Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 26, 2026, 2 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
225931 5 警告 Puppet - Puppet Labs の Puppet Enterprise におけるコンソールアクセスを取得される脆弱性 CWE-310
暗号の問題
CVE-2013-2716 2013-04-12 11:03 2013-03-28 Show GitHub Exploit DB Packet Storm
225932 7.5 危険 Digineo - Ruby 用 Thumbshooter gem の lib/thumbshooter.rb における任意のコマンドを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2013-1898 2013-04-11 19:42 2013-03-25 Show GitHub Exploit DB Packet Storm
225933 7.5 危険 Dan Kubb - Ruby 用 extlib gem におけるオブジェクトインジェクション攻撃を実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-1802 2013-04-11 19:41 2013-01-14 Show GitHub Exploit DB Packet Storm
225934 7.5 危険 John Nunemaker - Ruby 用 httparty gem におけるオブジェクトインジェクション攻撃を実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-1801 2013-04-11 19:41 2013-01-14 Show GitHub Exploit DB Packet Storm
225935 7.5 危険 John Nunemaker - Ruby 用 crack gem におけるオブジェクトインジェクション攻撃を実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-1800 2013-04-11 19:40 2013-01-14 Show GitHub Exploit DB Packet Storm
225936 7.5 危険 Daniel Harrington - Ruby 用 nori gem におけるオブジェクトインジェクション攻撃を実行される脆弱性 CWE-20
不適切な入力確認
CVE-2013-0285 2013-04-11 19:39 2013-01-14 Show GitHub Exploit DB Packet Storm
225937 5 警告 New Relic - Ruby Agent における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2013-0284 2013-04-11 19:38 2013-02-13 Show GitHub Exploit DB Packet Storm
225938 6.8 警告 Michael Bleigh and Intridea, Inc. - Ruby 用 omniauth-oauth2 gem におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2012-6134 2013-04-11 19:37 2013-02-25 Show GitHub Exploit DB Packet Storm
225939 5.8 警告 Apache Software Foundation - Apache Maven のデフォルト設定におけるサーバになりすまされる脆弱性 CWE-16
環境設定
CVE-2013-0253 2013-04-11 17:36 2013-04-2 Show GitHub Exploit DB Packet Storm
225940 4.3 警告 fedorahosted.org - cronie におけるファイル記述子が漏えいする脆弱性 CWE-200
情報漏えい
CVE-2012-6097 2013-04-11 17:35 2013-01-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 26, 2026, 4:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
213421 6.5 MEDIUM
Network
titanhq spamtitan An issue was discovered in Titan SpamTitan 7.07. Improper sanitization of the parameter fname, used on the page certs-x.php, would allow an attacker to retrieve the contents of arbitrary files. The u… CWE-22
Path Traversal
CVE-2020-11700 2024-11-21 13:58 2020-09-18 Show GitHub Exploit DB Packet Storm
213422 8.8 HIGH
Network
titanhq spamtitan An issue was discovered in Titan SpamTitan 7.07. Improper validation of the parameter fname on the page certs-x.php would allow an attacker to execute remote code on the target server. The user has t… CWE-78
OS Command 
CVE-2020-11699 2024-11-21 13:58 2020-09-18 Show GitHub Exploit DB Packet Storm
213423 9.8 CRITICAL
Network
titanhq spamtitan An issue was discovered in Titan SpamTitan 7.07. Improper input sanitization of the parameter community on the page snmp-x.php would allow a remote attacker to inject commands into the file snmpd.con… CWE-77
Command Injection
CVE-2020-11698 2024-11-21 13:58 2020-09-18 Show GitHub Exploit DB Packet Storm
213424 7.5 HIGH
Network
mikrotik routeros An array index error in MikroTik RouterOS 6.41.3 through 6.46.5, and 7.x through 7.0 Beta5, allows an unauthenticated remote attacker to crash the SMB server via modified setup-request packets, aka S… CWE-129
 Improper Validation of Array Index
CVE-2020-11881 2024-11-21 13:58 2020-09-15 Show GitHub Exploit DB Packet Storm
213425 9.1 CRITICAL
Network
linux4sam at91bootstrap AT91bootstrap before 3.9.2 does not properly wipe encryption and authentication keys from memory before passing control to a less privileged software component. This can be exploited to disclose thes… CWE-212
 Improper Removal of Sensitive Information Before Storage or Transfer
CVE-2020-11684 2024-11-21 13:58 2020-09-14 Show GitHub Exploit DB Packet Storm
213426 6.8 MEDIUM
Physics
linux4sam at91bootstrap A timing side channel was discovered in AT91bootstrap before 3.9.2. It can be exploited by attackers with physical access to forge CMAC values and subsequently boot arbitrary code on an affected syst… CWE-203
 Information Exposure Through Discrepancy
CVE-2020-11683 2024-11-21 13:58 2020-09-14 Show GitHub Exploit DB Packet Storm
213427 8.1 HIGH
Network
foxitsoftware phantompdf
reader
In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can obtain sensitive information about an uninitialized object because of direct transformation from PDF Object to… CWE-345
 Insufficient Verification of Data Authenticity
CVE-2020-11493 2024-11-21 13:58 2020-09-4 Show GitHub Exploit DB Packet Storm
213428 7.5 HIGH
Network
chadhaajay phpkb An issue was discovered in Chadha PHPKB 9.0 Enterprise Edition. installer/test-connection.php (part of the installation process) allows a remote unauthenticated attacker to disclose local files on ho… CWE-306
Missing Authentication for Critical Function
CVE-2020-11579 2024-11-21 13:58 2020-09-4 Show GitHub Exploit DB Packet Storm
213429 7.8 HIGH
Local
thomsonstb
philips
tht741fta_firmware
dtr3502bfta_dvb-t2_firmware
THOMSON THT741FTA 2.2.1 and Philips DTR3502BFTA DVB-T2 2.2.1 set-top boxes have their TELNET service hardcoded to start on boot, which allows an attacker on the local network to achieve root access v… NVD-CWE-noinfo
CVE-2020-11618 2024-11-21 13:58 2020-09-1 Show GitHub Exploit DB Packet Storm
213430 5.9 MEDIUM
Network
thomsonstb
philips
tht741fta_firmware
dtr3502bfta_dvb-t2_firmware
The RSS application on THOMSON THT741FTA 2.2.1 and Philips DTR3502BFTA DVB-T2 2.2.1 set-top boxes doesn't validate the SSL certificates of RSS servers, which allows a man-in-the-middle attacker to mo… CWE-295
Improper Certificate Validation 
CVE-2020-11617 2024-11-21 13:58 2020-09-1 Show GitHub Exploit DB Packet Storm