Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 19, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228781 6.8 警告 IBM - IBM Tivoli Endpoint Manager の SUA アプリケーションにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2013-0452 2013-04-2 14:59 2013-03-20 Show GitHub Exploit DB Packet Storm
228782 5 警告 Digium - 複数の Asterisk 製品におけるサービス運用妨害 (デーモンクラッシュ) 状態にされる脆弱性 CWE-119
バッファエラー
CVE-2013-2686 2013-04-2 14:35 2013-03-27 Show GitHub Exploit DB Packet Storm
228783 7.5 危険 Digium - Asterisk Open Source の res/res_format_attr_h264.c におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2013-2685 2013-04-2 14:35 2013-03-27 Show GitHub Exploit DB Packet Storm
228784 5 警告 Digium - 複数の Asterisk 製品の SIP チャンネルドライバにおけるアカウント名を列挙される脆弱性 CWE-200
情報漏えい
CVE-2013-2264 2013-04-2 14:34 2013-02-21 Show GitHub Exploit DB Packet Storm
228785 7.5 危険 Synchroweb Technology - Synchroweb Technology SynConnect の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2013-2690 2013-04-2 14:03 2013-03-28 Show GitHub Exploit DB Packet Storm
228786 - - ヒューレット・パッカード - ** 削除 ** HP ProCurve 1700-8 および 1700-24 スイッチにおけるクロスサイトリクエストフォージェリの脆弱性 - CVE-2012-5216 2013-04-2 13:53 2013-03-25 Show GitHub Exploit DB Packet Storm
228787 4.3 警告 アップル
Google
- Google Chrome におけるクロスサイトスクリプティング攻撃を実行される脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-3058 2013-04-2 11:33 2012-03-28 Show GitHub Exploit DB Packet Storm
228788 4.3 警告 アルバネットワークス株式会社 - Mobility Controller で使用される Aruba Networks ArubaOS におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-2290 2013-04-1 20:54 2013-03-18 Show GitHub Exploit DB Packet Storm
228789 7.8 危険 シスコシステムズ - Cisco IOS の IP Service Level Agreement 機能におけるサービス運用妨害 (デバイスリロード) の脆弱性 CWE-119
バッファエラー
CVE-2013-1148 2013-04-1 20:47 2013-02-8 Show GitHub Exploit DB Packet Storm
228790 7.8 危険 シスコシステムズ - Cisco IOS の Protocol Translation (PT) 機能におけるサービス運用妨害 (デバイスリロード) の脆弱性 CWE-119
バッファエラー
CVE-2013-1147 2013-04-1 20:46 2013-03-27 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 20, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
207111 4.3 MEDIUM
Network
ibm api_connect IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions tr… CWE-352
 Origin Validation Error
CVE-2020-4827 2024-11-21 14:33 2021-02-5 Show GitHub Exploit DB Packet Storm
207112 4.3 MEDIUM
Network
ibm api_connect IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions tr… CWE-352
 Origin Validation Error
CVE-2020-4826 2024-11-21 14:33 2021-02-5 Show GitHub Exploit DB Packet Storm
207113 5.4 MEDIUM
Network
ibm api_connect IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI th… CWE-79
Cross-site Scripting
CVE-2020-4825 2024-11-21 14:33 2021-02-5 Show GitHub Exploit DB Packet Storm
207114 4.1 MEDIUM
Adjacent
ibm api_connect Certain IBM API Connect 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.13 configurations can result in sensitive information in the URL fragment identifiers. This information can be cached… CWE-200
Information Exposure
CVE-2020-4640 2024-11-21 14:33 2021-02-5 Show GitHub Exploit DB Packet Storm
207115 4.3 MEDIUM
Network
ibm content_navigator IBM Content Navigator 3.0.CD could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view … CWE-22
Path Traversal
CVE-2020-4934 2024-11-21 14:33 2021-02-3 Show GitHub Exploit DB Packet Storm
207116 8.8 HIGH
Network
ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.4.0 to 7.4.2 Patch 1 and 7.3.0 to 7.3.3 Patch 7 could allow a remote attacker to execute arbitrary commands on the system, caused by insecure deserialization of user-supplied conten… CWE-502
 Deserialization of Untrusted Data
CVE-2020-4888 2024-11-21 14:33 2021-01-28 Show GitHub Exploit DB Packet Storm
207117 9.8 CRITICAL
Network
ibm websphere_mq
mq
mq_appliance
IBM MQ 7.5, 8.0, 9.0, 9.1, 9.2 LTS, and 9.2 CD could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization of trusted data. An attacker could exploit th… CWE-502
 Deserialization of Untrusted Data
CVE-2020-4682 2024-11-21 14:33 2021-01-28 Show GitHub Exploit DB Packet Storm
207118 8.8 HIGH
Network
ibm security_guardium IBM Security Guardium 11.2 could allow an authenticated user to gain root access due to improper access control. IBM X-Force ID: 192028. NVD-CWE-noinfo
CVE-2020-4952 2024-11-21 14:33 2021-01-28 Show GitHub Exploit DB Packet Storm
207119 6.5 MEDIUM
Network
ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.4.2 GA to 7.4.2 Patch 1, 7.4.0 to 7.4.1 Patch 1, and 7.3.0 to 7.3.3 Patch 5 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-c… CWE-22
Path Traversal
CVE-2020-4789 2024-11-21 14:33 2021-01-28 Show GitHub Exploit DB Packet Storm
207120 2.3 LOW
Local
ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.4.2 GA to 7.4.2 Patch 1, 7.4.0 to 7.4.1 Patch 1, and 7.3.0 to 7.3.3 Patch 5 is vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send una… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2020-4787 2024-11-21 14:33 2021-01-28 Show GitHub Exploit DB Packet Storm