Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 20, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228381 6.5 警告 GroundWork - GroundWork Monitor Enterprise の Cacti コンポーネントにおける構成の設定を読まれるの脆弱性 CWE-20
不適切な入力確認
CVE-2013-3512 2013-05-9 16:33 2013-03-7 Show GitHub Exploit DB Packet Storm
228382 5.8 警告 GroundWork - GroundWork Monitor Enterprise の NeDi コンポーネントにおけるオープンリダイレクトの脆弱性 CWE-20
不適切な入力確認
CVE-2013-3511 2013-05-9 16:32 2013-03-7 Show GitHub Exploit DB Packet Storm
228383 6.5 警告 GroundWork - GroundWork Monitor Enterprise における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2013-3510 2013-05-9 16:31 2013-03-7 Show GitHub Exploit DB Packet Storm
228384 6.5 警告 GroundWork - GroundWork Monitor Enterprise の NeDi コンポーネントにおける任意のコマンドを実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-3509 2013-05-9 16:30 2013-03-7 Show GitHub Exploit DB Packet Storm
228385 6.5 警告 GroundWork - GroundWork Monitor Enterprise の NeDi コンポーネントにおける任意のコマンドを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2013-3508 2013-05-9 16:26 2013-03-7 Show GitHub Exploit DB Packet Storm
228386 4 警告 GroundWork - GroundWork Monitor Enterprise の NeDi コンポーネントにおける重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2013-3507 2013-05-9 16:24 2013-03-7 Show GitHub Exploit DB Packet Storm
228387 7.5 危険 GroundWork - GroundWork Monitor Enterprise の Performance コンポーネントにおける任意のコマンドを実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-3506 2013-05-9 16:23 2013-03-7 Show GitHub Exploit DB Packet Storm
228388 4 警告 GroundWork - GroundWork Monitor Enterprise の Nagios-App コンポーネントにおけるアクセス制限を回避される脆弱性 CWE-255
証明書・パスワード管理
CVE-2013-3505 2013-05-9 16:22 2013-03-7 Show GitHub Exploit DB Packet Storm
228389 5.5 警告 GroundWork - GroundWork Monitor Enterprise の MONARCH コンポーネントにおけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2013-3504 2013-05-9 16:21 2013-03-7 Show GitHub Exploit DB Packet Storm
228390 3.5 注意 GroundWork - GroundWork Monitor Enterprise の MONARCH コンポーネントにおける任意のファイルを読まれる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-3503 2013-05-9 16:18 2013-03-7 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 20, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
319931 4.7 MEDIUM
Network
qnap qts
quts_hero
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands … CWE-78
OS Command 
CVE-2024-21906 2024-09-21 01:49 2024-09-7 Show GitHub Exploit DB Packet Storm
319932 9.8 CRITICAL
Network
playsms playsms A vulnerability classified as critical has been found in playSMS 1.4.4/1.4.5/1.4.6/1.4.7. Affected is an unknown function of the file /playsms/index.php?app=main&inc=core_auth&route=forgot&op=forgot … CWE-94
Code Injection
CVE-2024-8880 2024-09-21 01:41 2024-09-16 Show GitHub Exploit DB Packet Storm
319933 7.8 HIGH
Local
qnap qts
quts_hero
A missing authorization vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow local authenticated users to access data or perfo… CWE-862
 Missing Authorization
CVE-2023-39298 2024-09-21 01:39 2024-09-7 Show GitHub Exploit DB Packet Storm
319934 6.1 MEDIUM
Network
intumit smartrobot_firmware SmartRobot from INTUMIT does not properly validate a specific page parameter, allowing unautheticated remote attackers to inject JavaScript code to the parameter for Reflected Cross-site Scripting at… CWE-79
Cross-site Scripting
CVE-2024-8776 2024-09-21 01:38 2024-09-16 Show GitHub Exploit DB Packet Storm
319935 2.4 LOW
Adjacent
qnap qts
quts_hero
An improper restriction of excessive authentication attempts vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow local networ… CWE-307
mproper Restriction of Excessive Authentication Attempts
CVE-2024-32771 2024-09-21 01:38 2024-09-7 Show GitHub Exploit DB Packet Storm
319936 7.5 HIGH
Network
openjsf body-parser body-parser is Node.js body parsing middleware. body-parser <1.20.3 is vulnerable to denial of service when url encoding is enabled. A malicious actor using a specially crafted payload could flood th… NVD-CWE-noinfo
CVE-2024-45590 2024-09-21 01:26 2024-09-11 Show GitHub Exploit DB Packet Storm
319937 2.7 LOW
Network
fortinet fortiedrmanager An improper access control vulnerability [CWE-284] in FortiEDR Manager API 6.2.0 through 6.2.2, 6.0 all versions may allow in a shared environment context an authenticated admin with REST API permiss… NVD-CWE-Other
CVE-2024-45323 2024-09-21 01:23 2024-09-11 Show GitHub Exploit DB Packet Storm
319938 5.3 MEDIUM
Network
lizardbyte sunshine Sunshine is a self-hosted game stream host for Moonlight. Clients that experience a MITM attack during the pairing process may inadvertantly allow access to an unintended client rather than failing a… NVD-CWE-noinfo
CVE-2024-45407 2024-09-21 01:18 2024-09-11 Show GitHub Exploit DB Packet Storm
319939 4.7 MEDIUM
Network
openjsf express Express.js minimalist web framework for node. In express < 4.20.0, passing untrusted user input - even after sanitizing it - to response.redirect() may execute untrusted code. This issue is patched i… CWE-79
Cross-site Scripting
CVE-2024-43796 2024-09-21 01:07 2024-09-11 Show GitHub Exploit DB Packet Storm
319940 5.5 MEDIUM
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nfsd: fix nfsd4_deleg_getattr_conflict in presence of third party lease It is not safe to dereference fl->c.flc_owner without fir… NVD-CWE-noinfo
CVE-2024-46690 2024-09-21 00:55 2024-09-13 Show GitHub Exploit DB Packet Storm