Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 6, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
249481 4.3 警告 NetWebLogic - WordPress 用 Login With Ajax プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-2759 2012-05-24 13:38 2012-05-22 Show GitHub Exploit DB Packet Storm
249482 4.3 警告 Schneider Electric - Schneider Electric Kerweb および Kerwin におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-1990 2012-05-24 12:32 2012-05-22 Show GitHub Exploit DB Packet Storm
249483 7.5 危険 Thomas Abeel - Simple PHP Agenda の engine.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2012-2925 2012-05-23 19:35 2012-05-21 Show GitHub Exploit DB Packet Storm
249484 7.5 危険 HyperMethod IBS - Hypermethod eLearning Server の admin/setup.inc.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2012-2924 2012-05-23 19:35 2012-05-21 Show GitHub Exploit DB Packet Storm
249485 7.5 危険 HyperMethod IBS - Hypermethod eLearning Server の news.php4 における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2012-2923 2012-05-23 19:34 2012-05-21 Show GitHub Exploit DB Packet Storm
249486 5 警告 Drupal - Drupal の includes/bootstrap.inc 内の request_path 関数における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2012-2922 2012-05-23 19:33 2012-05-21 Show GitHub Exploit DB Packet Storm
249487 3.5 注意 Geoff Davies - Drupal 用 Contact Forms モジュールにおけるモジュールの設定を変更される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-2340 2012-05-23 19:12 2012-05-21 Show GitHub Exploit DB Packet Storm
249488 4.3 警告 Nancy Wichmann - Drupal 用 Glossary モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-2339 2012-05-23 19:00 2012-05-21 Show GitHub Exploit DB Packet Storm
249489 2.6 注意 Ishmael Sanchez - Drupal 用 Aberdeen テーマの aberdeen_breadcrumb 関数におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-2907 2012-05-23 18:57 2012-05-21 Show GitHub Exploit DB Packet Storm
249490 5 警告 mark pilgrim - Universal Feed Parser におけるサービス運用妨害 (メモリ消費) の脆弱性 CWE-399
リソース管理の問題
CVE-2012-2921 2012-05-23 18:50 2012-05-2 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 6, 2026, 4:18 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
201351 6.7 MEDIUM
Local
huawei taurus-an00b_firmware Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2) have an insufficient input validation vulnerability. Due to the input validation logic is incorrect, an attacker can exploit this vulnerabil… CWE-20
 Improper Input Validation 
CVE-2020-9105 2024-11-21 14:40 2020-10-9 Show GitHub Exploit DB Packet Storm
201352 7.5 HIGH
Network
apache nifi In Apache NiFi 1.2.0 to 1.11.4, the NiFi UI and API were protected by mandating TLS v1.2, as well as listening connections established by processors like ListenHTTP, HandleHttpRequest, etc. However i… CWE-327
 Use of a Broken or Risky Cryptographic Algorithm
CVE-2020-9491 2024-11-21 14:40 2020-10-2 Show GitHub Exploit DB Packet Storm
201353 7.5 HIGH
Network
apache nifi In Apache NiFi 1.0.0 to 1.11.4, the NiFi download token (one-time password) mechanism used a fixed cache size and did not authenticate a request to create a download token, only when attempting to us… CWE-306
Missing Authentication for Critical Function
CVE-2020-9487 2024-11-21 14:40 2020-10-2 Show GitHub Exploit DB Packet Storm
201354 7.5 HIGH
Network
apache nifi In Apache NiFi 1.10.0 to 1.11.4, the NiFi stateless execution engine produced log output which included sensitive property values. When a flow was triggered, the flow definition configuration JSON wa… CWE-532
 Inclusion of Sensitive Information in Log Files
CVE-2020-9486 2024-11-21 14:40 2020-10-2 Show GitHub Exploit DB Packet Storm
201355 5.4 MEDIUM
Network
tibco spotfire_server
spotfire_desktop
spotfire_analytics_platform
spotfire_analyst
The Spotfire client component of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Desktop, and TIBCO Spotfire Server contains a vuln… CWE-79
Cross-site Scripting
CVE-2020-9416 2024-11-21 14:40 2020-09-16 Show GitHub Exploit DB Packet Storm
201356 5.5 MEDIUM
Local
huawei bla-a09_firmware
bla-tl00b_firmware
berkeley-l09_firmware
duke-l09_firmware
p20_firmware
p20_pro_firmware
jimmy-al00a_firmware
lon-l29d_firmware
neo-al00d_firmware
stanford…
Huawei smartphones BLA-A09 versions 8.0.0.123(C212),versions earlier than 8.0.0.123(C567),versions earlier than 8.0.0.123(C797);BLA-TL00B versions earlier than 8.1.0.326(C01);Berkeley-L09 versions ea… CWE-20
 Improper Input Validation 
CVE-2020-9239 2024-11-21 14:40 2020-09-11 Show GitHub Exploit DB Packet Storm
201357 6.8 MEDIUM
Adjacent
huawei b2368-22_firmware
b2368-57_firmware
b2368-66_firmware
B2368-22 V100R001C00;B2368-57 V100R001C00;B2368-66 V100R001C00 have a command injection vulnerability. An attacker with high privileges may exploit this vulnerability through some operations on the L… CWE-77
Command Injection
CVE-2020-9199 2024-11-21 14:40 2020-09-4 Show GitHub Exploit DB Packet Storm
201358 5.5 MEDIUM
Local
huawei honor_20_pro_firmware
honor_view_20_firmware
oxfords-an00a_firmware
princeton-al10b_firmware
princeton-al10d_firmware
princeton-tl10c_firmware
tony-al00b_firmware
yale-al00a_firm…
Huawei smartphones HONOR 20 PRO Versions earlier than 10.1.0.230(C432E9R5P1),Versions earlier than 10.1.0.231(C10E3R3P2),Versions earlier than 10.1.0.231(C185E3R5P1),Versions earlier than 10.1.0.231(… CWE-20
 Improper Input Validation 
CVE-2020-9235 2024-11-21 14:40 2020-09-4 Show GitHub Exploit DB Packet Storm
201359 7.5 HIGH
Network
spinnaker orca The Spinnaker template resolution functionality is vulnerable to Server-Side Request Forgery (SSRF), which allows an attacker to send requests on behalf of Spinnaker potentially leading to sensitive … CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2020-9298 2024-11-21 14:40 2020-08-29 Show GitHub Exploit DB Packet Storm
201360 6.5 MEDIUM
Network
huawei fusioncompute FusionCompute 8.0.0 has an information leak vulnerability. A module does not launch strict access control and information protection. Attackers with low privilege can get some extra information. This… NVD-CWE-noinfo
CVE-2020-9246 2024-11-21 14:40 2020-08-21 Show GitHub Exploit DB Packet Storm