2012-06-11 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 2, 2026, 4:18 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
212901 7.8 HIGH
Local
nakivo backup_\&_replication_director Insecure permissions in Nakivo Backup & Replication Director version 9.4.0.r43656 on Linux allow local users to access the Nakivo Director web interface and gain root privileges. This occurs because … CWE-276
Incorrect Default Permissions 
CVE-2020-15850 2024-11-21 14:06 2020-09-25 Show GitHub Exploit DB Packet Storm
212902 6.1 MEDIUM
Network
joplin_project joplin An XSS issue in Joplin desktop 1.0.190 to 1.0.245 allows arbitrary code execution via a malicious HTML embed tag. CWE-79
Cross-site Scripting
CVE-2020-15930 2024-11-21 14:06 2020-09-25 Show GitHub Exploit DB Packet Storm
212903 5.3 MEDIUM
Network
liferay dxp
liferay_portal
In Liferay Portal before 7.3.1, Liferay Portal 6.2 EE, and Liferay DXP 7.2, DXP 7.1 and DXP 7.0, the property 'portlet.resource.id.banned.paths.regexp' can be bypassed with doubled encoded URLs. NVD-CWE-noinfo
CVE-2020-15840 2024-11-21 14:06 2020-09-25 Show GitHub Exploit DB Packet Storm
212904 7.2 HIGH
Network
telmat accesslog_firmware
educ\@box_firmware
git\@box_firmware
The ping page of the administration panel in Telmat AccessLog <= 6.0 (TAL_20180415) allows an attacker to get root shell access via authenticated code injection over the network. CWE-78
OS Command 
CVE-2020-16148 2024-11-21 14:06 2020-09-24 Show GitHub Exploit DB Packet Storm
212905 9.8 CRITICAL
Network
telmat accesslog_firmware
educ\@box_firmware
git\@box_firmware
The login page in Telmat AccessLog <= 6.0 (TAL_20180415) allows an attacker to get root shell access via Unauthenticated code injection over the network. CWE-78
OS Command 
CVE-2020-16147 2024-11-21 14:06 2020-09-24 Show GitHub Exploit DB Packet Storm
212906 6.5 MEDIUM
Network
liferay liferay_portal
digital_experience_platform
Liferay Portal before 7.3.3, and Liferay DXP 7.1 before fix pack 18 and 7.2 before fix pack 6, does not restrict the size of a multipart/form-data POST action, which allows remote authenticated users… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2020-15839 2024-11-21 14:06 2020-09-23 Show GitHub Exploit DB Packet Storm
212907 7.8 HIGH
Local
advantech webaccess WebAccess Node (All versions prior to 9.0.1) has incorrect permissions set for resources used by specific services, which may allow code execution with system privileges. - CVE-2020-16202 2024-11-21 14:06 2020-09-23 Show GitHub Exploit DB Packet Storm
212908 4.3 MEDIUM
Network
google
debian
opensuse
fedoraproject
chrome
debian_linux
leap
backports_sle
fedora
Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive informa… NVD-CWE-noinfo
CVE-2020-15966 2024-11-21 14:06 2020-09-22 Show GitHub Exploit DB Packet Storm
212909 8.8 HIGH
Network
google
debian
opensuse
fedoraproject
chrome
debian_linux
leap
fedora
backports_sle
Type confusion in V8 in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. CWE-843
Type Confusion
CVE-2020-15965 2024-11-21 14:06 2020-09-22 Show GitHub Exploit DB Packet Storm
212910 8.8 HIGH
Network
google
opensuse
fedoraproject
debian
chrome
leap
backports_sle
fedora
debian_linux
Insufficient data validation in media in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. CWE-20
CWE-787
CWE-476
 Improper Input Validation 
 Out-of-bounds Write
 NULL Pointer Dereference
CVE-2020-15964 2024-11-21 14:06 2020-09-22 Show GitHub Exploit DB Packet Storm