Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 13, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
226701 10 危険 サン・マイクロシステムズ - Fedora 上で稼動する OpenJDK の IcedTea における任意のコードを実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2009-1896 2012-12-20 19:10 2009-08-7 Show GitHub Exploit DB Packet Storm
226702 7.2 危険 PulseAudio - PulseAudio における権限を取得される脆弱性 CWE-362
競合状態
CVE-2009-1894 2012-12-20 19:10 2009-07-17 Show GitHub Exploit DB Packet Storm
226703 7.5 危険 PHPNUKE - Francisco Burzi PHP-Nuke の main/tracking/userLog.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-1842 2012-12-20 19:10 2009-06-1 Show GitHub Exploit DB Packet Storm
226704 10 危険 slsknet - Soulseek におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-1830 2012-12-20 19:10 2009-05-29 Show GitHub Exploit DB Packet Storm
226705 9.3 危険 sonicspot - Sonic Spot Audioactive Player におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-1815 2012-12-20 19:10 2009-05-29 Show GitHub Exploit DB Packet Storm
226706 7.5 危険 submitterscript - Submitter Script の admin/index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-1813 2012-12-20 19:10 2009-05-29 Show GitHub Exploit DB Packet Storm
226707 7.5 危険 videoscript - VideoScript.us YouTube Video Script の admin/index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-1804 2012-12-20 19:10 2009-05-28 Show GitHub Exploit DB Packet Storm
226708 6.8 警告 sebastian-thiele - ST-Gallery の st_admin/gallery_output.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-1799 2012-12-20 19:10 2009-05-28 Show GitHub Exploit DB Packet Storm
226709 4.3 警告 サン・マイクロシステムズ - Sun Java System Portal Server におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-1796 2012-12-20 19:10 2009-05-22 Show GitHub Exploit DB Packet Storm
226710 9.3 危険 stonetrip - StoneTrip Ston3D StandalonePlayer および WebPlayer の system.openURL 関数における任意のコマンドを実行される脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2009-1792 2012-12-20 19:10 2009-05-29 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 14, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
210271 5.4 MEDIUM
Network
bludit bludit showAlert() in the administration panel in Bludit 3.12.0 allows XSS. CWE-79
Cross-site Scripting
CVE-2020-13889 2024-11-21 14:02 2020-06-7 Show GitHub Exploit DB Packet Storm
210272 6.7 MEDIUM
Network
wso2 identity_server_as_key_manager
api_microgateway
api_manager
In WSO2 API Manager 3.0.0 and earlier, WSO2 API Microgateway 2.2.0, and WSO2 IS as Key Manager 5.9.0 and earlier, Management Console allows XXE during addition or update of a Lifecycle. CWE-611
XXE
CVE-2020-13883 2024-11-21 14:02 2020-06-7 Show GitHub Exploit DB Packet Storm
210273 7.5 HIGH
Network
pam_tacplus_project
debian
canonical
arista
pam_tacplus
debian_linux
ubuntu_linux
cloudvision_portal
In support.c in pam_tacplus 1.3.8 through 1.5.1, the TACACS+ shared secret gets logged via syslog if the DEBUG loglevel and journald are used. CWE-532
 Inclusion of Sensitive Information in Log Files
CVE-2020-13881 2024-11-21 14:02 2020-06-7 Show GitHub Exploit DB Packet Storm
210274 7.5 HIGH
Network
sqlite
fedoraproject
debian
oracle
siemens
netapp
sqlite
fedora
debian_linux
hyperion_infrastructure_technology
enterprise_manager_ops_center
communications_network_charging_and_control
zfs_storage_appliance_kit
communications_m…
SQLite 3.32.2 has a use-after-free in resetAccumulator in select.c because the parse tree rewrite for window functions is too late. CWE-416
 Use After Free
CVE-2020-13871 2024-11-21 14:02 2020-06-7 Show GitHub Exploit DB Packet Storm
210275 5.4 MEDIUM
Network
elementor elementor_page_builder The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from multiple stored XSS vulnerabilities. An author user can create posts that result in stored XSS vulnerabilities, by using a cr… CWE-79
Cross-site Scripting
CVE-2020-13865 2024-11-21 14:02 2020-06-6 Show GitHub Exploit DB Packet Storm
210276 5.4 MEDIUM
Network
elementor elementor_page_builder The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from a stored XSS vulnerability. An author user can create posts that result in a stored XSS by using a crafted payload in custom … CWE-79
Cross-site Scripting
CVE-2020-13864 2024-11-21 14:02 2020-06-6 Show GitHub Exploit DB Packet Storm
210277 5.4 MEDIUM
Network
verbb comments An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. There is stored XSS via an asset volume name. CWE-79
Cross-site Scripting
CVE-2020-13870 2024-11-21 14:02 2020-06-6 Show GitHub Exploit DB Packet Storm
210278 5.4 MEDIUM
Network
verbb comments An issue was discovered in the Comments plugin before 1.5.6 for Craft CMS. There is stored XSS via a guest name. CWE-79
Cross-site Scripting
CVE-2020-13869 2024-11-21 14:02 2020-06-6 Show GitHub Exploit DB Packet Storm
210279 6.5 MEDIUM
Network
verbb comments An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. CSRF affects comment integrity. CWE-352
 Origin Validation Error
CVE-2020-13868 2024-11-21 14:02 2020-06-6 Show GitHub Exploit DB Packet Storm
210280 5.5 MEDIUM
Local
targetcli-fb_project
fedoraproject
targetcli-fb
fedora
Open-iSCSI targetcli-fb through 2.1.52 has weak permissions for /etc/target (and for the backup directory and backup files). CWE-276
Incorrect Default Permissions 
CVE-2020-13867 2024-11-21 14:02 2020-06-6 Show GitHub Exploit DB Packet Storm