Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 21, 2026, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
249201 3.5 注意 ヒューレット・パッカード - HP OpenView Performance Insight におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-2406 2012-03-27 18:43 2011-08-8 Show GitHub Exploit DB Packet Storm
249202 7.8 危険 ヒューレット・パッカード - HP ProLiant SL-APM におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2011-2405 2012-03-27 18:43 2011-08-9 Show GitHub Exploit DB Packet Storm
249203 7.5 危険 ヒューレット・パッカード - HP Easy Printer Care Software の特定の ActiveX コントロールにおけるクライアントマシンで任意のプログラムを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2011-2404 2012-03-27 18:43 2011-08-8 Show GitHub Exploit DB Packet Storm
249204 6.5 警告 ヒューレット・パッカード - HP Network Automation における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2011-2403 2012-03-27 18:43 2011-07-28 Show GitHub Exploit DB Packet Storm
249205 4.3 警告 ヒューレット・パッカード - HP Network Automation におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-2402 2012-03-27 18:43 2011-07-28 Show GitHub Exploit DB Packet Storm
249206 8.3 危険 ヒューレット・パッカード - HP SiteScope におけるセッションをハイジャックされる脆弱性 CWE-Other
その他
CVE-2011-2401 2012-03-27 18:43 2011-07-27 Show GitHub Exploit DB Packet Storm
249207 4.3 警告 ヒューレット・パッカード - HP SiteScope におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-2400 2012-03-27 18:43 2011-07-27 Show GitHub Exploit DB Packet Storm
249208 7.8 危険 ヒューレット・パッカード - HP Data Protector の mmd におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2011-2399 2012-03-27 18:43 2011-07-27 Show GitHub Exploit DB Packet Storm
249209 9.3 危険 visiwave - VisiWave Site Survey の VisiWaveReport.exe における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2011-2386 2012-03-27 18:43 2011-05-20 Show GitHub Exploit DB Packet Storm
249210 6.5 警告 OTRS プロジェクト - OTRS の iPhoneHandle パッケージにおける権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2011-2385 2012-03-27 18:43 2011-07-19 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 21, 2026, 4:10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
212701 8.8 HIGH
Network
pepperl-fuchs io-link_master_4-eip_firmware
io-link_master_8-eip_firmware
io-link_master_8-eip-l_firmware
io-link_master_dr-8-eip_firmware
io-link_master_dr-8-eip-p_firmware
io-link_master_dr-8-eip-…
Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated blind OS Command Injection. CWE-78
OS Command 
CVE-2020-12513 2024-11-21 13:59 2021-01-23 Show GitHub Exploit DB Packet Storm
212702 5.4 MEDIUM
Network
pepperl-fuchs io-link_master_4-eip_firmware
io-link_master_8-eip_firmware
io-link_master_8-eip-l_firmware
io-link_master_dr-8-eip_firmware
io-link_master_dr-8-eip-p_firmware
io-link_master_dr-8-eip-…
Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated reflected POST Cross-Site Scripting CWE-79
Cross-site Scripting
CVE-2020-12512 2024-11-21 13:59 2021-01-23 Show GitHub Exploit DB Packet Storm
212703 8.8 HIGH
Network
pepperl-fuchs io-link_master_4-eip_firmware
io-link_master_8-eip_firmware
io-link_master_8-eip-l_firmware
io-link_master_dr-8-eip_firmware
io-link_master_dr-8-eip-p_firmware
io-link_master_dr-8-eip-…
Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to a Cross-Site Request Forgery (CSRF) in the web interface. CWE-352
 Origin Validation Error
CVE-2020-12511 2024-11-21 13:59 2021-01-23 Show GitHub Exploit DB Packet Storm
212704 4.3 MEDIUM
Network
apache guacamole Apache Guacamole 1.2.0 and earlier do not consistently restrict access to connection history based on user visibility. If multiple users share access to the same connection, those users may be able t… CWE-276
Incorrect Default Permissions 
CVE-2020-11997 2024-11-21 13:59 2021-01-20 Show GitHub Exploit DB Packet Storm
212705 9.8 CRITICAL
Network
apache dubbo A deserialization vulnerability existed in dubbo 2.7.5 and its earlier versions, which could lead to malicious code execution. Most Dubbo users use Hessian2 as the default serialization/deserializati… CWE-502
 Deserialization of Untrusted Data
CVE-2020-11995 2024-11-21 13:59 2021-01-11 Show GitHub Exploit DB Packet Storm
212706 9.8 CRITICAL
Network
apache dolphinscheduler In DolphinScheduler 1.2.0 and 1.2.1, with mysql connectorj a remote code execution vulnerability exists when choosing mysql as database. NVD-CWE-noinfo
CVE-2020-11974 2024-11-21 13:59 2020-12-19 Show GitHub Exploit DB Packet Storm
212707 6.5 MEDIUM
Adjacent
phoenixcontact plcnext_firmware On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS a specially crafted LLDP packet may lead to a high system load in the PROFINET stack. An attacker can cause failure of system ser… CWE-20
 Improper Input Validation 
CVE-2020-12521 2024-11-21 13:59 2020-12-18 Show GitHub Exploit DB Packet Storm
212708 9.8 CRITICAL
Network
phoenixcontact plcnext_firmware On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an attacker can use this vulnerability i.e. to open a reverse shell with root privileges. CWE-269
 Improper Privilege Management
CVE-2020-12519 2024-11-21 13:59 2020-12-18 Show GitHub Exploit DB Packet Storm
212709 5.5 MEDIUM
Local
phoenixcontact plcnext_firmware On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an attacker can use the knowledge gained by reading the insufficiently protected sensitive information to plan further attacks. CWE-200
Information Exposure
CVE-2020-12518 2024-11-21 13:59 2020-12-18 Show GitHub Exploit DB Packet Storm
212710 9.0 CRITICAL
Network
phoenixcontact plcnext_firmware On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an authenticated low privileged user could embed malicious Javascript code to gain admin rights when the admin user visits the vu… CWE-79
Cross-site Scripting
CVE-2020-12517 2024-11-21 13:59 2020-12-18 Show GitHub Exploit DB Packet Storm