Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":April 30, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
250581 7.2 危険 マイクロソフト - Microsoft Windows の win32k.sys における権限昇格の脆弱性 CWE-Other
その他
CVE-2011-1888 2011-07-22 10:51 2011-07-12 Show GitHub Exploit DB Packet Storm
250582 7.2 危険 マイクロソフト
日立
- Microsoft Windows の win32k.sys における権限昇格の脆弱性 CWE-Other
その他
CVE-2011-1887 2011-07-22 10:50 2011-07-12 Show GitHub Exploit DB Packet Storm
250583 7.2 危険 マイクロソフト - Microsoft Windows の win32k.sys における権限昇格の脆弱性 CWE-Other
その他
CVE-2011-1885 2011-07-22 10:50 2011-07-12 Show GitHub Exploit DB Packet Storm
250584 7.2 危険 マイクロソフト - Microsoft Windows の win32k.sys における権限昇格の脆弱性 CWE-Other
その他
CVE-2011-1881 2011-07-22 10:49 2011-07-12 Show GitHub Exploit DB Packet Storm
250585 7.2 危険 マイクロソフト - Microsoft Windows の win32k.sys における権限昇格の脆弱性 CWE-Other
その他
CVE-2011-1880 2011-07-22 10:47 2011-07-12 Show GitHub Exploit DB Packet Storm
250586 7.2 危険 マイクロソフト - Microsoft Windows の win32k.sys における権限昇格の脆弱性 CWE-399
リソース管理の問題
CVE-2011-1884 2011-07-22 10:46 2011-07-12 Show GitHub Exploit DB Packet Storm
250587 7.2 危険 マイクロソフト - Microsoft Windows の win32k.sys における権限昇格の脆弱性 CWE-399
リソース管理の問題
CVE-2011-1883 2011-07-22 10:46 2011-07-12 Show GitHub Exploit DB Packet Storm
250588 7.2 危険 マイクロソフト - Microsoft Windows の win32k.sys における権限昇格の脆弱性 CWE-399
リソース管理の問題
CVE-2011-1882 2011-07-22 10:45 2011-07-12 Show GitHub Exploit DB Packet Storm
250589 7.2 危険 マイクロソフト - Microsoft Windows の win32k.sys における権限昇格の脆弱性 CWE-399
リソース管理の問題
CVE-2011-1879 2011-07-22 10:44 2011-07-12 Show GitHub Exploit DB Packet Storm
250590 7.2 危険 マイクロソフト - Microsoft Windows の win32k.sys における権限昇格の脆弱性 CWE-399
リソース管理の問題
CVE-2011-1878 2011-07-21 10:30 2011-07-12 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 30, 2026, 4:58 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
198361 7.4 HIGH
Network
saltstack
fedoraproject
debian
salt
fedora
debian_linux
In SaltStack Salt before 3002.5, when authenticating to services using certain modules, the SSL certificate is not always validated. CWE-295
Improper Certificate Validation 
CVE-2020-35662 2024-11-21 14:27 2021-02-27 Show GitHub Exploit DB Packet Storm
198362 6.1 MEDIUM
Network
acronis cyber_protect An issue was discovered in Acronis Cyber Protect before 15 Update 1 build 26172. There is cross-site scripting (XSS) in the console. CWE-79
Cross-site Scripting
CVE-2020-35664 2024-11-21 14:27 2021-02-22 Show GitHub Exploit DB Packet Storm
198363 6.1 MEDIUM
Network
mantisbt mantisbt An issue was discovered in MantisBT through 2.24.3. In the helper_ensure_confirmed call in manage_custom_field_update.php, the custom field name is not sanitized. This may be problematic depending on… CWE-79
Cross-site Scripting
CVE-2020-35571 2024-11-21 14:27 2021-02-22 Show GitHub Exploit DB Packet Storm
198364 7.5 HIGH
Network
acronis cyber_protect An issue was discovered in Acronis Cyber Protect before 15 Update 1 build 26172. Because the local notification service misconfigures CORS, information disclosure can occur. NVD-CWE-noinfo
CVE-2020-35556 2024-11-21 14:27 2021-02-22 Show GitHub Exploit DB Packet Storm
198365 7.4 HIGH
Network
djangoproject channels Django Channels 3.x before 3.0.3 allows remote attackers to obtain sensitive information from a different request scope. The legacy channels.http.AsgiHandler class, used for handling HTTP type reques… CWE-200
Information Exposure
CVE-2020-35681 2024-11-21 14:27 2021-02-22 Show GitHub Exploit DB Packet Storm
198366 6.7 MEDIUM
Local
linux linux_kernel A NULL pointer dereference flaw in Linux kernel versions prior to 5.11 may be seen if sco_sock_getsockopt function in net/bluetooth/sco.c do not have a sanity check for a socket connection, when usin… CWE-476
 NULL Pointer Dereference
CVE-2020-35499 2024-11-21 14:27 2021-02-20 Show GitHub Exploit DB Packet Storm
198367 5.4 MEDIUM
Network
pi-hole pi-hole Pi-hole 5.0, 5.1, and 5.1.1 allows XSS via the Options header to the admin/ URI. A remote user is able to inject arbitrary web script or HTML due to incorrect sanitization of user-supplied data and a… CWE-79
Cross-site Scripting
CVE-2020-35592 2024-11-21 14:27 2021-02-19 Show GitHub Exploit DB Packet Storm
198368 5.4 MEDIUM
Network
pi-hole pi-hole Pi-hole 5.0, 5.1, and 5.1.1 allows Session Fixation. The application does not generate a new session cookie after the user is logged in. A malicious user is able to create a new session cookie value … CWE-384
 Session Fixation
CVE-2020-35591 2024-11-21 14:27 2021-02-19 Show GitHub Exploit DB Packet Storm
198369 6.5 MEDIUM
Network
endalia selection_portal In Endalia Selection Portal before 4.205.0, an Insecure Direct Object Reference (IDOR) allows any authenticated user to download every file uploaded to the platform by changing the value of the file … NVD-CWE-Other
CVE-2020-35577 2024-11-21 14:27 2021-02-18 Show GitHub Exploit DB Packet Storm
198370 9.8 CRITICAL
Network
74cms 74cms In 74cms version 5.0.1, there is a remote code execution vulnerability in /Application/Admin/Controller/ConfigController.class.php and /ThinkPHP/Common/functions.php where attackers can obtain server… CWE-94
Code Injection
CVE-2020-35339 2024-11-21 14:27 2021-02-18 Show GitHub Exploit DB Packet Storm