Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 31, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
227571 5 警告 libssh - libssh の keys.c におけるサービス運用妨害 (クラッシュ) の脆弱性 CWE-noinfo
情報不足
CVE-2012-4561 2012-12-21 15:19 2012-11-20 Show GitHub Exploit DB Packet Storm
227572 6.8 警告 libssh - libssh の複数の関数におけるメモリ二重解放の脆弱性 CWE-399
リソース管理の問題
CVE-2012-4559 2012-12-21 15:18 2012-11-20 Show GitHub Exploit DB Packet Storm
227573 7.5 危険 libssh - libssh の sftp.c におけるメモリ二重解放の脆弱性 CWE-399
リソース管理の問題
CVE-2012-6063 2012-12-21 15:16 2012-11-20 Show GitHub Exploit DB Packet Storm
227574 3.6 注意 oVirt - SANLock の log.h におけるファイルコンテンツを上書きされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-5638 2012-12-21 15:08 2012-12-20 Show GitHub Exploit DB Packet Storm
227575 7.9 危険 IBM - IBM POWER5 のサービス・プロセッサーに権限昇格の脆弱性 CWE-255
証明書・パスワード管理
CVE-2012-4856 2012-12-21 14:56 2012-12-13 Show GitHub Exploit DB Packet Storm
227576 7.5 危険 Ciprian Popescu - WordPress 用 Portable phpMyAdmin プラグインにおける認証を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-5469 2012-12-21 14:08 2012-12-20 Show GitHub Exploit DB Packet Storm
227577 2.6 注意 NHN Japan - Android 版 ロケタッチにおける情報管理不備の脆弱性 CWE-Other
その他
CVE-2012-5183 2012-12-21 12:02 2012-12-21 Show GitHub Exploit DB Packet Storm
227578 2.6 注意 NHN Japan - Android 版 ロケタッチにおける暗黙的 Intent の扱いに関する脆弱性 CWE-DesignError
CVE-2012-5182 2012-12-21 12:01 2012-12-21 Show GitHub Exploit DB Packet Storm
227579 10 危険 IBM - IBM WAS for z/OS の IBM HTTP Server コンポーネントにおける任意のコマンドを実行される脆弱性 CWE-noinfo
情報不足
CVE-2012-5955 2012-12-21 11:50 2012-12-19 Show GitHub Exploit DB Packet Storm
227580 5 警告 IBM - IBM Rational ClearQuest の Web クライアントにおける重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2012-5765 2012-12-21 11:48 2012-12-12 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 31, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
208501 5.4 MEDIUM
Network
codologic codoforum A stored cross site scripting (XSS) vulnerability in the 'Pages' feature of Codoforum v5.0.2 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payload entered into t… CWE-79
Cross-site Scripting
CVE-2020-25876 2024-11-21 14:18 2021-07-10 Show GitHub Exploit DB Packet Storm
208502 5.4 MEDIUM
Network
codologic codoforum A stored cross site scripting (XSS) vulnerability in the 'Smileys' feature of Codoforum v5.0.2 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payload entered into… CWE-79
Cross-site Scripting
CVE-2020-25875 2024-11-21 14:18 2021-07-10 Show GitHub Exploit DB Packet Storm
208503 6.1 MEDIUM
Network
icewarp webclient Cross Site Scripting (XSS) in Webmail Calender in IceWarp WebClient 10.3.5 allows remote attackers to inject arbitrary web script or HTML via the "p4" field. CWE-79
Cross-site Scripting
CVE-2020-25925 2024-11-21 14:18 2021-07-7 Show GitHub Exploit DB Packet Storm
208504 7.5 HIGH
Network
pexip pexip_infinity Pexip Infinity 22.x through 24.x before 24.2 has Improper Input Validation for call setup. An unauthenticated remote attacker can trigger a software abort (temporary loss of service). CWE-20
 Improper Input Validation 
CVE-2020-25868 2024-11-21 14:18 2021-07-7 Show GitHub Exploit DB Packet Storm
208505 8.8 HIGH
Network
enphase envoy_firmware An issue was discovered on Enphase Envoy R3.x and D4.x (and other current) devices. The upgrade_start function in /installer/upgrade_start allows remote authenticated users to execute arbitrary comma… CWE-78
OS Command 
CVE-2020-25755 2024-11-21 14:18 2021-06-17 Show GitHub Exploit DB Packet Storm
208506 7.5 HIGH
Network
enphase envoy_firmware An issue was discovered on Enphase Envoy R3.x and D4.x devices. There is a custom PAM module for user authentication that circumvents traditional user authentication. This module uses a password deri… CWE-916
 Use of Password Hash With Insufficient Computational Effort
CVE-2020-25754 2024-11-21 14:18 2021-06-17 Show GitHub Exploit DB Packet Storm
208507 9.8 CRITICAL
Network
enphase envoy_firmware An issue was discovered on Enphase Envoy R3.x and D4.x devices with v3 software. The default admin password is set to the last 6 digits of the serial number. The serial number can be retrieved by an … NVD-CWE-noinfo
CVE-2020-25753 2024-11-21 14:18 2021-06-17 Show GitHub Exploit DB Packet Storm
208508 5.3 MEDIUM
Network
enphase envoy_firmware An issue was discovered on Enphase Envoy R3.x and D4.x devices. There are hardcoded web-panel login passwords for the installer and Enphase accounts. The passwords for these accounts are hardcoded va… CWE-798
 Use of Hard-coded Credentials
CVE-2020-25752 2024-11-21 14:18 2021-06-17 Show GitHub Exploit DB Packet Storm
208509 5.5 MEDIUM
Local
long_range_zip_project
debian
long_range_zip
debian_linux
A null pointer dereference was discovered lzo_decompress_buf in stream.c in Irzip 0.621 which allows an attacker to cause a denial of service (DOS) via a crafted compressed file. CWE-476
 NULL Pointer Dereference
CVE-2020-25467 2024-11-21 14:18 2021-06-11 Show GitHub Exploit DB Packet Storm
208510 4.8 MEDIUM
Network
silverstripe silverstripe SilverStripe through 4.6.0-rc1 has an XXE Vulnerability in CSSContentParser. A developer utility meant for parsing HTML within unit tests can be vulnerable to XML External Entity (XXE) attacks. When … CWE-611
XXE
CVE-2020-25817 2024-11-21 14:18 2021-06-9 Show GitHub Exploit DB Packet Storm