Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 3, 2026, 4:05 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
250581 5 警告 The Tor Project - Tor の tor_realloc 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2011-0491 2012-03-27 18:42 2011-01-17 Show GitHub Exploit DB Packet Storm
250582 5 警告 The Tor Project - Tor におけるサービス運用妨害 (DoS) の脆弱性 CWE-DesignError
CVE-2011-0490 2012-03-27 18:42 2011-01-17 Show GitHub Exploit DB Packet Storm
250583 4.3 警告 IBM - IBM Cognos 8 BI の cognos.cgi におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-0486 2012-03-27 18:42 2011-01-18 Show GitHub Exploit DB Packet Storm
250584 6.9 警告 Novell - openSUSE の aaa_base パッケージにおける権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2011-0468 2012-03-27 18:42 2011-04-4 Show GitHub Exploit DB Packet Storm
250585 6.4 警告 Novell - SUSE OBS の API におけるパッケージまたはプロジェクトの書き込みアクセス制限を回避する脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2011-0466 2012-03-27 18:42 2011-03-2 Show GitHub Exploit DB Packet Storm
250586 10 危険 Novell - Novell Vibe OnPrem における任意のコードを実行される脆弱性 CWE-noinfo
情報不足
CVE-2011-0464 2012-03-27 18:42 2011-02-25 Show GitHub Exploit DB Packet Storm
250587 2.1 注意 Linux - Linux kernel の ocfs2_prepare_page_for_write 関数における重要な情報を取得される脆弱性 CWE-20
不適切な入力確認
CVE-2011-0463 2012-03-27 18:42 2011-04-9 Show GitHub Exploit DB Packet Storm
250588 4.3 警告 Novell - SUSE OBS のログインページにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-0462 2012-03-27 18:42 2011-03-2 Show GitHub Exploit DB Packet Storm
250589 6.3 警告 Novell - openSUSE の /etc/init.d/boot.localfs における任意のファイルを上書きされる脆弱性 CWE-59
リンク解釈の問題
CVE-2011-0461 2012-03-27 18:42 2011-04-4 Show GitHub Exploit DB Packet Storm
250590 7.5 危険 Ruby on Rails project - Ruby on Rails の actionpack/lib/action_view/template/resolver.rb におけるアクセス制限を回避する脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2011-0449 2012-03-27 18:42 2011-02-8 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 3, 2026, 4:18 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
214841 7.5 HIGH
Network
mods-for-hesk mods_for_hesk An issue was discovered in Mods for HESK 3.1.0 through 2019.1.0. A blind time-based SQL injection issue allows remote unauthenticated attackers to retrieve information from the database via a ticket. CWE-89
SQL Injection
CVE-2020-13993 2024-11-21 14:02 2020-07-10 Show GitHub Exploit DB Packet Storm
214842 6.1 MEDIUM
Network
mods-for-hesk mods_for_hesk An issue was discovered in Mods for HESK 3.1.0 through 2019.1.0. A Stored XSS issue allows remote unauthenticated attackers to abuse a helpdesk user's logged in session. A user with sufficient privil… CWE-79
Cross-site Scripting
CVE-2020-13992 2024-11-21 14:02 2020-07-10 Show GitHub Exploit DB Packet Storm
214843 7.5 HIGH
Network
samba
fedoraproject
opensuse
debian
canonical
samba
fedora
leap
debian_linux
ubuntu_linux
A flaw was found in the AD DC NBT server in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4. A samba user could send an empty UDP packet to cause the samba server to crash. CWE-834
 Excessive Iteration
CVE-2020-14303 2024-11-21 14:02 2020-07-7 Show GitHub Exploit DB Packet Storm
214844 5.4 MEDIUM
Network
atlassian jira
jira_software_data_center
jira_server
jira_data_center
The file upload feature in Atlassian Jira Server and Data Center in affected versions allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability. Th… CWE-79
Cross-site Scripting
CVE-2020-14173 2024-11-21 14:02 2020-07-3 Show GitHub Exploit DB Packet Storm
214845 9.8 CRITICAL
Network
atlassian jira
jira_software_data_center
This issue exists to document that a security improvement in the way that Jira Server and Data Center use velocity templates has been implemented. The way in which velocity templates were used in Atl… CWE-502
 Deserialization of Untrusted Data
CVE-2020-14172 2024-11-21 14:02 2020-07-3 Show GitHub Exploit DB Packet Storm
214846 9.8 CRITICAL
Network
ithemes paypal_pro The CodePeople Payment Form for PayPal Pro plugin before 1.1.65 for WordPress allows SQL Injection. CWE-89
SQL Injection
CVE-2020-14092 2024-11-21 14:02 2020-07-3 Show GitHub Exploit DB Packet Storm
214847 5.3 MEDIUM
Network
powerdns recursor In PowerDNS Recursor versions up to and including 4.3.1, 4.2.2 and 4.1.16, the ACL restricting access to the internal web server is not properly enforced. CWE-863
 Incorrect Authorization
CVE-2020-14196 2024-11-21 14:02 2020-07-2 Show GitHub Exploit DB Packet Storm
214848 9.8 CRITICAL
Network
monstaftp monsta_ftp Monsta FTP 2.10.1 or below allows external control of paths used in filesystem operations. This allows attackers to read and write arbitrary local files, allowing an attacker to gain remote code exec… CWE-610
Externally Controlled Reference to a Resource in Another Sphere
CVE-2020-14057 2024-11-21 14:02 2020-07-2 Show GitHub Exploit DB Packet Storm
214849 9.8 CRITICAL
Network
monstaftp monsta_ftp Monsta FTP 2.10.1 or below is prone to a server-side request forgery vulnerability due to insufficient restriction of the web fetch functionality. This allows attackers to read arbitrary local files … CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2020-14056 2024-11-21 14:02 2020-07-2 Show GitHub Exploit DB Packet Storm
214850 6.1 MEDIUM
Network
monstaftp monsta_ftp Monsta FTP 2.10.1 or below is prone to a stored cross-site scripting vulnerability in the language setting due to insufficient output encoding. CWE-79
Cross-site Scripting
CVE-2020-14055 2024-11-21 14:02 2020-07-2 Show GitHub Exploit DB Packet Storm