Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 1, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
248951 2.6 注意 株式会社バンダイナムコゲームス - 魔法少女まどか☆マギカ iP for Android における情報漏えいの脆弱性 CWE-200
情報漏えい
CVE-2012-2630 2012-06-1 12:04 2012-06-1 Show GitHub Exploit DB Packet Storm
248952 7.5 危険 Segue Project - Segue における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2012-1255 2012-06-1 12:03 2012-06-1 Show GitHub Exploit DB Packet Storm
248953 4.3 警告 Segue Project - Segue におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-1254 2012-06-1 12:02 2012-06-1 Show GitHub Exploit DB Packet Storm
248954 7.5 危険 Jaow - Jaow の add_ons.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2012-2952 2012-05-31 14:52 2012-05-29 Show GitHub Exploit DB Packet Storm
248955 7.5 危険 Plogger Project - Plogger の plog-rss.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2012-2951 2012-05-31 14:52 2012-05-29 Show GitHub Exploit DB Packet Storm
248956 3.3 注意 Puppet - Puppet および Puppet Enterprise における任意のファイルを上書きされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-1906 2012-05-31 14:25 2012-05-29 Show GitHub Exploit DB Packet Storm
248957 4.3 警告 ikiwiki - ikiwiki のメタプラグイン (Plugin/meta.pm) におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-0220 2012-05-31 14:15 2012-05-29 Show GitHub Exploit DB Packet Storm
248958 10 危険 ZTE - ZTE Score M デバイス上の Android 用 ZTE sync_agent プログラムにおける権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-2949 2012-05-31 14:11 2012-05-29 Show GitHub Exploit DB Packet Storm
248959 6.5 警告 Pligg - Pligg CMS の captcha モジュールにおけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2012-2435 2012-05-30 11:22 2012-05-27 Show GitHub Exploit DB Packet Storm
248960 1.2 注意 ヒューレット・パッカード - HP Linux Imaging and Printing の send_data_to_stdout 関数における任意のファイルを上書される脆弱性 CWE-59
リンク解釈の問題
CVE-2011-2722 2012-05-29 16:10 2012-05-25 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 1, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
212871 7.8 HIGH
Local
openbsd
netapp
broadcom
openssh
a700s_firmware
steelstore_cloud_integrated_storage
active_iq_unified_manager
solidfire
hci_management_node
hci_storage_node
hci_compute_node
fabric_operating_system
scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that t… CWE-78
OS Command 
CVE-2020-15778 2024-11-21 14:06 2020-07-24 Show GitHub Exploit DB Packet Storm
212872 7.5 HIGH
Network
midasolutions eframework There is a SQL Injection in Mida eFramework through 2.9.0 that leads to Information Disclosure. No authentication is required. The injection point resides in one of the authentication parameters. CWE-89
SQL Injection
CVE-2020-15924 2024-11-21 14:06 2020-07-24 Show GitHub Exploit DB Packet Storm
212873 7.5 HIGH
Network
midasolutions eframework Mida eFramework through 2.9.0 allows unauthenticated ../ directory traversal. CWE-22
Path Traversal
CVE-2020-15923 2024-11-21 14:06 2020-07-24 Show GitHub Exploit DB Packet Storm
212874 9.8 CRITICAL
Network
midasolutions eframework There is an OS Command Injection in Mida eFramework 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) privileges. Authentication is required. CWE-78
OS Command 
CVE-2020-15922 2024-11-21 14:06 2020-07-24 Show GitHub Exploit DB Packet Storm
212875 9.8 CRITICAL
Network
midasolutions eframework Mida eFramework through 2.9.0 has a back door that permits a change of the administrative password and access to restricted functionalities, such as Code Execution. CWE-287
Improper Authentication
CVE-2020-15921 2024-11-21 14:06 2020-07-24 Show GitHub Exploit DB Packet Storm
212876 9.8 CRITICAL
Network
midasolutions eframework There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) privileges. No authentication is required. CWE-78
OS Command 
CVE-2020-15920 2024-11-21 14:06 2020-07-24 Show GitHub Exploit DB Packet Storm
212877 6.1 MEDIUM
Network
midasolutions eframework A Reflected Cross Site Scripting (XSS) vulnerability was discovered in Mida eFramework through 2.9.0. CWE-79
Cross-site Scripting
CVE-2020-15919 2024-11-21 14:06 2020-07-24 Show GitHub Exploit DB Packet Storm
212878 5.4 MEDIUM
Network
midasolutions eframework Multiple Stored Cross Site Scripting (XSS) vulnerabilities were discovered in Mida eFramework through 2.9.0. CWE-79
Cross-site Scripting
CVE-2020-15918 2024-11-21 14:06 2020-07-24 Show GitHub Exploit DB Packet Storm
212879 9.8 CRITICAL
Network
claws-mail
fedoraproject
opensuse
claws-mail
fedora
leap
backports_sle
common/session.c in Claws Mail before 3.17.6 has a protocol violation because suffix data after STARTTLS is mishandled. NVD-CWE-noinfo
CVE-2020-15917 2024-11-21 14:06 2020-07-24 Show GitHub Exploit DB Packet Storm
212880 9.8 CRITICAL
Network
tenda ac15_firmware goform/AdvSetLanip endpoint on Tenda AC15 AC1900 15.03.05.19 devices allows remote attackers to execute arbitrary system commands via shell metacharacters in the lanIp POST parameter. CWE-78
OS Command 
CVE-2020-15916 2024-11-21 14:06 2020-07-24 Show GitHub Exploit DB Packet Storm