Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 26, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
248671 4.3 警告 NetWebLogic - WordPress 用 Login With Ajax プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-2759 2012-05-24 13:38 2012-05-22 Show GitHub Exploit DB Packet Storm
248672 4.3 警告 Schneider Electric - Schneider Electric Kerweb および Kerwin におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-1990 2012-05-24 12:32 2012-05-22 Show GitHub Exploit DB Packet Storm
248673 7.5 危険 Thomas Abeel - Simple PHP Agenda の engine.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2012-2925 2012-05-23 19:35 2012-05-21 Show GitHub Exploit DB Packet Storm
248674 7.5 危険 HyperMethod IBS - Hypermethod eLearning Server の admin/setup.inc.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2012-2924 2012-05-23 19:35 2012-05-21 Show GitHub Exploit DB Packet Storm
248675 7.5 危険 HyperMethod IBS - Hypermethod eLearning Server の news.php4 における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2012-2923 2012-05-23 19:34 2012-05-21 Show GitHub Exploit DB Packet Storm
248676 5 警告 Drupal - Drupal の includes/bootstrap.inc 内の request_path 関数における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2012-2922 2012-05-23 19:33 2012-05-21 Show GitHub Exploit DB Packet Storm
248677 3.5 注意 Geoff Davies - Drupal 用 Contact Forms モジュールにおけるモジュールの設定を変更される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-2340 2012-05-23 19:12 2012-05-21 Show GitHub Exploit DB Packet Storm
248678 4.3 警告 Nancy Wichmann - Drupal 用 Glossary モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-2339 2012-05-23 19:00 2012-05-21 Show GitHub Exploit DB Packet Storm
248679 2.6 注意 Ishmael Sanchez - Drupal 用 Aberdeen テーマの aberdeen_breadcrumb 関数におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-2907 2012-05-23 18:57 2012-05-21 Show GitHub Exploit DB Packet Storm
248680 5 警告 mark pilgrim - Universal Feed Parser におけるサービス運用妨害 (メモリ消費) の脆弱性 CWE-399
リソース管理の問題
CVE-2012-2921 2012-05-23 18:50 2012-05-2 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 26, 2026, 4:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
211861 6.5 MEDIUM
Network
hcltechsw onetest_performance HCL OneTest Performance V9.5, V10.0, V10.1 contains an inadequate session timeout, which could allow an attacker time to guess and use a valid session ID. CWE-613
 Insufficient Session Expiration
CVE-2020-14247 2024-11-21 14:02 2021-02-4 Show GitHub Exploit DB Packet Storm
211862 7.5 HIGH
Network
hcltechsw onetest_performance HCL OneTest Performance V9.5, V10.0, V10.1 uses basic authentication which is relatively weak. An attacker could potentially decode the encoded credentials. CWE-327
 Use of a Broken or Risky Cryptographic Algorithm
CVE-2020-14246 2024-11-21 14:02 2021-02-4 Show GitHub Exploit DB Packet Storm
211863 9.8 CRITICAL
Network
hcltechsw onetest_performance HCL OneTest UI V9.5, V10.0, and V10.1 does not perform authentication for functionality that either requires a provable user identity or consumes a significant amount of resources. CWE-306
Missing Authentication for Critical Function
CVE-2020-14245 2024-11-21 14:02 2021-02-4 Show GitHub Exploit DB Packet Storm
211864 7.5 HIGH
Network
hcltech digital_experience HCL Digital Experience 9.5 containers include vulnerabilities that could expose sensitive data to unauthorized parties via crafted requests. These affect containers only. These do not affect traditio… NVD-CWE-noinfo
CVE-2020-14255 2024-11-21 14:02 2021-02-3 Show GitHub Exploit DB Packet Storm
211865 4.9 MEDIUM
Network
hcltech digital_experience HCL Digital Experience 8.5, 9.0, and 9.5 exposes information about the server to unauthorized users. NVD-CWE-noinfo
CVE-2020-14221 2024-11-21 14:02 2021-02-3 Show GitHub Exploit DB Packet Storm
211866 4.3 MEDIUM
Network
atlassian crucible
fisheye
Affected versions of Atlassian Fisheye and Crucible allow remote attackers to view a product's SEN via an Information Disclosure vulnerability in the x-asen response header from Atlassian Analytics. … CWE-200
Information Exposure
CVE-2020-14192 2024-11-21 14:02 2021-02-2 Show GitHub Exploit DB Packet Storm
211867 7.5 HIGH
Network
mofinetwork mofi4500-4gxelte_firmware An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. The one-time password algorithm for the undocumented system account mofidev generates a predictable six-digit password. CWE-330
 Use of Insufficiently Random Values
CVE-2020-13860 2024-11-21 14:02 2021-02-1 Show GitHub Exploit DB Packet Storm
211868 9.8 CRITICAL
Network
mofinetwork mofi4500-4gxelte_firmware An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. A format error in /etc/shadow, coupled with a logic bug in the LuCI - OpenWrt Configuration Interface framework, allows the… CWE-287
CWE-755
Improper Authentication
 Improper Handling of Exceptional Conditions
CVE-2020-13859 2024-11-21 14:02 2021-02-1 Show GitHub Exploit DB Packet Storm
211869 9.8 CRITICAL
Network
mofinetwork mofi4500-4gxelte_firmware An issue was discovered on Mofi Network MOFI4500-4GXeLTE 3.6.1-std and 4.0.8-std devices. They contain two undocumented administrator accounts. The sftp and mofidev accounts are defined in /etc/passw… CWE-798
 Use of Hard-coded Credentials
CVE-2020-13858 2024-11-21 14:02 2021-02-1 Show GitHub Exploit DB Packet Storm
211870 7.5 HIGH
Network
mofinetwork mofi4500-4gxelte_firmware An issue was discovered on Mofi Network MOFI4500-4GXeLTE 3.6.1-std and 4.0.8-std devices. They can be rebooted by sending an unauthenticated poof.cgi HTTP GET request. NVD-CWE-noinfo
CVE-2020-13857 2024-11-21 14:02 2021-02-1 Show GitHub Exploit DB Packet Storm