Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 1, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
226251 6.8 警告 レッドハット - JBoss Enterprise Portal Platform の GateIn Portal コンポーネントにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2012-3532 2013-04-16 16:20 2012-08-23 Show GitHub Exploit DB Packet Storm
226252 9.3 危険 IBM - IBM Cognos Disclosure Management およびその他の製品における任意のファイルを読まれる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-0501 2013-04-16 16:15 2013-04-5 Show GitHub Exploit DB Packet Storm
226253 9.3 危険 IBM - 複数の IBM 製品における任意のコマンドを実行される脆弱性 CWE-noinfo
情報不足
CVE-2012-5937 2013-04-16 15:56 2013-04-10 Show GitHub Exploit DB Packet Storm
226254 5 警告 OpenStack - 複数の OpenStack コンポーネントにおけるアクセスの制限を回避される脆弱性 CWE-287
不適切な認証
CVE-2013-0282 2013-04-16 15:52 2013-02-20 Show GitHub Exploit DB Packet Storm
226255 5 警告 OpenStack - OpenStack Keystone の Grizzly および Folsom におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2013-0270 2013-04-16 15:47 2013-04-4 Show GitHub Exploit DB Packet Storm
226256 7.5 危険 ZAPms - ZAPms における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2013-3050 2013-04-16 15:40 2013-04-10 Show GitHub Exploit DB Packet Storm
226257 7.1 危険 シスコシステムズ - Cisco Adaptive Security Appliances におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2013-1151 2013-04-15 11:42 2013-04-10 Show GitHub Exploit DB Packet Storm
226258 5.7 警告 シスコシステムズ - Cisco ユニバーサルブロードバンド 10000 シリーズルータにおけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2013-1189 2013-04-15 11:39 2013-04-10 Show GitHub Exploit DB Packet Storm
226259 6.6 警告 シスコシステムズ - Cisco AnyConnect Secure Mobility Client におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2013-1173 2013-04-15 11:38 2013-04-10 Show GitHub Exploit DB Packet Storm
226260 6.6 警告 シスコシステムズ - Cisco AnyConnect Secure Mobility Client における権限を取得される脆弱性 CWE-20
不適切な入力確認
CVE-2013-1172 2013-04-15 11:38 2013-04-10 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 2, 2026, 4:18 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
224161 5.4 MEDIUM
Network
atlassian editor-core The hyperlinks functionality in atlaskit/editor-core in before version 113.1.5 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in link ta… CWE-79
Cross-site Scripting
CVE-2019-20903 2024-11-21 13:39 2020-10-1 Show GitHub Exploit DB Packet Storm
224162 7.5 HIGH
Network
atlassian crowd Upgrading Crowd via XML Data Transfer can reactivate a disabled user from OpenLDAP. The affected versions are from before version 3.4.6 and from 3.5.0 before 3.5.1. NVD-CWE-noinfo
CVE-2019-20902 2024-11-21 13:39 2020-10-1 Show GitHub Exploit DB Packet Storm
224163 7.5 HIGH
Network
handlebarsjs handlebars Handlebars before 4.4.5 allows Regular Expression Denial of Service (ReDoS) because of eager matching. The parser may be forced into an endless loop while processing crafted templates. This may allow… CWE-400
 Uncontrolled Resource Consumption
CVE-2019-20922 2024-11-21 13:39 2020-10-1 Show GitHub Exploit DB Packet Storm
224164 6.1 MEDIUM
Network
snapappointments bootstrap-select bootstrap-select before 1.13.6 allows Cross-Site Scripting (XSS). It does not escape title values in OPTION elements. This may allow attackers to execute arbitrary JavaScript in a victim's browser. CWE-79
Cross-site Scripting
CVE-2019-20921 2024-11-21 13:39 2020-10-1 Show GitHub Exploit DB Packet Storm
224165 8.1 HIGH
Network
handlebarsjs handlebars Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrary Code Execution. The lookup helper fails to properly validate templates, allowing attackers to submit templates that execute arb… CWE-94
Code Injection
CVE-2019-20920 2024-11-21 13:39 2020-10-1 Show GitHub Exploit DB Packet Storm
224166 4.7 MEDIUM
Local
perl
fedoraproject
canonical
debian
opensuse
dbi
fedora
ubuntu_linux
debian_linux
leap
An issue was discovered in the DBI module before 1.643 for Perl. The hv_fetch() documentation requires checking for NULL and the code does that. But, shortly thereafter, it calls SvOK(profile), causi… CWE-476
 NULL Pointer Dereference
CVE-2019-20919 2024-11-21 13:39 2020-09-18 Show GitHub Exploit DB Packet Storm
224167 6.5 MEDIUM
Network
inspircd inspircd An issue was discovered in InspIRCd 3 before 3.1.0. The silence module contains a use after free vulnerability. This vulnerability can be used for remote crashing of an InspIRCd server by any user ab… CWE-416
 Use After Free
CVE-2019-20918 2024-11-21 13:39 2020-09-11 Show GitHub Exploit DB Packet Storm
224168 6.5 MEDIUM
Network
inspircd
debian
inspircd
debian_linux
An issue was discovered in InspIRCd 2 before 2.0.28 and 3 before 3.3.0. The mysql module contains a NULL pointer dereference when built against mariadb-connector-c 3.0.5 or newer. When combined with … CWE-476
 NULL Pointer Dereference
CVE-2019-20917 2024-11-21 13:39 2020-09-11 Show GitHub Exploit DB Packet Storm
224169 7.5 HIGH
Network
pypa
opensuse
debian
oracle
pip
leap
debian_linux
communications_cloud_native_core_policy
communications_cloud_native_core_network_function_cloud_native_environment
The pip package before 19.2 for Python allows Directory Traversal when a URL is given in an install command, because a Content-Disposition header can have ../ in a filename, as demonstrated by overwr… CWE-22
Path Traversal
CVE-2019-20916 2024-11-21 13:39 2020-09-5 Show GitHub Exploit DB Packet Storm
224170 8.1 HIGH
Network
gnu libredwg An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a heap-based buffer over-read in bit_write_TF in bits.c. CWE-125
Out-of-bounds Read
CVE-2019-20915 2024-11-21 13:39 2020-07-17 Show GitHub Exploit DB Packet Storm