Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 27, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
248991 6.4 警告 HTC Corporation - 複数の HTC の Android 上で動作する HTC IQRD サービスにおける SMS メッセージを送信される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-2217 2012-05-7 15:54 2012-05-1 Show GitHub Exploit DB Packet Storm
248992 2.1 注意 Mumble - Mumble における平文パスワードおよび設定データを取得される脆弱性 CWE-310
暗号の問題
CVE-2012-0863 2012-05-2 15:17 2012-04-30 Show GitHub Exploit DB Packet Storm
248993 6.5 警告 Digium - Asterisk Open Source および Asterisk Business Edition におけるサービス運用妨害 (デーモンクラッシュ) の脆弱性 CWE-119
バッファエラー
CVE-2012-2416 2012-05-2 15:14 2012-04-16 Show GitHub Exploit DB Packet Storm
248994 7.5 危険 Google - Google Chrome のプロセス間通信の実装におけるサンドボックスの制限を回避される脆弱性 CWE-362
競合状態
CVE-2011-3080 2012-05-2 14:00 2012-04-30 Show GitHub Exploit DB Packet Storm
248995 10 危険 Google - Google Chrome のプロセス間通信の実装における詳細不明な脆弱性 CWE-399
リソース管理の問題
CVE-2011-3079 2012-05-2 13:57 2012-04-30 Show GitHub Exploit DB Packet Storm
248996 8.5 危険 RuggedCom - RuggedCom の Rugged Operating System (ROS) におけるアクセス権限を取得される脆弱性 CWE-310
暗号の問題
CVE-2012-2441 2012-05-1 14:49 2012-04-27 Show GitHub Exploit DB Packet Storm
248997 7.5 危険 ネットギア - Netgear FVS318N の初期設定に問題 CWE-264
認可・権限・アクセス制御
CVE-2012-2439 2012-05-1 14:05 2012-04-3 Show GitHub Exploit DB Packet Storm
248998 7.5 危険 TP-LINK Technologies - TP-Link 8840T の初期設定に問題 CWE-264
認可・権限・アクセス制御
CVE-2012-2440 2012-05-1 12:21 2012-04-3 Show GitHub Exploit DB Packet Storm
248999 1.8 注意 Intuit - Intuit QuickBooks の intu-help-qb ハンドラにおけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2012-2425 2012-04-27 15:48 2012-04-25 Show GitHub Exploit DB Packet Storm
249000 1.8 注意 Intuit - Intuit QuickBooks の intu-help-qb ハンドラにおけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2012-2424 2012-04-27 15:47 2012-04-25 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 27, 2026, 4:52 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
198951 7.5 HIGH
Network
nextcloud nextcloud_server A wrong check in Nextcloud Server 19 and prior allowed to perform a denial of service attack when resetting the password for a user. CWE-400
 Uncontrolled Resource Consumption
CVE-2020-8295 2024-11-21 14:38 2021-01-27 Show GitHub Exploit DB Packet Storm
198952 6.5 MEDIUM
Network
nextcloud nextcloud_server A missing input validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows users to store unlimited data in workflow rules causing load and potential DDoS on later interactions and usage wi… CWE-400
 Uncontrolled Resource Consumption
CVE-2020-8293 2024-11-21 14:38 2021-01-27 Show GitHub Exploit DB Packet Storm
198953 5.4 MEDIUM
Network
rocket.chat rocket.chat Rocket.Chat server before 3.9.0 is vulnerable to a self cross-site scripting (XSS) vulnerability via the drag & drop functionality in message boxes. CWE-79
Cross-site Scripting
CVE-2020-8292 2024-11-21 14:38 2021-01-27 Show GitHub Exploit DB Packet Storm
198954 5.4 MEDIUM
Network
rocket.chat rocket.chat The `specializedRendering` function in Rocket.Chat server before 3.9.2 allows a cross-site scripting (XSS) vulnerability by way of the `value` parameter. CWE-79
Cross-site Scripting
CVE-2020-8288 2024-11-21 14:38 2021-01-27 Show GitHub Exploit DB Packet Storm
198955 6.5 MEDIUM
Network
nodejs
debian
fedoraproject
oracle
siemens
node.js
debian_linux
fedora
graalvm
sinec_infrastructure_network_services
Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 allow two copies of a header field in an HTTP request (for example, two Transfer-Encoding header fields). In this case, Node.js identifies th… CWE-444
HTTP Request Smuggling
CVE-2020-8287 2024-11-21 14:38 2021-01-7 Show GitHub Exploit DB Packet Storm
198956 5.4 MEDIUM
Network
nextcloud contacts A missing file type check in Nextcloud Contacts 3.3.0 allows a malicious user to upload malicious SVG files to perform cross-site scripting (XSS) attacks. CWE-79
Cross-site Scripting
CVE-2020-8281 2024-11-21 14:38 2021-01-7 Show GitHub Exploit DB Packet Storm
198957 5.4 MEDIUM
Network
nextcloud contacts A missing file type check in Nextcloud Contacts 3.4.0 allows a malicious user to upload SVG files as PNG files to perform cross-site scripting (XSS) attacks. CWE-79
Cross-site Scripting
CVE-2020-8280 2024-11-21 14:38 2021-01-7 Show GitHub Exploit DB Packet Storm
198958 4.3 MEDIUM
Network
citrix secure_mail Citrix Secure Mail for Android before 20.11.0 suffers from improper access control allowing unauthenticated access to read limited calendar related data stored within Secure Mail. Note that a malicio… CWE-269
 Improper Privilege Management
CVE-2020-8275 2024-11-21 14:38 2021-01-7 Show GitHub Exploit DB Packet Storm
198959 6.5 MEDIUM
Network
citrix secure_mail Citrix Secure Mail for Android before 20.11.0 suffers from Improper Control of Generation of Code ('Code Injection') by allowing unauthenticated access to read data stored within Secure Mail. Note th… CWE-94
Code Injection
CVE-2020-8274 2024-11-21 14:38 2021-01-7 Show GitHub Exploit DB Packet Storm
198960 6.1 MEDIUM
Network
rubyonrails rails In actionpack gem >= 6.0.0, a possible XSS vulnerability exists when an application is running in development mode allowing an attacker to send or embed (in another page) a specially crafted URL whic… CWE-79
Cross-site Scripting
CVE-2020-8264 2024-11-21 14:38 2021-01-7 Show GitHub Exploit DB Packet Storm