Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 30, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
248941 5 警告 インターネットイニシアティブ - SEIL シリーズにおけるアクセス制限不備の脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-2632 2012-06-6 12:01 2012-06-6 Show GitHub Exploit DB Packet Storm
248942 5 警告 WassUp - WordPress 用プラグイン WassUp におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-2633 2012-06-6 12:00 2012-06-6 Show GitHub Exploit DB Packet Storm
248943 4.3 警告 株式会社ウェブロジック - @WEBショッピングカートにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-2631 2012-06-5 12:01 2012-06-5 Show GitHub Exploit DB Packet Storm
248944 7.2 危険 VMware - VMware vMA における権限を取得される脆弱性 CWE-Other
その他
CVE-2012-2752 2012-06-5 10:59 2012-05-25 Show GitHub Exploit DB Packet Storm
248945 7.5 危険 DELL EMC (旧 EMC Corporation) - EMC AutoStart におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2012-0409 2012-06-5 10:58 2012-06-1 Show GitHub Exploit DB Packet Storm
248946 7.5 危険 Sympa - Sympa の投稿保管庫管理ページにおける任意の投稿保管庫を操作される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-2352 2012-06-4 14:27 2012-05-31 Show GitHub Exploit DB Packet Storm
248947 5 警告 Canonical - Ubuntu で使用される Update Manager におけるレポジトリ証明書を読まれる脆弱性 CWE-200
情報漏えい
CVE-2012-0949 2012-06-4 14:03 2012-05-31 Show GitHub Exploit DB Packet Storm
248948 10 危険 Mozilla Foundation - 複数の Mozilla 製品におけるサービス運用妨害 (DoS) の脆弱性 CWE-DesignError
CVE-2012-0444 2012-06-1 14:19 2012-01-31 Show GitHub Exploit DB Packet Storm
248949 7.8 危険 シスコシステムズ - Cisco ASR 9000 および CRS シリーズの Cisco IOS XR におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2012-2488 2012-06-1 14:14 2012-05-30 Show GitHub Exploit DB Packet Storm
248950 6.8 警告 TYPO3 Association - TYPO3 の fileDenyPattern 機能におけるアクセス制限を回避される脆弱性 CWE-20
不適切な入力確認
CVE-2010-5099 2012-06-1 13:50 2010-12-16 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 30, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
213141 5.5 MEDIUM
Local
rockcarry ffjpeg ffjpeg through 2020-02-24 has a heap-based buffer overflow in jfif_decode in jfif.c. CWE-787
 Out-of-bounds Write
CVE-2020-15470 2024-11-21 14:05 2020-07-1 Show GitHub Exploit DB Packet Storm
213142 9.8 CRITICAL
Network
persian_vip_download_script_project persian_vip_download_script Persian VIP Download Script 1.0 allows SQL Injection via the cart_edit.php active parameter. CWE-89
SQL Injection
CVE-2020-15468 2024-11-21 14:05 2020-07-1 Show GitHub Exploit DB Packet Storm
213143 6.1 MEDIUM
Network
nozominetworks guardian Nozomi Guardian before 19.0.4 allows attackers to achieve stored XSS (in the web front end) by leveraging the ability to create a custom field with a crafted field name. CWE-79
Cross-site Scripting
CVE-2020-15307 2024-11-21 14:05 2020-07-1 Show GitHub Exploit DB Packet Storm
213144 9.8 CRITICAL
Network
draytek vigor3900_firmware
vigor2960_firmware
vigor300b_firmware
On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution via shell metacharacters in a filename when the text/x-pytho… CWE-78
OS Command 
CVE-2020-15415 2024-11-21 14:05 2020-06-30 Show GitHub Exploit DB Packet Storm
213145 4.3 MEDIUM
Network
misp misp An issue was discovered in MISP 2.4.128. app/Controller/EventsController.php lacks an event ACL check before proceeding to allow a user to send an event contact form. CWE-862
 Missing Authorization
CVE-2020-15412 2024-11-21 14:05 2020-06-30 Show GitHub Exploit DB Packet Storm
213146 9.8 CRITICAL
Network
misp misp An issue was discovered in MISP 2.4.128. app/Controller/AttributesController.php has insufficient ACL checks in the attachment downloader. NVD-CWE-noinfo
CVE-2020-15411 2024-11-21 14:05 2020-06-30 Show GitHub Exploit DB Packet Storm
213147 4.4 MEDIUM
Local
iobit malware_fighter IOBit Malware Fighter Pro 8.0.2.547 allows local users to gain privileges for file deletion by manipulating malicious flagged file locations with an NTFS junction and an Object Manager symbolic link. CWE-59
Link Following
CVE-2020-15401 2024-11-21 14:05 2020-06-30 Show GitHub Exploit DB Packet Storm
213148 4.3 MEDIUM
Network
cakefoundation cakephp CakePHP before 4.0.6 mishandles CSRF token generation. This might be remotely exploitable in conjunction with XSS. CWE-352
CWE-79
 Origin Validation Error
Cross-site Scripting
CVE-2020-15400 2024-11-21 14:05 2020-06-30 Show GitHub Exploit DB Packet Storm
213149 7.8 HIGH
Local
hylafax\+_project
ifax
hylafax\+
hylafax_enterprise
HylaFAX+ through 7.0.2 and HylaFAX Enterprise have scripts that execute binaries from directories writable by unprivileged users (e.g., locations under /var/spool/hylafax that are writable by the uuc… CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2020-15397 2024-11-21 14:05 2020-06-30 Show GitHub Exploit DB Packet Storm
213150 7.8 HIGH
Local
hylafax\+_project
ifax
fedoraproject
opensuse
hylafax\+
hylafax_enterprise
fedora
leap
backports_sle
In HylaFAX+ through 7.0.2 and HylaFAX Enterprise, the faxsetup utility calls chown on files in user-owned directories. By winning a race, a local attacker could use this to escalate his privileges to… CWE-362
Race Condition
CVE-2020-15396 2024-11-21 14:05 2020-06-30 Show GitHub Exploit DB Packet Storm