Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 26, 2026, noon

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
225931 5 警告 Puppet - Puppet Labs の Puppet Enterprise におけるコンソールアクセスを取得される脆弱性 CWE-310
暗号の問題
CVE-2013-2716 2013-04-12 11:03 2013-03-28 Show GitHub Exploit DB Packet Storm
225932 7.5 危険 Digineo - Ruby 用 Thumbshooter gem の lib/thumbshooter.rb における任意のコマンドを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2013-1898 2013-04-11 19:42 2013-03-25 Show GitHub Exploit DB Packet Storm
225933 7.5 危険 Dan Kubb - Ruby 用 extlib gem におけるオブジェクトインジェクション攻撃を実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-1802 2013-04-11 19:41 2013-01-14 Show GitHub Exploit DB Packet Storm
225934 7.5 危険 John Nunemaker - Ruby 用 httparty gem におけるオブジェクトインジェクション攻撃を実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-1801 2013-04-11 19:41 2013-01-14 Show GitHub Exploit DB Packet Storm
225935 7.5 危険 John Nunemaker - Ruby 用 crack gem におけるオブジェクトインジェクション攻撃を実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-1800 2013-04-11 19:40 2013-01-14 Show GitHub Exploit DB Packet Storm
225936 7.5 危険 Daniel Harrington - Ruby 用 nori gem におけるオブジェクトインジェクション攻撃を実行される脆弱性 CWE-20
不適切な入力確認
CVE-2013-0285 2013-04-11 19:39 2013-01-14 Show GitHub Exploit DB Packet Storm
225937 5 警告 New Relic - Ruby Agent における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2013-0284 2013-04-11 19:38 2013-02-13 Show GitHub Exploit DB Packet Storm
225938 6.8 警告 Michael Bleigh and Intridea, Inc. - Ruby 用 omniauth-oauth2 gem におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2012-6134 2013-04-11 19:37 2013-02-25 Show GitHub Exploit DB Packet Storm
225939 5.8 警告 Apache Software Foundation - Apache Maven のデフォルト設定におけるサーバになりすまされる脆弱性 CWE-16
環境設定
CVE-2013-0253 2013-04-11 17:36 2013-04-2 Show GitHub Exploit DB Packet Storm
225940 4.3 警告 fedorahosted.org - cronie におけるファイル記述子が漏えいする脆弱性 CWE-200
情報漏えい
CVE-2012-6097 2013-04-11 17:35 2013-01-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 26, 2026, 4:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
213371 5.5 MEDIUM
Local
canonical
debian
ubuntu_linux
debian_linux
It was discovered that aufs improperly managed inode reference counts in the vfsub_dentry_open() method. A local attacker could use this vulnerability to cause a denial of service attack. NVD-CWE-Other
CVE-2020-11935 2024-11-21 13:58 2023-04-7 Show GitHub Exploit DB Packet Storm
213372 8.1 HIGH
Network
thimpress learnpress The LearnPress plugin before 3.2.6.9 for WordPress allows remote attackers to escalate the privileges of any user to LP Instructor via the accept-to-be-teacher action parameter. CWE-862
 Missing Authorization
CVE-2020-11511 2024-11-21 13:58 2021-07-30 Show GitHub Exploit DB Packet Storm
213373 7.8 HIGH
Local
zscaler client_connector The Zscaler Client Connector for Windows prior to 2.1.2.105 had a DLL hijacking vulnerability caused due to the configuration of OpenSSL. A local adversary may be able to execute arbitrary code in th… CWE-427
 Uncontrolled Search Path Element
CVE-2020-11634 2024-11-21 13:58 2021-07-16 Show GitHub Exploit DB Packet Storm
213374 7.8 HIGH
Local
zscaler client_connector The Zscaler Client Connector prior to 2.1.2.150 did not quote the search path for services, which allows a local adversary to execute code with system privileges. CWE-428
 Unquoted Search Path or Element
CVE-2020-11632 2024-11-21 13:58 2021-07-16 Show GitHub Exploit DB Packet Storm
213375 9.8 CRITICAL
Network
zscaler client_connector The Zscaler Client Connector for Windows prior to 2.1.2.74 had a stack based buffer overflow when connecting to misconfigured TLS servers. An adversary would potentially have been able to execute arb… CWE-787
 Out-of-bounds Write
CVE-2020-11633 2024-11-21 13:58 2021-07-16 Show GitHub Exploit DB Packet Storm
213376 5.5 MEDIUM
Local
wizconnected colors_a60_firmware An issue was discovered in WiZ Colors A60 1.14.0. Wi-Fi credentials are stored in cleartext in flash memory, which presents an information-disclosure risk for a discarded or resold device. CWE-312
 Cleartext Storage of Sensitive Information
CVE-2020-11924 2024-11-21 13:58 2021-04-3 Show GitHub Exploit DB Packet Storm
213377 5.5 MEDIUM
Local
wizconnected wiz An issue was discovered in WiZ Colors A60 1.14.0. API credentials are locally logged. CWE-312
 Cleartext Storage of Sensitive Information
CVE-2020-11923 2024-11-21 13:58 2021-04-3 Show GitHub Exploit DB Packet Storm
213378 8.8 HIGH
Adjacent
luvion grand_elite_3_connect_firmware An issue was discovered in Luvion Grand Elite 3 Connect through 2020-02-25. Authentication to the device is based on a username and password. The root credentials are the same across all devices of t… CWE-522
 Insufficiently Protected Credentials
CVE-2020-11925 2024-11-21 13:58 2021-04-3 Show GitHub Exploit DB Packet Storm
213379 4.3 MEDIUM
Adjacent
wizconnected a60_colors_firmware An issue was discovered in WiZ Colors A60 1.14.0. The device sends unnecessary information to the cloud controller server. Although this information is sent encrypted and has low risk in isolation, i… CWE-200
Information Exposure
CVE-2020-11922 2024-11-21 13:58 2021-04-3 Show GitHub Exploit DB Packet Storm
213380 7.8 HIGH
Local
zscaler client_connector The Zscaler Client Connector prior to 3.1.0 did not sufficiently validate RPC clients, which allows a local adversary to execute code with system privileges or perform limited actions for which they … NVD-CWE-noinfo
CVE-2020-11635 2024-11-21 13:58 2021-02-17 Show GitHub Exploit DB Packet Storm