Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 31, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
225801 2.6 注意 アドビシステムズ - Adobe Reader X における Sandbox 機能が回避される脆弱性 CWE-Other
その他
- 2013-05-31 12:04 2013-05-31 Show GitHub Exploit DB Packet Storm
225802 2.6 注意 アップル - Safari における情報漏えいの脆弱性 CWE-Other
その他
- 2013-05-31 12:03 2013-05-31 Show GitHub Exploit DB Packet Storm
225803 7.2 危険 Google
LG Electronics
- LG Optimus G E973 上の Android 用 LG Hidden Menu における任意のコマンドを実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-3666 2013-05-30 16:39 2013-05-23 Show GitHub Exploit DB Packet Storm
225804 6.8 警告 IBM - UNIX 用の IBM Sterling Connect:Direct におけるファイルシステムの読み取り権限および書き込み権限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-2989 2013-05-30 16:37 2013-05-14 Show GitHub Exploit DB Packet Storm
225805 4.3 警告 IBM - IBM Tivoli Monitoring の Tivoli Enterprise Portal browser クライアントにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-0576 2013-05-30 16:36 2013-05-17 Show GitHub Exploit DB Packet Storm
225806 4.3 警告 IBM - IBM WebSphere DataPower SOA アプライアンスにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-0499 2013-05-30 16:34 2013-05-17 Show GitHub Exploit DB Packet Storm
225807 7.2 危険 レッドハット - Red Hat livecd-tools における権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-2069 2013-05-30 14:07 2013-05-23 Show GitHub Exploit DB Packet Storm
225808 4.9 警告 マイクロソフト - Microsoft Windows の win32k.sys の EPATHOBJ::bFlatten 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-22
パス・トラバーサル
CVE-2013-3661 2013-05-29 16:54 2013-05-17 Show GitHub Exploit DB Packet Storm
225809 5 警告 IBM - IBM InfoSphere Optim Data Growth for Oracle E-Business Suite における重要な情報を取得される脆弱性 CWE-255
証明書・パスワード管理
CVE-2013-2959 2013-05-29 16:37 2013-05-13 Show GitHub Exploit DB Packet Storm
225810 3.5 注意 IBM - IBM InfoSphere Optim Data Growth for Oracle E-Business Suite におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-2957 2013-05-29 16:37 2013-05-13 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 31, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
210471 9.8 CRITICAL
Network
cmswing cmswing An issue was found in CMSWing project version 1.3.8, Because the rechargeAction function does not check the balance parameter, malicious parameters can execute arbitrary SQL commands. CWE-89
SQL Injection
CVE-2020-20296 2024-11-21 14:12 2021-02-2 Show GitHub Exploit DB Packet Storm
210472 9.8 CRITICAL
Network
cmswing cmswing An issue was found in CMSWing project version 1.3.8. Because the updateAction function does not check the detail parameter, malicious parameters can execute arbitrary SQL commands. CWE-89
SQL Injection
CVE-2020-20295 2024-11-21 14:12 2021-02-2 Show GitHub Exploit DB Packet Storm
210473 9.8 CRITICAL
Network
cmswing cmswing An issue was found in CMSWing project version 1.3.8. Because the log function does not check the log parameter, malicious parameters can execute arbitrary commands. CWE-89
SQL Injection
CVE-2020-20294 2024-11-21 14:12 2021-02-2 Show GitHub Exploit DB Packet Storm
210474 7.5 HIGH
Network
yccms yccms Directory traversal vulnerability in the yccms 3.3 project. The delete, deletesite, and deleteAll functions' improper judgment of the request parameters, triggers a directory traversal vulnerability. CWE-22
Path Traversal
CVE-2020-20290 2024-11-21 14:12 2021-02-2 Show GitHub Exploit DB Packet Storm
210475 9.8 CRITICAL
Network
yccms yccms Sql injection vulnerability in the yccms 3.3 project. The no_top function's improper judgment of the request parameters, triggers a sql injection vulnerability. CWE-89
SQL Injection
CVE-2020-20289 2024-11-21 14:12 2021-02-2 Show GitHub Exploit DB Packet Storm
210476 4.8 MEDIUM
Network
rockoa rockoa RockOA V1.9.8 is affected by a cross-site scripting (XSS) vulnerability which allows remote attackers to send malicious code to the administrator and execute JavaScript code, because webmain/flow/inp… CWE-79
Cross-site Scripting
CVE-2020-21147 2024-11-21 14:12 2021-01-27 Show GitHub Exploit DB Packet Storm
210477 6.1 MEDIUM
Network
feehi feehi_cms Feehi CMS 2.0.8 is affected by a cross-site scripting (XSS) vulnerability. When the user name is inserted as JavaScript code, browsing the post will trigger the XSS. CWE-79
Cross-site Scripting
CVE-2020-21146 2024-11-21 14:12 2021-01-27 Show GitHub Exploit DB Packet Storm
210478 5.9 MEDIUM
Network
st
ietf
stm32cubemx
stm32cubeide
stm32cubeprogrammer
stm32cubemonitor
stm32cubel1
stm32cubel0
stm32cubel4
stm32cubel5
stm32cubef0
stm32cubef1
stm32cubef2
stm32cubef3
stm32…
Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in STM32 cryptographic firmware library software expansion for STM32Cube (UM1924). The vulnerability can allow one to use Bleichenbacher's orac… CWE-327
 Use of a Broken or Risky Cryptographic Algorithm
CVE-2020-20949 2024-11-21 14:12 2021-01-21 Show GitHub Exploit DB Packet Storm
210479 5.9 MEDIUM
Network
ietf
microchip
public_key_cryptography_standards_\#1
microchip_libraries_for_applications
Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in Microchip Libraries for Applications 2018-11-26 All up to 2018-11-26. The vulnerability can allow one to use Bleichenbacher's oracle attack … CWE-327
 Use of a Broken or Risky Cryptographic Algorithm
CVE-2020-20950 2024-11-21 14:12 2021-01-19 Show GitHub Exploit DB Packet Storm
210480 6.5 MEDIUM
Network
xiph.org
stepmania
libvorbis
stepmania
lib/codebook.c in libvorbis before 1.3.6, as used in StepMania 5.0.12 and other products, has insufficient array bounds checking via a crafted OGG file. NOTE: this may overlap CVE-2018-5146. CWE-129
 Improper Validation of Array Index
CVE-2020-20412 2024-11-21 14:12 2020-12-26 Show GitHub Exploit DB Packet Storm