Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 8, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
253341 4.3 警告 オラクル - Oracle Fusion Middleware の Oracle WebCenter Content コンポーネントにおける脆弱性 CWE-noinfo
情報不足
CVE-2012-0085 2012-01-20 15:39 2012-01-17 Show GitHub Exploit DB Packet Storm
253342 5 警告 オラクル - Oracle Fusion Middleware の Oracle Web Services Manager コンポーネントにおける脆弱性 CWE-noinfo
情報不足
CVE-2011-3569 2012-01-20 15:25 2012-01-17 Show GitHub Exploit DB Packet Storm
253343 5 警告 オラクル - Oracle Fusion Middleware の Oracle Web Services Manager コンポーネントにおける脆弱性 CWE-noinfo
情報不足
CVE-2011-3531 2012-01-20 15:22 2012-01-17 Show GitHub Exploit DB Packet Storm
253344 5.5 警告 オラクル - Oracle Fusion Middleware の Oracle Web Services Manager コンポーネントにおける脆弱性 CWE-noinfo
情報不足
CVE-2011-3568 2012-01-20 15:17 2012-01-17 Show GitHub Exploit DB Packet Storm
253345 6.4 警告 オラクル - Oracle Fusion Middleware における Search の処理に関する脆弱性 CWE-noinfo
情報不足
CVE-2012-0083 2012-01-20 15:09 2012-01-17 Show GitHub Exploit DB Packet Storm
253346 5 警告 オラクル - Oracle Fusion Middleware の Oracle WebLogic Server コンポーネントにおける脆弱性 CWE-noinfo
情報不足
CVE-2011-3566 2012-01-20 12:12 2012-01-17 Show GitHub Exploit DB Packet Storm
253347 2.6 注意 オラクル - Oracle WebLogic Server におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-0077 2012-01-20 12:09 2012-01-20 Show GitHub Exploit DB Packet Storm
253348 5 警告 osCommerce - osCommerce におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2005-2330 2012-01-20 12:08 2012-01-20 Show GitHub Exploit DB Packet Storm
253349 4.3 警告 osCommerce - osCommerce 日本語版におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-0311 2012-01-20 12:08 2012-01-20 Show GitHub Exploit DB Packet Storm
253350 2.7 注意 オラクル - Oracle PeopleSoft Products の PeopleSoft Enterprise PeopleTools コンポーネントにおける脆弱性 CWE-noinfo
情報不足
CVE-2012-0091 2012-01-20 11:36 2012-01-17 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 8, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
218991 9.8 CRITICAL
Network
microsoft windows_10
windows_server_2016
windows_server_2019
An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation of Privilege Vulnerability'. NVD-CWE-noinfo
CVE-2020-0690 2024-11-21 13:54 2020-03-13 Show GitHub Exploit DB Packet Storm
218992 9.8 CRITICAL
Network
twistedmatrix
fedoraproject
debian
canonical
twisted
fedora
debian_linux
ubuntu_linux
In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with a content-length and a chunked encoding header, the content-length took precedence and the remai… CWE-444
HTTP Request Smuggling
CVE-2020-10109 2024-11-21 13:54 2020-03-12 Show GitHub Exploit DB Packet Storm
218993 9.8 CRITICAL
Network
twistedmatrix
fedoraproject
debian
canonical
oracle
twisted
fedora
debian_linux
ubuntu_linux
solaris
zfs_storage_appliance_kit
In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with two content-length headers, it ignored the first header. When the second content-length value wa… CWE-444
HTTP Request Smuggling
CVE-2020-10108 2024-11-21 13:54 2020-03-12 Show GitHub Exploit DB Packet Storm
218994 9.8 CRITICAL
Network
sumavision enhanced_multimedia_router_firmware goform/formEMR30 in Sumavision Enhanced Multimedia Router (EMR) 3.0.4.27 allows creation of arbitrary users with elevated privileges (administrator) on a device, as demonstrated by a setString=new_us… CWE-352
 Origin Validation Error
CVE-2020-10181 2024-11-21 13:54 2020-03-12 Show GitHub Exploit DB Packet Storm
218995 6.1 MEDIUM
Network
munkireport_project munkireport An issue was discovered in Munkireport before 5.3.0.3923. An unauthenticated actor can send a custom XSS payload through the /report/broken_client endpoint. The payload will be executed by any authen… CWE-79
Cross-site Scripting
CVE-2020-10192 2024-11-21 13:54 2020-03-10 Show GitHub Exploit DB Packet Storm
218996 5.4 MEDIUM
Network
munkireport_project munkireport An issue was discovered in MunkiReport before 5.3.0. An authenticated actor can send a custom XSS payload through the /module/comment/save endpoint. The payload will be executed by any authenticated … CWE-79
Cross-site Scripting
CVE-2020-10191 2024-11-21 13:54 2020-03-10 Show GitHub Exploit DB Packet Storm
218997 8.8 HIGH
Network
munkireport_project munkireport An issue was discovered in MunkiReport before 5.3.0. An authenticated user could achieve SQL Injection in app/models/tablequery.php by crafting a special payload on the /datatables/data endpoint. CWE-89
SQL Injection
CVE-2020-10190 2024-11-21 13:54 2020-03-10 Show GitHub Exploit DB Packet Storm
218998 8.1 HIGH
Network
gonitro nitro_pro npdf.dll in Nitro Pro before 13.13.2.242 is vulnerable to JBIG2Decode CNxJBIG2DecodeStream Heap Corruption at npdf!CAPPDAnnotHandlerUtils::create_popup_for_markup+0x12fbe via a crafted PDF document. CWE-787
 Out-of-bounds Write
CVE-2020-10223 2024-11-21 13:54 2020-03-9 Show GitHub Exploit DB Packet Storm
218999 8.1 HIGH
Network
gonitro nitro_pro npdf.dll in Nitro Pro before 13.13.2.242 is vulnerable to Heap Corruption at npdf!nitro::get_property+2381 via a crafted PDF document. NVD-CWE-noinfo
CVE-2020-10222 2024-11-21 13:54 2020-03-9 Show GitHub Exploit DB Packet Storm
219000 8.8 HIGH
Network
rconfig rconfig lib/ajaxHandlers/ajaxAddTemplate.php in rConfig through 3.94 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the fileName POST parameter. CWE-78
OS Command 
CVE-2020-10221 2024-11-21 13:54 2020-03-9 Show GitHub Exploit DB Packet Storm