Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 29, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
252241 7.5 危険 Vastal I-Tech & Co. - Vastal I-Tech Agent Zone の search.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2012-0982 2012-02-7 16:18 2012-02-2 Show GitHub Exploit DB Packet Storm
252242 5 警告 KYBERNETIKA - phpShowtime における任意のディレクトリおよびイメージファイルをリストアップされる脆弱性 CWE-22
パス・トラバーサル
CVE-2012-0981 2012-02-7 16:17 2012-02-2 Show GitHub Exploit DB Packet Storm
252243 7.5 危険 phux Development - phux Download Manager の download.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2012-0980 2012-02-7 16:16 2012-02-2 Show GitHub Exploit DB Packet Storm
252244 4.3 警告 TWiki - TWiki におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-0979 2012-02-7 16:14 2012-02-2 Show GitHub Exploit DB Packet Storm
252245 6.8 警告 LuraTech - LuraWave JP2 Browser Plug-In におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2012-0978 2012-02-7 16:13 2012-02-2 Show GitHub Exploit DB Packet Storm
252246 9.3 危険 LuraTech - LuraWave JP2 ActiveX Control におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2012-0977 2012-02-7 16:12 2012-02-2 Show GitHub Exploit DB Packet Storm
252247 2.1 注意 SilverStripe - SilverStripe の admin/EditForm におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-0976 2012-02-7 16:10 2012-02-2 Show GitHub Exploit DB Packet Storm
252248 4.3 警告 Clixint Technologies - Image Hosting Script DPI の misc.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-0975 2012-02-7 16:00 2012-02-2 Show GitHub Exploit DB Packet Storm
252249 7.8 危険 FreeBSD
NetBSD
- 複数の BSD-based オペレーティングシステムにおけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2011-2393 2012-02-7 15:51 2012-02-2 Show GitHub Exploit DB Packet Storm
252250 5 警告 Linux - Linux kernel におけるネットワーク盗聴を検出される脆弱性 CWE-200
情報漏えい
CVE-2010-4563 2012-02-7 15:50 2012-02-2 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 29, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
215251 7.5 HIGH
Network
oppo coloros In ColorOS (oppo mobile phone operating system, based on AOSP frameworks/native code position/services/surfaceflinger surfaceflinger.CPP), RGB is defined on the stack but uninitialized, so when the s… CWE-908
 Use of Uninitialized Resource
CVE-2020-11828 2024-11-21 13:58 2020-04-21 Show GitHub Exploit DB Packet Storm
215252 7.8 HIGH
Local
re2c
canonical
re2c
ubuntu_linux
re2c 1.3 has a heap-based buffer overflow in Scanner::fill in parse/scanner.cc via a long lexeme. CWE-787
 Out-of-bounds Write
CVE-2020-11958 2024-11-21 13:58 2020-04-21 Show GitHub Exploit DB Packet Storm
215253 9.8 CRITICAL
Network
evenroute iqrouter_firmware IQrouter through 3.3.1, when unconfigured, has multiple remote code execution vulnerabilities in the web-panel because of Bash Shell Metacharacter Injection. Note: The vendor claims that this vulnera… CWE-78
OS Command 
CVE-2020-11963 2024-11-21 13:58 2020-04-21 Show GitHub Exploit DB Packet Storm
215254 6.1 MEDIUM
Network
bitcoin-abe_project bitcoin-abe Abe (aka bitcoin-abe) through 0.7.2, and 0.8pre, allows XSS in __call__ in abe.py because the PATH_INFO environment variable is mishandled during a PageNotFound exception. CWE-79
Cross-site Scripting
CVE-2020-11944 2024-11-21 13:58 2020-04-21 Show GitHub Exploit DB Packet Storm
215255 7.5 HIGH
Network
zohocorp manageengine_opmanager Zoho ManageEngine OpManager before 125120 allows an unauthenticated user to retrieve an API key via a servlet call. CWE-306
Missing Authentication for Critical Function
CVE-2020-11946 2024-11-21 13:58 2020-04-21 Show GitHub Exploit DB Packet Storm
215256 8.8 HIGH
Network
sonatype nexus_repository_manager_3 An issue was discovered in Sonatype Nexus Repository Manager in versions 3.21.1 and 3.22.0. It is possible for a user with appropriate privileges to create, modify, and execute scripting tasks withou… CWE-863
 Incorrect Authorization
CVE-2020-11753 2024-11-21 13:58 2020-04-21 Show GitHub Exploit DB Packet Storm
215257 6.1 MEDIUM
Network
python-markdown2_project python-markdown2 python-markdown2 through 2.3.8 allows XSS because element names are mishandled unless a \w+ match succeeds. For example, an attack might use elementname@ or elementname- with an onclick attribute. CWE-79
Cross-site Scripting
CVE-2020-11888 2024-11-21 13:58 2020-04-21 Show GitHub Exploit DB Packet Storm
215258 6.1 MEDIUM
Network
gtranslate translate_wordpress_with_gtranslate The GTranslate plugin before 2.8.52 for WordPress has Reflected XSS via a crafted link. This requires use of the hreflang tags feature within a sub-domain or sub-directory paid option. CWE-79
Cross-site Scripting
CVE-2020-11930 2024-11-21 13:58 2020-04-20 Show GitHub Exploit DB Packet Storm
215259 9.8 CRITICAL
Network
davidlingren media_library_assistant In the media-library-assistant plugin before 2.82 for WordPress, Remote Code Execution can occur via the tax_query, meta_query, or date_query parameter in mla_gallery via an admin. NVD-CWE-noinfo
CVE-2020-11928 2024-11-21 13:58 2020-04-20 Show GitHub Exploit DB Packet Storm
215260 9.1 CRITICAL
Network
libming libming Ming (aka libming) 0.4.8 has a heap-based buffer over-read (2 bytes) in the function decompileIF() in decompile.c. CWE-125
Out-of-bounds Read
CVE-2020-11895 2024-11-21 13:58 2020-04-20 Show GitHub Exploit DB Packet Storm