Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 12, 2026, 4:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
226281 4.9 警告 QNAP Systems - QNAP TS-239 Pro および TS-639 Pro における重要な情報を取得される脆弱性 CWE-310
暗号の問題
CVE-2009-3279 2012-12-20 19:28 2009-09-21 Show GitHub Exploit DB Packet Storm
226282 4.9 警告 QNAP Systems - QNAP TS-239 Pro などにおける鍵を特定される脆弱性 CWE-310
暗号の問題
CVE-2009-3278 2012-12-20 19:28 2009-09-21 Show GitHub Exploit DB Packet Storm
226283 5 警告 xenu by - datavault の DataVault.Tesla/Impl/TypeSystem/AssociationHelper.cs におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2009-3277 2012-12-20 19:28 2009-09-21 Show GitHub Exploit DB Packet Storm
226284 7.5 危険 thomas cuchta - RQMS における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-3259 2012-12-20 19:28 2009-09-18 Show GitHub Exploit DB Packet Storm
226285 9 危険 Vtiger - vtiger CRM における添付ファイルを削除される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2009-3258 2012-12-20 19:28 2009-03-6 Show GitHub Exploit DB Packet Storm
226286 6.8 警告 thomas cuchta - RQMS における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-3255 2012-12-20 19:28 2009-09-18 Show GitHub Exploit DB Packet Storm
226287 9.3 危険 ultimatevideosite - Ultimate Player におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-3254 2012-12-20 19:28 2009-09-18 Show GitHub Exploit DB Packet Storm
226288 9.3 危険 tricerasoft - TriceraSoft Swift Ultralite におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-3253 2012-12-20 19:28 2009-09-18 Show GitHub Exploit DB Packet Storm
226289 9 危険 Vtiger - vtiger CRM の Compose Mail 機能における任意のコードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2009-3250 2012-12-20 19:28 2009-09-18 Show GitHub Exploit DB Packet Storm
226290 7.5 危険 Vtiger - vtiger CRM におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2009-3249 2012-12-20 19:28 2009-09-18 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 12, 2026, 5:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
200211 5.4 MEDIUM
Network
dropouts air_share Dropouts Technologies LLP Air Share v1.2 was discovered to contain a cross-site scripting (XSS) vulnerability in the devicename parameter. This vulnerability allows attackers to execute arbitrary web… CWE-79
Cross-site Scripting
CVE-2020-36489 2024-11-21 14:29 2021-10-23 Show GitHub Exploit DB Packet Storm
200212 6.5 MEDIUM
Network
sky_file_project sky_file An issue in the FTP server of Sky File v2.1.0 allows attackers to perform directory traversal via `/null//` path commands. CWE-22
Path Traversal
CVE-2020-36488 2024-11-21 14:29 2021-10-23 Show GitHub Exploit DB Packet Storm
200213 6.1 MEDIUM
Network
swiftfiletransfer swift_file_transfer Swift File Transfer Mobile v1.1.2 and below was discovered to contain a cross-site scripting (XSS) vulnerability via the 'path' parameter of the 'list' and 'download' exception-handling. CWE-79
Cross-site Scripting
CVE-2020-36486 2024-11-21 14:29 2021-10-23 Show GitHub Exploit DB Packet Storm
200214 7.8 HIGH
Local
madeportable playable Portable Ltd Playable v9.18 was discovered to contain an arbitrary file upload vulnerability in the filename parameter of the upload module. This vulnerability allows attackers to execute arbitrary c… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2020-36485 2024-11-21 14:29 2021-10-23 Show GitHub Exploit DB Packet Storm
200215 7.5 HIGH
Network
arm
debian
mbed_tls
debian_linux
An issue was discovered in Mbed TLS before 2.24.0 (and before 2.16.8 LTS and before 2.7.17 LTS). There is missing zeroization of plaintext buffers in mbedtls_ssl_read to erase unused application data… CWE-212
 Improper Removal of Sensitive Information Before Storage or Transfer
CVE-2020-36476 2024-11-21 14:29 2021-08-23 Show GitHub Exploit DB Packet Storm
200216 7.5 HIGH
Network
arm
siemens
debian
mbed_tls
logo\!_cmr2020_firmware
logo\!_cmr2040_firmware
simatic_rtu3031c_firmware
simatic_rtu3041c_firmware
simatic_rtu3030c_firmware
simatic_rtu3000c_firmware
debian_linux
An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). The calculations performed by mbedtls_mpi_exp_mod are not limited; thus, supplying overly large parame… CWE-131
Incorrect Calculation of Buffer Size
CVE-2020-36475 2024-11-21 14:29 2021-08-23 Show GitHub Exploit DB Packet Storm
200217 7.5 HIGH
Network
arm
siemens
debian
mbed_tls
logo\!_cmr2020_firmware
logo\!_cmr2040_firmware
simatic_rtu3031c_firmware
simatic_rtu3041c_firmware
simatic_rtu3030c_firmware
simatic_rtu3000c_firmware
debian_linux
An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). A NULL algorithm parameters entry looks identical to an array of REAL (size zero) and thus the certifi… CWE-295
Improper Certificate Validation 
CVE-2020-36478 2024-11-21 14:29 2021-08-23 Show GitHub Exploit DB Packet Storm
200218 5.9 MEDIUM
Network
arm mbed_tls An issue was discovered in Mbed TLS before 2.24.0. The verification of X.509 certificates when matching the expected common name (the cn argument of mbedtls_x509_crt_verify) with the actual certifica… CWE-295
Improper Certificate Validation 
CVE-2020-36477 2024-11-21 14:29 2021-08-23 Show GitHub Exploit DB Packet Storm
200219 9.8 CRITICAL
Network
safecurl_project safecurl SafeCurl before 0.9.2 has a DNS rebinding vulnerability. NVD-CWE-Other
CVE-2020-36474 2024-11-21 14:29 2021-08-21 Show GitHub Exploit DB Packet Storm
200220 3.7 LOW
Network
ucweb ucweb_uc UCWeb UC 12.12.3.1219 through 12.12.3.1226 uses cleartext HTTP, and thus man-in-the-middle attackers can discover visited URLs. CWE-312
 Cleartext Storage of Sensitive Information
CVE-2020-36473 2024-11-21 14:29 2021-08-15 Show GitHub Exploit DB Packet Storm