Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 14, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
250521 4.3 警告 Horde - Horde Groupware Webmail Edition におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-0909 2012-01-27 11:05 2012-01-24 Show GitHub Exploit DB Packet Storm
250522 4.3 警告 SimpleSAMLphp - SimpleSAMLphp の logout.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-0908 2012-01-27 11:04 2012-01-24 Show GitHub Exploit DB Packet Storm
250523 4.3 警告 Horde - Horde IMP および Horde Groupware Webmail Edition におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-0791 2012-01-27 11:04 2012-01-24 Show GitHub Exploit DB Packet Storm
250524 4.3 警告 OETIKER - Smokeping の smokeping_cgi におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-0790 2012-01-27 11:03 2012-01-24 Show GitHub Exploit DB Packet Storm
250525 4.3 警告 MailEnable - MailEnable の ForgottenPassword.aspx におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-0389 2012-01-27 11:01 2012-01-24 Show GitHub Exploit DB Packet Storm
250526 7.5 危険 Batavi - Batavi の ajax.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2012-0069 2012-01-27 10:55 2012-01-24 Show GitHub Exploit DB Packet Storm
250527 10 危険 日立 - 日立の複数の COBOL2002 製品における任意のコードを実行される脆弱性 CWE-noinfo
情報不足
CVE-2012-0918 2012-01-26 16:54 2012-01-20 Show GitHub Exploit DB Packet Storm
250528 4.3 警告 日立 - Hitachi IT Operations Director におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-0919 2012-01-26 16:53 2012-01-10 Show GitHub Exploit DB Packet Storm
250529 4.3 警告 日立 - Hitachi IT Operations Analyzer におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-0917 2012-01-26 16:49 2012-01-10 Show GitHub Exploit DB Packet Storm
250530 7.5 危険 Google - Google Chrome で使用される Skia におけるサービス運用妨害 (DoS) の脆弱性 CWE-DesignError
CVE-2011-3927 2012-01-25 16:09 2012-01-23 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 14, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
210271 5.4 MEDIUM
Network
bludit bludit showAlert() in the administration panel in Bludit 3.12.0 allows XSS. CWE-79
Cross-site Scripting
CVE-2020-13889 2024-11-21 14:02 2020-06-7 Show GitHub Exploit DB Packet Storm
210272 6.7 MEDIUM
Network
wso2 identity_server_as_key_manager
api_microgateway
api_manager
In WSO2 API Manager 3.0.0 and earlier, WSO2 API Microgateway 2.2.0, and WSO2 IS as Key Manager 5.9.0 and earlier, Management Console allows XXE during addition or update of a Lifecycle. CWE-611
XXE
CVE-2020-13883 2024-11-21 14:02 2020-06-7 Show GitHub Exploit DB Packet Storm
210273 7.5 HIGH
Network
pam_tacplus_project
debian
canonical
arista
pam_tacplus
debian_linux
ubuntu_linux
cloudvision_portal
In support.c in pam_tacplus 1.3.8 through 1.5.1, the TACACS+ shared secret gets logged via syslog if the DEBUG loglevel and journald are used. CWE-532
 Inclusion of Sensitive Information in Log Files
CVE-2020-13881 2024-11-21 14:02 2020-06-7 Show GitHub Exploit DB Packet Storm
210274 7.5 HIGH
Network
sqlite
fedoraproject
debian
oracle
siemens
netapp
sqlite
fedora
debian_linux
hyperion_infrastructure_technology
enterprise_manager_ops_center
communications_network_charging_and_control
zfs_storage_appliance_kit
communications_m…
SQLite 3.32.2 has a use-after-free in resetAccumulator in select.c because the parse tree rewrite for window functions is too late. CWE-416
 Use After Free
CVE-2020-13871 2024-11-21 14:02 2020-06-7 Show GitHub Exploit DB Packet Storm
210275 5.4 MEDIUM
Network
elementor elementor_page_builder The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from multiple stored XSS vulnerabilities. An author user can create posts that result in stored XSS vulnerabilities, by using a cr… CWE-79
Cross-site Scripting
CVE-2020-13865 2024-11-21 14:02 2020-06-6 Show GitHub Exploit DB Packet Storm
210276 5.4 MEDIUM
Network
elementor elementor_page_builder The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from a stored XSS vulnerability. An author user can create posts that result in a stored XSS by using a crafted payload in custom … CWE-79
Cross-site Scripting
CVE-2020-13864 2024-11-21 14:02 2020-06-6 Show GitHub Exploit DB Packet Storm
210277 5.4 MEDIUM
Network
verbb comments An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. There is stored XSS via an asset volume name. CWE-79
Cross-site Scripting
CVE-2020-13870 2024-11-21 14:02 2020-06-6 Show GitHub Exploit DB Packet Storm
210278 5.4 MEDIUM
Network
verbb comments An issue was discovered in the Comments plugin before 1.5.6 for Craft CMS. There is stored XSS via a guest name. CWE-79
Cross-site Scripting
CVE-2020-13869 2024-11-21 14:02 2020-06-6 Show GitHub Exploit DB Packet Storm
210279 6.5 MEDIUM
Network
verbb comments An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. CSRF affects comment integrity. CWE-352
 Origin Validation Error
CVE-2020-13868 2024-11-21 14:02 2020-06-6 Show GitHub Exploit DB Packet Storm
210280 5.5 MEDIUM
Local
targetcli-fb_project
fedoraproject
targetcli-fb
fedora
Open-iSCSI targetcli-fb through 2.1.52 has weak permissions for /etc/target (and for the backup directory and backup files). CWE-276
Incorrect Default Permissions 
CVE-2020-13867 2024-11-21 14:02 2020-06-6 Show GitHub Exploit DB Packet Storm