Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 1, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
249361 4.4 警告 Debian - Debian GNU/Linux 上で稼働する apache2 におけるクロスサイトスクリプティング (XSS) 攻撃を誘発される脆弱性 CWE-DesignError
CVE-2012-0216 2012-04-24 16:05 2012-04-15 Show GitHub Exploit DB Packet Storm
249362 4.3 警告 TeamPass - TeamPass の sources/users.queries.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-2234 2012-04-24 15:59 2012-04-22 Show GitHub Exploit DB Packet Storm
249363 4.3 警告 WordPress.org - WordPress の wp-comments-post.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-2404 2012-04-24 15:51 2012-04-21 Show GitHub Exploit DB Packet Storm
249364 4.3 警告 WordPress.org - WordPress の wp-includes/formatting.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-2403 2012-04-24 15:49 2012-04-21 Show GitHub Exploit DB Packet Storm
249365 5.5 警告 WordPress.org - WordPress の wp-admin/plugins.php におけるアクセス制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-2402 2012-04-24 15:43 2012-04-21 Show GitHub Exploit DB Packet Storm
249366 5 警告 WordPress.org
Moxiecode Systems
- WordPress および他の製品で使用される Plupload における同一生成元ポリシーを回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-2401 2012-04-24 15:35 2012-04-21 Show GitHub Exploit DB Packet Storm
249367 10 危険 WordPress.org - WordPress の wp-includes/js/swfobject.js における詳細不明な脆弱性 CWE-noinfo
情報不足
CVE-2012-2400 2012-04-24 15:27 2012-04-21 Show GitHub Exploit DB Packet Storm
249368 6.8 警告 ジャストシステム - 複数のジャストシステム製品における DLL 読み込みに関する脆弱性 CWE-Other
その他
CVE-2012-1242 2012-04-24 12:00 2012-04-24 Show GitHub Exploit DB Packet Storm
249369 5 警告 CA Technologies - Windows 上で稼働する CA ARCserve Backup におけるサービス運用妨害 (サービスシャットダウン) の脆弱性 CWE-20
不適切な入力確認
CVE-2012-1662 2012-04-23 15:35 2012-03-20 Show GitHub Exploit DB Packet Storm
249370 6.5 警告 Ryan Walberg - PHP Gift Registry の users.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2012-2236 2012-04-23 14:41 2012-04-20 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 2, 2026, 4:18 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
201021 5.7 MEDIUM
Network
openmicroscopy omero.web OMERO.web before 5.6.3 optionally allows sensitive data elements (e.g., a session key) to be passed as URL query parameters. If an attacker tricks a user into clicking a malicious link in OMERO.web, … CWE-200
Information Exposure
CVE-2020-7932 2024-11-21 14:38 2020-06-18 Show GitHub Exploit DB Packet Storm
201022 6.5 MEDIUM
Network
open-xchange open-xchange_appsuite OX App Suite through 7.10.3 allows XXE attacks. CWE-611
XXE
CVE-2020-8541 2024-11-21 14:38 2020-06-16 Show GitHub Exploit DB Packet Storm
201023 6.7 MEDIUM
Local
synaptics smart_audio_uwp An unquoted search path vulnerability was reported in versions prior to 1.0.83.0 of the Synaptics Smart Audio UWP app associated with the DCHU audio drivers on Lenovo platforms that could allow an ad… CWE-428
 Unquoted Search Path or Element
CVE-2020-8337 2024-11-21 14:38 2020-06-10 Show GitHub Exploit DB Packet Storm
201024 6.8 MEDIUM
Physics
lenovo thinkpad_e14_firmware
thinkpad_e15_firmware
thinkpad_r14_firmware
thinkpad_s3_gen_2_firmware
thinkpad_e490s_firmware
thinkpad_s3_firmware
thinkpad_e490_firmware
thinkpad_e590_fir…
Lenovo implemented Intel CSME Anti-rollback ARB protections on some ThinkPad models to prevent roll back of CSME Firmware in flash. NVD-CWE-noinfo
CVE-2020-8336 2024-11-21 14:38 2020-06-10 Show GitHub Exploit DB Packet Storm
201025 6.8 MEDIUM
Physics
lenovo thinkpad_t495s_firmware
thinkpad_x395_firmware
thinkpad_t495_firmware
thinkpad_a485_firmware
thinkpad_a285_firmware
thinkpad_a475_firmware
thinkpad_a275_firmware
The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T495s, X395, T495, A485, A285, A475, A275 which may allow for unauthorized access. CWE-754
 Improper Check for Unusual or Exceptional Conditions
CVE-2020-8334 2024-11-21 14:38 2020-06-10 Show GitHub Exploit DB Packet Storm
201026 6.7 MEDIUM
Local
lenovo 330-14ast_firmware
330-15ast_firmware
330-17ast_firmware
340c-15api_firmware
340c-15ast_firmware
720s_touch-15ikb_firmware
720s-15ikb_firmware
730s-13iwl_firmware
c640-iml_fir…
A potential vulnerability in the SMI callback function used in the Legacy SD driver in some Lenovo ThinkPad, ThinkStation, and Lenovo Notebook models may allow arbitrary code execution. NVD-CWE-noinfo
CVE-2020-8323 2024-11-21 14:38 2020-06-10 Show GitHub Exploit DB Packet Storm
201027 6.7 MEDIUM
Local
lenovo 330-14ast_firmware
330-15ast_firmware
330-17ast_firmware
340c-15api_firmware
340c-15ast_firmware
720s_touch-15ikb_firmware
720s-15ikb_firmware
730s-13iwl_firmware
c640-iml_fir…
A potential vulnerability in the SMI callback function used in the Legacy USB driver in some Lenovo Notebook and ThinkStation models may allow arbitrary code execution. NVD-CWE-noinfo
CVE-2020-8322 2024-11-21 14:38 2020-06-10 Show GitHub Exploit DB Packet Storm
201028 6.7 MEDIUM
Local
lenovo 130-14ast_firmware
130-14ikb_firmware
130-15ast_firmware
130-15ikb_firmware
320c-15ikb_firmware
330-14igm_firmware
330-14ikb_firmware
330-14ikbr_firmware
330-15arr_firmware
A potential vulnerability in the SMI callback function used in the System Lock Preinstallation driver in some Lenovo Notebook and ThinkStation models may allow arbitrary code execution. NVD-CWE-noinfo
CVE-2020-8321 2024-11-21 14:38 2020-06-10 Show GitHub Exploit DB Packet Storm
201029 6.8 MEDIUM
Physics
lenovo thinkpad_11e_yoga_gen_6_firmware
thinkpad_11e_firmware
thinkpad_yoga_11e_3rd_gen_firmware
thinkpad_yoga_11e_4th_gen_firmware
thinkpad_yoga_11e_5th_gen_firmware
thinkpad_13_2nd_gen_firm…
An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege. CWE-269
 Improper Privilege Management
CVE-2020-8320 2024-11-21 14:38 2020-06-10 Show GitHub Exploit DB Packet Storm
201030 9.9 CRITICAL
Network
nextcloud talk A too lax check in Nextcloud Talk 6.0.4, 7.0.2 and 8.0.7 allowed a code injection when a not correctly sanitized talk command was added by an administrator. CWE-94
Code Injection
CVE-2020-8180 2024-11-21 14:38 2020-06-8 Show GitHub Exploit DB Packet Storm