Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 2, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
227381 2.6 注意 Google
Mozilla Foundation
- 複数の製品で使用される SPDY プロトコルにおける平文の HTTP ヘッダを取得される脆弱性 CWE-310
暗号の問題
CVE-2012-4930 2012-12-28 18:12 2012-09-15 Show GitHub Exploit DB Packet Storm
227382 6.8 警告 Google
Mozilla Foundation
- Google Chrome の OpenType サニタイザにおける一つずれ (Off-by-one) エラーの脆弱性 CWE-189
数値処理の問題
CVE-2011-3062 2012-12-28 18:09 2012-03-28 Show GitHub Exploit DB Packet Storm
227383 7.6 危険 Post Oak Traffic Systems - Post Oak AWAM Bluetooth Reader Traffic System におけるデバイスを偽装される脆弱性 CWE-310
暗号の問題
CVE-2012-4687 2012-12-28 16:25 2011-11-30 Show GitHub Exploit DB Packet Storm
227384 4.3 警告 日立 - 複数の日立製品に含まれる Collaboration - Bulletin board におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
- 2012-12-28 16:17 2012-12-25 Show GitHub Exploit DB Packet Storm
227385 4.3 警告 Catalin Florian Radut - Drupal 用 Zero Point モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-5591 2012-12-28 16:06 2012-11-28 Show GitHub Exploit DB Packet Storm
227386 7.5 危険 Script Head - Drupal 用 Webmail Plus モジュールにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2012-5590 2012-12-28 16:06 2012-11-28 Show GitHub Exploit DB Packet Storm
227387 3.5 注意 Net Genius - Drupal 用 MultiLink モジュールにおける任意のノードタイトルを読まれる脆弱性 CWE-200
情報漏えい
CVE-2012-5589 2012-12-28 16:04 2012-11-28 Show GitHub Exploit DB Packet Storm
227388 2.6 注意 Matthias Hutterer - Drupal 用 Email Field モジュールにおける電子メールを送信される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-5588 2012-12-28 16:02 2012-11-28 Show GitHub Exploit DB Packet Storm
227389 4.3 警告 Matthias Hutterer - Drupal 用 Email Field モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-5587 2012-12-28 15:58 2012-11-28 Show GitHub Exploit DB Packet Storm
227390 2.1 注意 Marc Ingram - Drupal 用 Services モジュールにおける任意のユーザの電子メールにアクセスされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-5586 2012-12-28 15:57 2012-11-28 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 2, 2026, 4:18 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
221031 4.8 MEDIUM
Network
lenovo xclarity_administrator A stored cross-site scripting (XSS) vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.5.0 that could allow an administrative user to cause JavaScript code to be s… CWE-79
Cross-site Scripting
CVE-2019-6180 2024-11-21 13:46 2019-09-4 Show GitHub Exploit DB Packet Storm
221032 7.5 HIGH
Network
lenovo xclarity_administrator
xclarity_integrator
An XML External Entity (XXE) processing vulnerability was reported in Lenovo XClarity Administrator (LXCA) prior to version 2.5.0 , Lenovo XClarity Integrator (LXCI) for Microsoft System Center prior… CWE-611
XXE
CVE-2019-6179 2024-11-21 13:46 2019-09-4 Show GitHub Exploit DB Packet Storm
221033 9.8 CRITICAL
Network
fortinet fortimanager Lack of root file system integrity checking in Fortinet FortiManager VM application images of 6.2.0, 6.0.6 and below may allow an attacker to implant third-party programs by recreating the image thro… CWE-345
 Insufficient Verification of Data Authenticity
CVE-2019-6695 2024-11-21 13:46 2019-08-24 Show GitHub Exploit DB Packet Storm
221034 9.8 CRITICAL
Network
fortinet fortirecorder_firmware Use of Hard-coded Credentials vulnerability in FortiRecorder all versions below 2.7.4 may allow an unauthenticated attacker with knowledge of the aforementioned credentials and network access to Fort… CWE-798
 Use of Hard-coded Credentials
CVE-2019-6698 2024-11-21 13:46 2019-08-24 Show GitHub Exploit DB Packet Storm
221035 9.8 CRITICAL
Network
lenovo solution_center A vulnerability reported in Lenovo Solution Center version 03.12.003, which is no longer supported, could allow log files to be written to non-standard locations, potentially leading to privilege esc… CWE-200
Information Exposure
CVE-2019-6177 2024-11-21 13:46 2019-08-22 Show GitHub Exploit DB Packet Storm
221036 9.1 CRITICAL
Network
forcepoint next_generation_firewall Forcepoint Next Generation Firewall (Forcepoint NGFW) 6.4.x before 6.4.7, 6.5.x before 6.5.4, and 6.6.x before 6.6.2 has a serious authentication vulnerability that potentially allows unauthorized us… CWE-287
Improper Authentication
CVE-2019-6143 2024-11-21 13:46 2019-08-21 Show GitHub Exploit DB Packet Storm
221037 5.3 MEDIUM
Network
lenovo px12-350r_firmware
ix12-300r_firmware
home_media_network_hard_drive_firmware
storecenter_ix2-200_firmware
storecenter_ix4-200d_firmware
storecenter_ix4-200rl_firmware
An information leakage vulnerability in Iomega and LenovoEMC NAS products could allow disclosure of some device details such as Share names through the device API when Personal Cloud is enabled. This… NVD-CWE-noinfo
CVE-2019-6178 2024-11-21 13:46 2019-08-20 Show GitHub Exploit DB Packet Storm
221038 6.8 MEDIUM
Physics
lenovo 20f1_firmware
20f2_firmware
20jq_firmware
20jr_firmware
20g9_firmware
20gb_firmware
20g8_firmware
20ga_firmware
20ht_firmware
20hv_firmware
20hs_firmware
20hu_firmwar…
A vulnerability was reported in various BIOS versions of older ThinkPad systems that could allow a user with administrative privileges or physical access the ability to update the Embedded Controller… NVD-CWE-noinfo
CVE-2019-6171 2024-11-21 13:46 2019-08-20 Show GitHub Exploit DB Packet Storm
221039 7.8 HIGH
Local
lenovo yoga_700-11isk_firmware
yoga_700-14isk_firmware
A DLL search path vulnerability was reported in PaperDisplay Hotkey Service version 1.2.0.8 that could allow privilege escalation. Lenovo has ended support for PaperDisplay Hotkey software as the Nig… CWE-426
 Untrusted Search Path
CVE-2019-6165 2024-11-21 13:46 2019-08-20 Show GitHub Exploit DB Packet Storm
221040 6.1 MEDIUM
Network
lenovo bladecenter_hs22_firmware
bladecenter_hs22v_firmware
bladecenter_hx5_firmware
system_x_idataplex_dx360_m2_firmware
system_x_idataplex_dx360_m3_firmware
system_x3400_m3_firmware
syst…
A stored cross-site scripting (XSS) vulnerability exists in various firmware versions of the legacy IBM System x IMM (IMM v1) embedded Baseboard Management Controller (BMC). This vulnerability could … CWE-79
Cross-site Scripting
CVE-2019-6159 2024-11-21 13:46 2019-08-20 Show GitHub Exploit DB Packet Storm