Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 14, 2026, noon

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228221 4.3 警告 IBM - IBM Security AppScan Enterprise におけるテストアカウントをハイジャックされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-0510 2013-04-2 15:11 2013-03-25 Show GitHub Exploit DB Packet Storm
228222 4.3 警告 IBM - IBM Security AppScan Enterprise および Rational Policy Tester における認証資格情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2013-0474 2013-04-2 15:09 2013-03-25 Show GitHub Exploit DB Packet Storm
228223 4.3 警告 IBM - IBM Security AppScan Enterprise および IBM Rational Policy Tester におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-0473 2013-04-2 15:03 2013-03-25 Show GitHub Exploit DB Packet Storm
228224 6.8 警告 IBM - IBM Tivoli Endpoint Manager の SUA アプリケーションにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2013-0452 2013-04-2 14:59 2013-03-20 Show GitHub Exploit DB Packet Storm
228225 5 警告 Digium - 複数の Asterisk 製品におけるサービス運用妨害 (デーモンクラッシュ) 状態にされる脆弱性 CWE-119
バッファエラー
CVE-2013-2686 2013-04-2 14:35 2013-03-27 Show GitHub Exploit DB Packet Storm
228226 7.5 危険 Digium - Asterisk Open Source の res/res_format_attr_h264.c におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2013-2685 2013-04-2 14:35 2013-03-27 Show GitHub Exploit DB Packet Storm
228227 5 警告 Digium - 複数の Asterisk 製品の SIP チャンネルドライバにおけるアカウント名を列挙される脆弱性 CWE-200
情報漏えい
CVE-2013-2264 2013-04-2 14:34 2013-02-21 Show GitHub Exploit DB Packet Storm
228228 7.5 危険 Synchroweb Technology - Synchroweb Technology SynConnect の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2013-2690 2013-04-2 14:03 2013-03-28 Show GitHub Exploit DB Packet Storm
228229 - - ヒューレット・パッカード - ** 削除 ** HP ProCurve 1700-8 および 1700-24 スイッチにおけるクロスサイトリクエストフォージェリの脆弱性 - CVE-2012-5216 2013-04-2 13:53 2013-03-25 Show GitHub Exploit DB Packet Storm
228230 4.3 警告 アップル
Google
- Google Chrome におけるクロスサイトスクリプティング攻撃を実行される脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-3058 2013-04-2 11:33 2012-03-28 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 14, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
216671 6.1 MEDIUM
Network
we-com municipality_portal_cms XSS can occur in We-com Municipality portal CMS 2.1.x via the cerca/ search bar. CWE-79
Cross-site Scripting
CVE-2020-15538 2024-11-21 14:05 2020-07-6 Show GitHub Exploit DB Packet Storm
216672 6.1 MEDIUM
Network
vanguard_project vanguard An issue was discovered in the Vanguard plugin 2.1 for WordPress. XSS can occur via the mails/new title field, a product field to the p/ URI, or the Products Search box. CWE-79
Cross-site Scripting
CVE-2020-15537 2024-11-21 14:05 2020-07-6 Show GitHub Exploit DB Packet Storm
216673 6.1 MEDIUM
Network
online_hotel_booking_system_project online_hotel_booking_system An issue was discovered in the bestsoftinc Hotel Booking System Pro plugin through 1.1 for WordPress. Persistent XSS can occur via any of the registration fields. CWE-79
Cross-site Scripting
CVE-2020-15536 2024-11-21 14:05 2020-07-6 Show GitHub Exploit DB Packet Storm
216674 6.1 MEDIUM
Network
bestsoftinc car_rental_system An issue was discovered in the bestsoftinc Car Rental System plugin through 1.3 for WordPress. Persistent XSS can occur via any of the registration fields. CWE-79
Cross-site Scripting
CVE-2020-15535 2024-11-21 14:05 2020-07-6 Show GitHub Exploit DB Packet Storm
216675 7.5 HIGH
Network
wireshark
opensuse
debian
wireshark
leap
debian_linux
In Wireshark 3.2.0 to 3.2.4, the GVCP dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-gvcp.c by ensuring that an offset increases in all situations. CWE-835
 Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2020-15466 2024-11-21 14:05 2020-07-5 Show GitHub Exploit DB Packet Storm
216676 7.8 HIGH
Local
valvesoftware steam_client An issue was discovered in Valve Steam Client 2.10.91.91. The installer allows local users to gain NT AUTHORITY\SYSTEM privileges because some parts of %PROGRAMFILES(X86)%\Steam and/or %COMMONPROGRAM… CWE-362
Race Condition
CVE-2020-15530 2024-11-21 14:05 2020-07-5 Show GitHub Exploit DB Packet Storm
216677 7.8 HIGH
Local
gog galaxy An issue was discovered in GOG Galaxy Client 2.0.17. Local escalation of privileges is possible when a user installs a game or performs a verify/repair operation. The issue exists because of weak fil… CWE-667
CWE-732
 Improper Locking
 Incorrect Permission Assignment for Critical Resource
CVE-2020-15529 2024-11-21 14:05 2020-07-5 Show GitHub Exploit DB Packet Storm
216678 7.8 HIGH
Local
gog galaxy An issue was discovered in GOG Galaxy Client 2.0.17. Local escalation of privileges is possible when a user starts or uninstalls a game because of weak file permissions and missing file integrity che… CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2020-15528 2024-11-21 14:05 2020-07-5 Show GitHub Exploit DB Packet Storm
216679 7.8 HIGH
Local
python
netapp
python
snapcenter
In Python 3.6 through 3.6.10, 3.7 through 3.7.8, 3.8 through 3.8.4rc1, and 3.9 through 3.9.0b4 on Windows, a Trojan horse python3.dll might be used in cases where CPython is embedded in a native appl… CWE-427
CWE-908
 Uncontrolled Search Path Element
 Use of Uninitialized Resource
CVE-2020-15523 2024-11-21 14:05 2020-07-5 Show GitHub Exploit DB Packet Storm
216680 8.8 HIGH
Network
veeam veeam_availability_suite
veeam_backup_\&_replication
VeeamFSR.sys in Veeam Availability Suite before 10 and Veeam Backup & Replication before 10 has no device object DACL, which allows unprivileged users to achieve total control over filesystem I/O req… CWE-862
 Missing Authorization
CVE-2020-15518 2024-11-21 14:05 2020-07-3 Show GitHub Exploit DB Packet Storm