Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 9, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
251211 10 危険 ヒューレット・パッカード - HP Data Protector のクライアントにおける任意のスクリプトコードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2011-0924 2012-03-27 18:43 2011-02-8 Show GitHub Exploit DB Packet Storm
251212 10 危険 ヒューレット・パッカード - HP Data Protector のクライアントにおける任意の Perl コードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2011-0923 2012-03-27 18:43 2011-02-8 Show GitHub Exploit DB Packet Storm
251213 10 危険 ヒューレット・パッカード - HP Data Protector のクライアントにおける任意のプログラムを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2011-0922 2012-03-27 18:43 2011-02-8 Show GitHub Exploit DB Packet Storm
251214 10 危険 ヒューレット・パッカード - HP Data Protector の crs.exe における任意のコードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2011-0921 2012-03-27 18:43 2011-02-8 Show GitHub Exploit DB Packet Storm
251215 9.3 危険 IBM - IBM Lotus Domino の Remote Console における認証を回避する脆弱性 CWE-287
不適切な認証
CVE-2011-0920 2012-03-27 18:43 2011-02-8 Show GitHub Exploit DB Packet Storm
251216 4.3 警告 Zikula Foundation - Zikula Users モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-0911 2012-03-27 18:43 2011-02-8 Show GitHub Exploit DB Packet Storm
251217 6.4 警告 Vanilla Forums - Vanilla Forums のクッキーの実装における署名されたリクエストを偽造される脆弱性 CWE-Other
その他
CVE-2011-0910 2012-03-27 18:43 2011-02-8 Show GitHub Exploit DB Packet Storm
251218 4.3 警告 Vanilla Forums - Vanilla Forums におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-0909 2012-03-27 18:43 2011-02-8 Show GitHub Exploit DB Packet Storm
251219 5.8 警告 Vanilla Forums - Vanilla Forums におけるオープンリダイレクトの脆弱性 CWE-20
不適切な入力確認
CVE-2011-0908 2012-03-27 18:43 2011-02-8 Show GitHub Exploit DB Packet Storm
251220 6.8 警告 awcm - AWCM におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2011-0903 2012-03-27 18:43 2011-02-7 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 9, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
202471 5.4 MEDIUM
Network
rocket.chat rocket.chat The `specializedRendering` function in Rocket.Chat server before 3.9.2 allows a cross-site scripting (XSS) vulnerability by way of the `value` parameter. CWE-79
Cross-site Scripting
CVE-2020-8288 2024-11-21 14:38 2021-01-27 Show GitHub Exploit DB Packet Storm
202472 6.5 MEDIUM
Network
nodejs
debian
fedoraproject
oracle
siemens
node.js
debian_linux
fedora
graalvm
sinec_infrastructure_network_services
Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 allow two copies of a header field in an HTTP request (for example, two Transfer-Encoding header fields). In this case, Node.js identifies th… CWE-444
HTTP Request Smuggling
CVE-2020-8287 2024-11-21 14:38 2021-01-7 Show GitHub Exploit DB Packet Storm
202473 5.4 MEDIUM
Network
nextcloud contacts A missing file type check in Nextcloud Contacts 3.3.0 allows a malicious user to upload malicious SVG files to perform cross-site scripting (XSS) attacks. CWE-79
Cross-site Scripting
CVE-2020-8281 2024-11-21 14:38 2021-01-7 Show GitHub Exploit DB Packet Storm
202474 5.4 MEDIUM
Network
nextcloud contacts A missing file type check in Nextcloud Contacts 3.4.0 allows a malicious user to upload SVG files as PNG files to perform cross-site scripting (XSS) attacks. CWE-79
Cross-site Scripting
CVE-2020-8280 2024-11-21 14:38 2021-01-7 Show GitHub Exploit DB Packet Storm
202475 4.3 MEDIUM
Network
citrix secure_mail Citrix Secure Mail for Android before 20.11.0 suffers from improper access control allowing unauthenticated access to read limited calendar related data stored within Secure Mail. Note that a malicio… CWE-269
 Improper Privilege Management
CVE-2020-8275 2024-11-21 14:38 2021-01-7 Show GitHub Exploit DB Packet Storm
202476 6.5 MEDIUM
Network
citrix secure_mail Citrix Secure Mail for Android before 20.11.0 suffers from Improper Control of Generation of Code ('Code Injection') by allowing unauthenticated access to read data stored within Secure Mail. Note th… CWE-94
Code Injection
CVE-2020-8274 2024-11-21 14:38 2021-01-7 Show GitHub Exploit DB Packet Storm
202477 6.1 MEDIUM
Network
rubyonrails rails In actionpack gem >= 6.0.0, a possible XSS vulnerability exists when an application is running in development mode allowing an attacker to send or embed (in another page) a specially crafted URL whic… CWE-79
Cross-site Scripting
CVE-2020-8264 2024-11-21 14:38 2021-01-7 Show GitHub Exploit DB Packet Storm
202478 8.1 HIGH
Network
nodejs
debian
fedoraproject
oracle
siemens
node.js
debian_linux
fedora
graalvm
sinec_infrastructure_network_services
Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 are vulnerable to a use-after-free bug in its TLS implementation. When writing to a TLS enabled socket, node::StreamBase::Write calls node::T… CWE-416
 Use After Free
CVE-2020-8265 2024-11-21 14:38 2021-01-7 Show GitHub Exploit DB Packet Storm
202479 6.1 MEDIUM
Network
mendix mendixsso MendixSSO <= 2.1.1 contains endpoints that make use of the openid handler, which is suffering from a Cross-Site Scripting vulnerability via the URL path. This is caused by the reflection of user-supp… CWE-79
Cross-site Scripting
CVE-2020-8160 2024-11-21 14:38 2021-01-7 Show GitHub Exploit DB Packet Storm
202480 7.8 HIGH
Local
backblaze backblaze Backblaze for Windows and Backblaze for macOS before 7.0.0.439 suffer from improper privilege management in `bztransmit` helper due to lack of permission handling and validation before creation of cl… CWE-269
 Improper Privilege Management
CVE-2020-8290 2024-11-21 14:38 2020-12-27 Show GitHub Exploit DB Packet Storm