Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 28, 2026, noon

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
251621 4.3 警告 LEPTON Project - LEPTON におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-1000 2012-02-27 15:25 2012-02-24 Show GitHub Exploit DB Packet Storm
251622 7.5 危険 LEPTON Project - LEPTON の modules/news/rss.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2012-0999 2012-02-27 15:24 2012-02-24 Show GitHub Exploit DB Packet Storm
251623 7.5 危険 LEPTON Project - LEPTON の account/preferences.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2012-0998 2012-02-27 15:24 2012-02-24 Show GitHub Exploit DB Packet Storm
251624 6.8 警告 11in1 - 11in1 の admin/index.php におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2012-0997 2012-02-27 15:23 2012-02-24 Show GitHub Exploit DB Packet Storm
251625 5 警告 11in1 - 11in1 におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2012-0996 2012-02-27 15:21 2012-02-24 Show GitHub Exploit DB Packet Storm
251626 7.5 危険 CONTIMEX - CONTIMEX Impulsio CMS における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2012-1294 2012-02-27 15:20 2011-02-23 Show GitHub Exploit DB Packet Storm
251627 4.3 警告 BoonEx - Boonex Dolphin におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-0873 2012-02-27 15:20 2011-02-23 Show GitHub Exploit DB Packet Storm
251628 5 警告 John Koleszar - VP8 Codec SDK (libvpx) におけるサービス運用妨害 (アプリケーションクラッシュ)の脆弱性 CWE-20
不適切な入力確認
CVE-2012-0823 2012-02-27 15:19 2012-02-23 Show GitHub Exploit DB Packet Storm
251629 5 警告 SAP - SAP NetWeaver における MessagingSystem Performance Data についての重要な情報を取得される脆弱性 CWE-noinfo
情報不足
CVE-2012-1292 2012-02-27 13:49 2012-02-23 Show GitHub Exploit DB Packet Storm
251630 5 警告 SAP - SAP NetWeaver における Adapter Monitor についての重要な情報を取得される脆弱性 CWE-noinfo
情報不足
CVE-2012-1291 2012-02-27 13:48 2012-02-23 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 28, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
208721 6.1 MEDIUM
Network
tailor_management_system_project tailor_management_system A Reflected Cross-Site Scripting (XSS) vulnerability in the index.php login-portal webpage of SourceCodester Tailor Management System v1.0 allows remote attackers to harvest keys pressed by an unauth… CWE-79
Cross-site Scripting
CVE-2020-23835 2024-11-21 14:14 2020-09-2 Show GitHub Exploit DB Packet Storm
208722 6.1 MEDIUM
Network
stock_management_system_project stock_management_system A Reflected Cross-Site Scripting (XSS) vulnerability in the index.php login-portal webpage of SourceCodester Stock Management System v1.0 allows remote attackers to harvest login credentials and sess… CWE-79
Cross-site Scripting
CVE-2020-23831 2024-11-21 14:14 2020-09-2 Show GitHub Exploit DB Packet Storm
208723 8.8 HIGH
Network
librehealth librehealth_ehr interface/new/new_comprehensive_save.php in LibreHealth EHR 2.0.0 suffers from an authenticated file upload vulnerability, allowing remote attackers to achieve remote code execution (RCE) on the host… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2020-23829 2024-11-21 14:14 2020-09-2 Show GitHub Exploit DB Packet Storm
208724 7.5 HIGH
Network
gmapfp gmapfp gmapfp.org Joomla Component GMapFP J3.30pro is affected by Insecure Permissions. An attacker can access the upload function without authenticating to the application and also can upload files due the… CWE-276
Incorrect Default Permissions 
CVE-2020-23971 2024-11-21 14:14 2020-09-2 Show GitHub Exploit DB Packet Storm
208725 7.5 HIGH
Network
liferay liferay_portal The redirect module in Liferay Portal before 7.3.3 does not limit the number of URLs resulting in a 404 error that is recorded, which allows remote attackers to perform a denial of service attack by … CWE-601
Open Redirect
CVE-2020-24554 2024-11-21 14:14 2020-09-1 Show GitHub Exploit DB Packet Storm
208726 8.8 HIGH
Network
zyxel vmg5313-b30b_firmware Zyxel VMG5313-B30B router on firmware 5.13(ABCJ.6)b3_1127, and possibly older versions of firmware are affected by shell injection. CWE-78
OS Command 
CVE-2020-24354 2024-11-21 14:14 2020-09-1 Show GitHub Exploit DB Packet Storm
208727 8.8 HIGH
Adjacent
tp-link tl-wa855re_firmware TP-Link TL-WA855RE V5 20200415-rel37464 devices allow an unauthenticated attacker (on the same network) to submit a TDDP_RESET POST request for a factory reset and reboot. The attacker can then obtai… CWE-306
Missing Authentication for Critical Function
CVE-2020-24363 2024-11-21 14:14 2020-09-1 Show GitHub Exploit DB Packet Storm
208728 9.8 CRITICAL
Network
online_book_store_project online_book_store In projectworlds Online Book Store 1.0 Use of Hard-coded Credentials in source code leads to admin panel access. CWE-798
 Use of Hard-coded Credentials
CVE-2020-24115 2024-11-21 14:14 2020-08-31 Show GitHub Exploit DB Packet Storm
208729 6.1 MEDIUM
Network
pix-link lv-wr07_firmware XSS on the PIX-Link Repeater/Router LV-WR07 with firmware v28K.Router.20170904 allows attackers to steal credentials without being connected to the network. The attack vector is a crafted ESSID, as d… CWE-79
Cross-site Scripting
CVE-2020-24104 2024-11-21 14:14 2020-08-31 Show GitHub Exploit DB Packet Storm
208730 6.1 MEDIUM
Network
mara_cms_project mara_cms Mara CMS 7.5 allows cross-site scripting (XSS) in contact.php via the theme or pagetheme parameters. CWE-79
Cross-site Scripting
CVE-2020-24223 2024-11-21 14:14 2020-08-31 Show GitHub Exploit DB Packet Storm