Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 29, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
225661 6.2 警告 Linux - 32-bit Xen paravirt_ops プラットフォーム上で稼働する Linux Kernel における権限を取得される脆弱性 CWE-189
数値処理の問題
CVE-2013-0228 2013-06-12 16:41 2013-02-17 Show GitHub Exploit DB Packet Storm
225662 6 警告 OpenStack
Canonical
- 複数の OpenStack 製品における VM へのアクセス権を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-0335 2013-06-12 16:39 2013-02-16 Show GitHub Exploit DB Packet Storm
225663 6.8 警告 QNAP Systems - QNAP VioStor NVR のファームウェア上で稼働する cgi-bin/create_user.cgi におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2013-0144 2013-06-12 15:11 2013-06-5 Show GitHub Exploit DB Packet Storm
225664 6.5 警告 QNAP Systems - QNAP VioStor NVR のファームウェア上で稼働する cgi-bin/pingping.cgi および QNAP 製 NAS 製品の Surveillance Station Pro における任意のコマンドを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2013-0143 2013-06-12 15:10 2013-06-5 Show GitHub Exploit DB Packet Storm
225665 5 警告 QNAP Systems - QNAP VioStor NVR のファームウェアおよび QNAP 製 NAS 製品の Surveillance Station Pro における Web サーバにログインされる脆弱性 CWE-255
証明書・パスワード管理
CVE-2013-0142 2013-06-12 15:10 2013-06-5 Show GitHub Exploit DB Packet Storm
225666 9.3 危険 Mozilla Foundation - 複数の Mozilla 製品の Web コンソールにおけるクローム特権で任意の JavaScript コードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2012-3980 2013-06-11 18:07 2012-08-28 Show GitHub Exploit DB Packet Storm
225667 6.8 警告 Mozilla Foundation - 複数の Mozilla 製品の nsLocation::CheckURL 関数におけるコンテンツのロードの制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-3978 2013-06-11 18:04 2012-08-28 Show GitHub Exploit DB Packet Storm
225668 5.8 警告 Mozilla Foundation - 複数の Mozilla 製品におけるアドレスバー内の X.509 証明書情報を偽造される脆弱性 CWE-DesignError
CVE-2012-3976 2013-06-11 18:00 2012-08-28 Show GitHub Exploit DB Packet Storm
225669 6.9 警告 Mozilla Foundation - Windows 上で稼働する複数の Mozilla 製品のインストーラにおける権限を取得される脆弱性 CWE-399
リソース管理の問題
CVE-2012-3974 2013-06-11 17:58 2012-08-28 Show GitHub Exploit DB Packet Storm
225670 5 警告 Mozilla Foundation - 複数の Mozilla 製品の XSLT の format-number の機能における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2012-3972 2013-06-11 17:55 2012-08-28 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 29, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
212931 9.8 CRITICAL
Network
duffel paginator There is a vulnerability in Paginator (Elixir/Hex package) which makes it susceptible to Remote Code Execution (RCE) attacks via input parameters to the paginate() function. This will potentially aff… - CVE-2020-15150 2024-11-21 14:04 2020-09-2 Show GitHub Exploit DB Packet Storm
212932 5.4 MEDIUM
Network
elementor website_builder An issue was discovered in the Elementor plugin through 2.9.13 for WordPress. An authenticated attacker can achieve stored XSS via the Name Your Template field. CWE-79
Cross-site Scripting
CVE-2020-15020 2024-11-21 14:04 2020-08-31 Show GitHub Exploit DB Packet Storm
212933 7.6 HIGH
Network
basercms basercms baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) and Remote Code Execution (RCE). This may be executed by logging in as a system administrator and uploading an executable script f… - CVE-2020-15159 2024-11-21 14:04 2020-08-29 Show GitHub Exploit DB Packet Storm
212934 7.3 HIGH
Network
basercms basercms baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) via arbitrary script execution. Admin access is required to exploit this vulnerability. The affected components is toolbar.php. Th… - CVE-2020-15155 2024-11-21 14:04 2020-08-29 Show GitHub Exploit DB Packet Storm
212935 7.3 HIGH
Network
basercms basercms baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) via arbitrary script execution. Admin access is required to exploit this vulnerability. The affected components are: content_field… CWE-79
Cross-site Scripting
CVE-2020-15154 2024-11-21 14:04 2020-08-29 Show GitHub Exploit DB Packet Storm
212936 9.1 CRITICAL
Network
chameleon_mini_live_debugger_project chameleon_mini_live_debugger Version 1.1.6-free of Chameleon Mini Live Debugger on Google Play Store may have had it's sources or permissions tampered by a malicious actor. The official maintainer of the package is recommending … - CVE-2020-15165 2024-11-21 14:04 2020-08-29 Show GitHub Exploit DB Packet Storm
212937 10.0 CRITICAL
Network
scratch-wiki scratch_login in Scratch Login (MediaWiki extension) before version 1.1, any account can be logged into by using the same username with leading, trailing, or repeated underscore(s), since those are treated as whit… CWE-74
Injection
CVE-2020-15164 2024-11-21 14:04 2020-08-29 Show GitHub Exploit DB Packet Storm
212938 8.1 HIGH
Network
nodebb blog_comments In nodebb-plugin-blog-comments before version 0.7.0, a logged in user is vulnerable to an XSS attack which could allow a third party to post on their behalf on the forum. This is due to lack of CSRF … - CVE-2020-15156 2024-11-21 14:04 2020-08-27 Show GitHub Exploit DB Packet Storm
212939 9.8 CRITICAL
Network
mz-automation libiec61850 In libIEC61850 before version 1.4.3, when a message with COTP message length field with value < 4 is received an integer underflow will happen leading to heap buffer overflow. This can cause an appli… CWE-191
 Integer Underflow (Wrap or Wraparound)
CVE-2020-15158 2024-11-21 14:04 2020-08-27 Show GitHub Exploit DB Packet Storm
212940 8.5 HIGH
Network
cogboard red_discord_bot Red Discord Bot before versions 3.3.12 and 3.4 has a Remote Code Execution vulnerability in the Streams module. This exploit allows Discord users with specifically crafted "going live" messages to in… CWE-74
Injection
CVE-2020-15147 2024-11-21 14:04 2020-08-22 Show GitHub Exploit DB Packet Storm