Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 5, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228291 6.8 警告 tweakfs - FSX 用の Create and Extract Zips TweakFS Zip Utility におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2010-1458 2012-12-20 19:29 2010-04-20 Show GitHub Exploit DB Packet Storm
228292 4.3 警告 Piwik - Piwik の Login フォームにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-1453 2012-12-20 19:29 2010-04-15 Show GitHub Exploit DB Packet Storm
228293 5 警告 レッドハット - Red Hat JBoss Enterprise Application Platform における重要な情報を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2010-1429 2012-12-20 19:29 2010-04-27 Show GitHub Exploit DB Packet Storm
228294 4.3 警告 PreProject.com - Pre Classified Listings ASP の signup.asp におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-1371 2012-12-20 19:29 2010-04-13 Show GitHub Exploit DB Packet Storm
228295 7.5 危険 PreProject.com - Pre Classified Listings ASP の detailad.asp における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-1370 2012-12-20 19:29 2010-04-13 Show GitHub Exploit DB Packet Storm
228296 7.5 危険 PreProject.com - Pre Classified Listings ASP の signup.asp における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-1369 2012-12-20 19:29 2010-04-13 Show GitHub Exploit DB Packet Storm
228297 4.3 警告 Uiga - Uiga Fan Club の admin/admin_login.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-1367 2012-12-20 19:29 2010-04-13 Show GitHub Exploit DB Packet Storm
228298 7.5 危険 Uiga - Uiga Fan Club の admin/admin_login.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-1366 2012-12-20 19:29 2010-04-13 Show GitHub Exploit DB Packet Storm
228299 7.5 危険 Uiga - Uiga Fan Club の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-1365 2012-12-20 19:29 2010-04-13 Show GitHub Exploit DB Packet Storm
228300 7.5 危険 Uiga - Uiga Personal Portal の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-1364 2012-12-20 19:29 2010-04-13 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 5, 2026, 4:11 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
207641 5.3 MEDIUM
Network
jenkins azure_ad Jenkins Azure AD Plugin 1.1.2 and earlier transmits configured credentials in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure. CWE-522
 Insufficiently Protected Credentials
CVE-2020-2119 2024-11-21 14:24 2020-02-13 Show GitHub Exploit DB Packet Storm
207642 4.3 MEDIUM
Network
jenkins pipeline_github_notify_step A missing permission check in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and earlier in form-related methods allowed users with Overall/Read access to enumerate credentials ID of credentials st… CWE-276
Incorrect Default Permissions 
CVE-2020-2118 2024-11-21 14:24 2020-02-13 Show GitHub Exploit DB Packet Storm
207643 4.3 MEDIUM
Network
jenkins pipeline_github_notify_step A missing permission check in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specifi… CWE-276
Incorrect Default Permissions 
CVE-2020-2117 2024-11-21 14:24 2020-02-13 Show GitHub Exploit DB Packet Storm
207644 8.8 HIGH
Network
jenkins pipeline_github_notify_step A cross-site request forgery vulnerability in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credential… CWE-352
 Origin Validation Error
CVE-2020-2116 2024-11-21 14:24 2020-02-13 Show GitHub Exploit DB Packet Storm
207645 8.8 HIGH
Network
jenkins nunit Jenkins NUnit Plugin 0.25 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks. CWE-611
XXE
CVE-2020-2115 2024-11-21 14:24 2020-02-13 Show GitHub Exploit DB Packet Storm
207646 7.5 HIGH
Network
jenkins s3_publisher Jenkins S3 publisher Plugin 0.11.4 and earlier transmits configured credentials in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure. CWE-522
 Insufficiently Protected Credentials
CVE-2020-2114 2024-11-21 14:24 2020-02-13 Show GitHub Exploit DB Packet Storm
207647 5.4 MEDIUM
Network
jenkins git_parameter Jenkins Git Parameter Plugin 0.9.11 and earlier does not escape the default value shown on the UI, resulting in a stored cross-site scripting vulnerability exploitable by users with Job/Configure per… CWE-79
Cross-site Scripting
CVE-2020-2113 2024-11-21 14:24 2020-02-13 Show GitHub Exploit DB Packet Storm
207648 5.4 MEDIUM
Network
jenkins git_parameter Jenkins Git Parameter Plugin 0.9.11 and earlier does not escape the parameter name shown on the UI, resulting in a stored cross-site scripting vulnerability exploitable by users with Job/Configure pe… CWE-79
Cross-site Scripting
CVE-2020-2112 2024-11-21 14:24 2020-02-13 Show GitHub Exploit DB Packet Storm
207649 5.4 MEDIUM
Network
jenkins subversion Jenkins Subversion Plugin 2.13.0 and earlier does not escape the error message for the Project Repository Base URL field form validation, resulting in a stored cross-site scripting vulnerability. CWE-79
Cross-site Scripting
CVE-2020-2111 2024-11-21 14:24 2020-02-13 Show GitHub Exploit DB Packet Storm
207650 8.8 HIGH
Network
jenkins script_security Sandbox protection in Jenkins Script Security Plugin 1.69 and earlier could be circumvented during the script compilation phase by applying AST transforming annotations to imports or by using them in… CWE-20
 Improper Input Validation 
CVE-2020-2110 2024-11-21 14:24 2020-02-13 Show GitHub Exploit DB Packet Storm