Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 11, 2026, 12:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228691 5 警告 Drupal - Drupal における重要な情報を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-5651 2013-01-7 15:09 2012-12-19 Show GitHub Exploit DB Packet Storm
228692 5.1 警告 ELinks - ELinks の protocol/http/http_negotiate.c におけるクライアントとして認証される脆弱性 CWE-287
不適切な認証
CVE-2012-4545 2013-01-7 11:45 2012-10-28 Show GitHub Exploit DB Packet Storm
228693 5 警告 WP PHP widget - WordPress 用 WP PHP widget プラグインにおける重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2013-0721 2013-01-7 11:38 2013-01-2 Show GitHub Exploit DB Packet Storm
228694 5 警告 Charybdis
ircd-ratbox
- ircd-ratbox および Charybdis の modules/m_capab.c おけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2012-6084 2013-01-7 11:37 2012-12-31 Show GitHub Exploit DB Packet Storm
228695 5 警告 The Tor Project - Tor の or/relay.c におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2012-5573 2013-01-7 11:35 2012-06-28 Show GitHub Exploit DB Packet Storm
228696 7.5 危険 Fail2ban - Fail2ban の server/action.py における安全でない動作を誘発される脆弱性 CWE-noinfo
情報不足
CVE-2012-5642 2013-01-7 11:34 2012-12-6 Show GitHub Exploit DB Packet Storm
228697 4.3 警告 Polycom - Polycom HDX Video End Points におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-4970 2013-01-4 16:45 2012-12-31 Show GitHub Exploit DB Packet Storm
228698 3.3 注意 Belkin International - Belkin N900 ルータの WPA2 の実装における Wi-Fi ネットワークにアクセスされる脆弱性 CWE-310
暗号の問題
CVE-2012-6371 2013-01-4 16:44 2012-12-31 Show GitHub Exploit DB Packet Storm
228699 7.5 危険 LemonLDAP::NG - LemonLDAP::NG におけるアクセスコントロール制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-6426 2013-01-4 16:39 2012-12-18 Show GitHub Exploit DB Packet Storm
228700 5.8 警告 IBM - IBM SPSS Modeler における任意のファイルを読まれる脆弱性 CWE-Other
その他
CVE-2012-5769 2013-01-4 16:38 2012-12-28 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 11, 2026, 5:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
216331 7.3 HIGH
Network
basercms basercms baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) via arbitrary script execution. Admin access is required to exploit this vulnerability. The affected components are: content_field… CWE-79
Cross-site Scripting
CVE-2020-15154 2024-11-21 14:04 2020-08-29 Show GitHub Exploit DB Packet Storm
216332 9.1 CRITICAL
Network
chameleon_mini_live_debugger_project chameleon_mini_live_debugger Version 1.1.6-free of Chameleon Mini Live Debugger on Google Play Store may have had it's sources or permissions tampered by a malicious actor. The official maintainer of the package is recommending … - CVE-2020-15165 2024-11-21 14:04 2020-08-29 Show GitHub Exploit DB Packet Storm
216333 10.0 CRITICAL
Network
scratch-wiki scratch_login in Scratch Login (MediaWiki extension) before version 1.1, any account can be logged into by using the same username with leading, trailing, or repeated underscore(s), since those are treated as whit… CWE-74
Injection
CVE-2020-15164 2024-11-21 14:04 2020-08-29 Show GitHub Exploit DB Packet Storm
216334 8.1 HIGH
Network
nodebb blog_comments In nodebb-plugin-blog-comments before version 0.7.0, a logged in user is vulnerable to an XSS attack which could allow a third party to post on their behalf on the forum. This is due to lack of CSRF … - CVE-2020-15156 2024-11-21 14:04 2020-08-27 Show GitHub Exploit DB Packet Storm
216335 9.8 CRITICAL
Network
mz-automation libiec61850 In libIEC61850 before version 1.4.3, when a message with COTP message length field with value < 4 is received an integer underflow will happen leading to heap buffer overflow. This can cause an appli… CWE-191
 Integer Underflow (Wrap or Wraparound)
CVE-2020-15158 2024-11-21 14:04 2020-08-27 Show GitHub Exploit DB Packet Storm
216336 8.5 HIGH
Network
cogboard red_discord_bot Red Discord Bot before versions 3.3.12 and 3.4 has a Remote Code Execution vulnerability in the Streams module. This exploit allows Discord users with specifically crafted "going live" messages to in… CWE-74
Injection
CVE-2020-15147 2024-11-21 14:04 2020-08-22 Show GitHub Exploit DB Packet Storm
216337 9.6 CRITICAL
Network
cogboard red_discord_bot In Red Discord Bot before version 3.3.11, a RCE exploit has been discovered in the Trivia module: this exploit allows Discord users with specifically crafted usernames to inject code into the Trivia … CWE-74
Injection
CVE-2020-15140 2024-11-21 14:04 2020-08-22 Show GitHub Exploit DB Packet Storm
216338 8.8 HIGH
Network
zulip zulip_server Zulip Server 2.x before 2.1.7 allows eval injection if a privileged attacker were able to write directly to the postgres database, and chose to write a crafted custom profile field value. CWE-94
Code Injection
CVE-2020-15070 2024-11-21 14:04 2020-08-21 Show GitHub Exploit DB Packet Storm
216339 8.0 HIGH
Network
openmage
magento
openmage_long_term_support
magento
OpenMage LTS before versions 19.4.6 and 20.0.2 allows attackers to circumvent the `fromkey protection` in the Admin Interface and increases the attack surface for Cross Site Request Forgery attacks. … CWE-352
 Origin Validation Error
CVE-2020-15151 2024-11-21 14:04 2020-08-20 Show GitHub Exploit DB Packet Storm
216340 8.8 HIGH
Network
sylius syliusresourcebundle In SyliusResourceBundle before versions 1.3.14, 1.4.7, 1.5.2 and 1.6.4, request parameters injected inside an expression evaluated by `symfony/expression-language` package haven't been sanitized prop… CWE-917
 Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
CVE-2020-15146 2024-11-21 14:04 2020-08-20 Show GitHub Exploit DB Packet Storm