Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 4, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
249121 9.3 危険 マイクロソフト - Microsoft Internet Explorer における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2012-1523 2012-06-15 17:32 2012-06-12 Show GitHub Exploit DB Packet Storm
249122 9.3 危険 マイクロソフト - Microsoft Lync における権限昇格の脆弱性 CWE-Other
その他
CVE-2012-1849 2012-06-15 17:31 2012-06-12 Show GitHub Exploit DB Packet Storm
249123 9.3 危険 マイクロソフト - Microsoft .NET Framework における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2012-1855 2012-06-15 17:30 2012-06-12 Show GitHub Exploit DB Packet Storm
249124 4.3 警告 マイクロソフト - Microsoft Dynamics AX におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-1857 2012-06-15 17:29 2012-06-12 Show GitHub Exploit DB Packet Storm
249125 7.2 危険 マイクロソフト - Microsoft Windows のカーネルモードドライバ内の win32k.sys における権限昇格の脆弱性 CWE-20
不適切な入力確認
CVE-2012-1864 2012-06-15 17:23 2012-06-12 Show GitHub Exploit DB Packet Storm
249126 7.2 危険 マイクロソフト - Microsoft Windows のカーネルモードドライバ内の win32k.sys における権限昇格の脆弱性 CWE-20
不適切な入力確認
CVE-2012-1865 2012-06-15 17:22 2012-06-12 Show GitHub Exploit DB Packet Storm
249127 7.2 危険 マイクロソフト - Microsoft Windows のカーネルモードドライバ内の win32k.sys における権限昇格の脆弱性 CWE-20
不適切な入力確認
CVE-2012-1866 2012-06-15 16:39 2012-06-12 Show GitHub Exploit DB Packet Storm
249128 4.3 警告 ヒューレット・パッカード - HP Web Jetadmin におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-2011 2012-06-15 16:36 2012-05-31 Show GitHub Exploit DB Packet Storm
249129 7.2 危険 マイクロソフト - Microsoft Windows のカーネルモードドライバ内の win32k.sys における整数オーバーフローの脆弱性 CWE-399
リソース管理の問題
CVE-2012-1867 2012-06-15 16:36 2012-06-12 Show GitHub Exploit DB Packet Storm
249130 4.3 警告 シスコシステムズ - 複数の Cisco 製品の SIP の実装におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-2545 2012-06-15 16:35 2012-06-12 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 4, 2026, 4:17 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
210031 6.5 MEDIUM
Adjacent
hpe universal_api_framework A potential security vulnerability has been identified in Hewlett Packard Enterprise Universal API Framework. The vulnerability could be remotely exploited to allow SQL injection in HPE Universal API… CWE-89
SQL Injection
CVE-2020-24623 2024-11-21 14:15 2020-09-19 Show GitHub Exploit DB Packet Storm
210032 9.8 CRITICAL
Network
lemonldap-ng
debian
lemonldap\
debian_linux
An issue was discovered in LemonLDAP::NG through 2.0.8, when NGINX is used. An attacker may bypass URL-based access control to protected Virtual Hosts by submitting a non-normalized URI. This also af… CWE-425
 Direct Request ('Forced Browsing')
CVE-2020-24660 2024-11-21 14:15 2020-09-14 Show GitHub Exploit DB Packet Storm
210033 6.1 MEDIUM
Network
zulipchat zulip_desktop Zulip Desktop before 5.4.3 allows XSS because string escaping is mishandled during composition of the HTML for the user interface. CWE-79
Cross-site Scripting
CVE-2020-24582 2024-11-21 14:15 2020-09-11 Show GitHub Exploit DB Packet Storm
210034 6.5 MEDIUM
Network
idreamsoft icms A CSRF vulnerability was found in iCMS v7.0.0 in the background deletion administrator account. When missing the CSRF_TOKEN and can still request normally, all administrators except the initial admin… CWE-352
 Origin Validation Error
CVE-2020-24739 2024-11-21 14:15 2020-09-10 Show GitHub Exploit DB Packet Storm
210035 5.1 MEDIUM
Local
twilio authy_2-factor_authentication A race condition in the Twilio Authy 2-Factor Authentication application before 24.3.7 for Android allows a user to potentially approve/deny an access request prior to unlocking the application with … CWE-362
Race Condition
CVE-2020-24655 2024-11-21 14:15 2020-09-10 Show GitHub Exploit DB Packet Storm
210036 7.5 HIGH
Network
octopus octopus_deploy In Octopus Deploy 2020.3.x before 2020.3.4 and 2020.4.x before 2020.4.1, if an authenticated user creates a deployment or runbook process using Azure steps and sets the step's execution location to r… CWE-532
 Inclusion of Sensitive Information in Log Files
CVE-2020-24566 2024-11-21 14:15 2020-09-10 Show GitHub Exploit DB Packet Storm
210037 7.5 HIGH
Network
gnu
fedoraproject
opensuse
canonical
gnutls
fedora
leap
ubuntu_linux
An issue was discovered in GnuTLS before 3.6.15. A server can trigger a NULL pointer dereference in a TLS 1.3 client if a no_renegotiation alert is sent with unexpected timing, and then an invalid se… CWE-787
CWE-476
 Out-of-bounds Write
 NULL Pointer Dereference
CVE-2020-24659 2024-11-21 14:15 2020-09-5 Show GitHub Exploit DB Packet Storm
210038 3.3 LOW
Local
kde
canonical
debian
opensuse
fedoraproject
ark
ubuntu_linux
debian_linux
leap
fedora
In KDE Ark before 20.08.1, a crafted TAR archive with symlinks can install files outside the extraction directory, as demonstrated by a write operation to a user's home directory. CWE-59
Link Following
CVE-2020-24654 2024-11-21 14:15 2020-09-3 Show GitHub Exploit DB Packet Storm
210039 6.1 MEDIUM
Network
igniterealtime openfire A Reflected XSS vulnerability was discovered in Ignite Realtime Openfire version 4.5.1. The XSS vulnerability allows remote attackers to inject arbitrary web script or HTML via the GET request "searc… CWE-79
Cross-site Scripting
CVE-2020-24604 2024-11-21 14:15 2020-09-3 Show GitHub Exploit DB Packet Storm
210040 6.1 MEDIUM
Network
igniterealtime openfire Ignite Realtime Openfire 4.5.1 has a reflected Cross-site scripting vulnerability which allows an attacker to execute arbitrary malicious URL via the vulnerable GET parameter searchName", "searchValu… CWE-79
Cross-site Scripting
CVE-2020-24602 2024-11-21 14:15 2020-09-3 Show GitHub Exploit DB Packet Storm