Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 26, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
248661 7.2 危険 シマンテック - Symantec Endpoint Protection および Symantec Network Access Control におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2012-0289 2012-05-25 12:17 2012-05-22 Show GitHub Exploit DB Packet Storm
248662 7.5 危険 ロジテック株式会社 - LAN-W300N/R シリーズにおけるアクセス制限不備の脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-1250 2012-05-25 12:04 2012-05-25 Show GitHub Exploit DB Packet Storm
248663 4.3 警告 Roundcube.net - Roundcube Webmail において任意のスクリプトが実行される脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-1253 2012-05-25 12:03 2012-05-25 Show GitHub Exploit DB Packet Storm
248664 4.3 警告 サイベース - Sybase 製 EAServer におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-4340 2012-05-25 12:02 2012-05-25 Show GitHub Exploit DB Packet Storm
248665 4.3 警告 RSSOwl - RSSOwl において任意のスクリプトが実行される脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-1252 2012-05-25 12:01 2012-05-25 Show GitHub Exploit DB Packet Storm
248666 7.5 危険 SIRINI.NET - GR Board における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2011-5091 2012-05-25 11:53 2012-05-24 Show GitHub Exploit DB Packet Storm
248667 6.4 警告 SIRINI.NET - GR Board におけるデータを変更または削除される脆弱性 CWE-287
不適切な認証
CVE-2011-5090 2012-05-25 11:52 2012-05-24 Show GitHub Exploit DB Packet Storm
248668 5 警告 Tornado - Tornado の tornado.web.RequestHandler.set_header 関数における CRLF インジェクションの脆弱性 CWE-20
不適切な入力確認
CVE-2012-2374 2012-05-25 11:26 2012-05-23 Show GitHub Exploit DB Packet Storm
248669 6.4 警告 Gliffy - Atlassian JIRA および Atlassian Confluence 用 Gliffy プラグインにおける任意のファイルを読まれる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-2928 2012-05-24 13:42 2012-05-22 Show GitHub Exploit DB Packet Storm
248670 4 警告 TM Software - Atlassian JIRA 用 TM Software Tempo プラグインにおけるサービス運用妨害 (リソース消費)の脆弱性 CWE-399
リソース管理の問題
CVE-2012-2927 2012-05-24 13:41 2012-05-22 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 26, 2026, 4:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
211861 6.5 MEDIUM
Network
hcltechsw onetest_performance HCL OneTest Performance V9.5, V10.0, V10.1 contains an inadequate session timeout, which could allow an attacker time to guess and use a valid session ID. CWE-613
 Insufficient Session Expiration
CVE-2020-14247 2024-11-21 14:02 2021-02-4 Show GitHub Exploit DB Packet Storm
211862 7.5 HIGH
Network
hcltechsw onetest_performance HCL OneTest Performance V9.5, V10.0, V10.1 uses basic authentication which is relatively weak. An attacker could potentially decode the encoded credentials. CWE-327
 Use of a Broken or Risky Cryptographic Algorithm
CVE-2020-14246 2024-11-21 14:02 2021-02-4 Show GitHub Exploit DB Packet Storm
211863 9.8 CRITICAL
Network
hcltechsw onetest_performance HCL OneTest UI V9.5, V10.0, and V10.1 does not perform authentication for functionality that either requires a provable user identity or consumes a significant amount of resources. CWE-306
Missing Authentication for Critical Function
CVE-2020-14245 2024-11-21 14:02 2021-02-4 Show GitHub Exploit DB Packet Storm
211864 7.5 HIGH
Network
hcltech digital_experience HCL Digital Experience 9.5 containers include vulnerabilities that could expose sensitive data to unauthorized parties via crafted requests. These affect containers only. These do not affect traditio… NVD-CWE-noinfo
CVE-2020-14255 2024-11-21 14:02 2021-02-3 Show GitHub Exploit DB Packet Storm
211865 4.9 MEDIUM
Network
hcltech digital_experience HCL Digital Experience 8.5, 9.0, and 9.5 exposes information about the server to unauthorized users. NVD-CWE-noinfo
CVE-2020-14221 2024-11-21 14:02 2021-02-3 Show GitHub Exploit DB Packet Storm
211866 4.3 MEDIUM
Network
atlassian crucible
fisheye
Affected versions of Atlassian Fisheye and Crucible allow remote attackers to view a product's SEN via an Information Disclosure vulnerability in the x-asen response header from Atlassian Analytics. … CWE-200
Information Exposure
CVE-2020-14192 2024-11-21 14:02 2021-02-2 Show GitHub Exploit DB Packet Storm
211867 7.5 HIGH
Network
mofinetwork mofi4500-4gxelte_firmware An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. The one-time password algorithm for the undocumented system account mofidev generates a predictable six-digit password. CWE-330
 Use of Insufficiently Random Values
CVE-2020-13860 2024-11-21 14:02 2021-02-1 Show GitHub Exploit DB Packet Storm
211868 9.8 CRITICAL
Network
mofinetwork mofi4500-4gxelte_firmware An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. A format error in /etc/shadow, coupled with a logic bug in the LuCI - OpenWrt Configuration Interface framework, allows the… CWE-287
CWE-755
Improper Authentication
 Improper Handling of Exceptional Conditions
CVE-2020-13859 2024-11-21 14:02 2021-02-1 Show GitHub Exploit DB Packet Storm
211869 9.8 CRITICAL
Network
mofinetwork mofi4500-4gxelte_firmware An issue was discovered on Mofi Network MOFI4500-4GXeLTE 3.6.1-std and 4.0.8-std devices. They contain two undocumented administrator accounts. The sftp and mofidev accounts are defined in /etc/passw… CWE-798
 Use of Hard-coded Credentials
CVE-2020-13858 2024-11-21 14:02 2021-02-1 Show GitHub Exploit DB Packet Storm
211870 7.5 HIGH
Network
mofinetwork mofi4500-4gxelte_firmware An issue was discovered on Mofi Network MOFI4500-4GXeLTE 3.6.1-std and 4.0.8-std devices. They can be rebooted by sending an unauthenticated poof.cgi HTTP GET request. NVD-CWE-noinfo
CVE-2020-13857 2024-11-21 14:02 2021-02-1 Show GitHub Exploit DB Packet Storm