Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 12, 2026, 12:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
254651 7.5 危険 Takeaweb - Time Returns コンポーネントにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2011-4570 2011-11-30 16:37 2011-11-29 Show GitHub Exploit DB Packet Storm
254652 7.5 危険 tommykent1210 - MyBB Forum 用 Userbar プラグインにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2011-4569 2011-11-30 16:36 2011-11-29 Show GitHub Exploit DB Packet Storm
254653 4.3 警告 WordPress.org - WordPress 用 Flowplayer プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-4568 2011-11-30 16:35 2011-11-29 Show GitHub Exploit DB Packet Storm
254654 4.3 警告 Zen Cart - Zen Cart におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-4567 2011-11-30 16:34 2011-11-29 Show GitHub Exploit DB Packet Storm
254655 4.3 警告 Zen Cart - Zen Cart におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-4547 2011-11-30 16:34 2011-11-29 Show GitHub Exploit DB Packet Storm
254656 4.3 警告 Hastymail - Hastymail2 の index.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-4541 2011-11-30 16:32 2011-11-29 Show GitHub Exploit DB Packet Storm
254657 4.3 警告 XOOPS - XOOPS におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-4565 2011-11-30 16:32 2011-10-3 Show GitHub Exploit DB Packet Storm
254658 4.3 警告 Activedev - Active CMS の admin script におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-4564 2011-11-30 16:31 2011-11-28 Show GitHub Exploit DB Packet Storm
254659 4.3 警告 JAKCMS - JAKCMS の index.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-4563 2011-11-30 16:27 2011-09-22 Show GitHub Exploit DB Packet Storm
254660 4.3 警告 Phorum - Phorum の admin.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2011-4561 2011-11-30 16:24 2011-11-28 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 12, 2026, 4:20 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
202821 4.6 MEDIUM
Physics
huawei p30_pro_firmware HUAWEI P30 Pro versions earlier than 10.1.0.160(C00E160R2P8) have a path traversal vulnerability. The system does not sufficiently validate certain pathname, successful exploit could allow the attack… CWE-22
Path Traversal
CVE-2020-9106 2024-11-21 14:40 2020-10-12 Show GitHub Exploit DB Packet Storm
202822 5.5 MEDIUM
Local
huawei taurus-an00b_firmware Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2) have an out-of-bounds read and write vulnerability. Some functions do not verify inputs sufficiently. Attackers can exploit this vulnerabili… CWE-125
CWE-787
Out-of-bounds Read
 Out-of-bounds Write
CVE-2020-9091 2024-11-21 14:40 2020-10-12 Show GitHub Exploit DB Packet Storm
202823 7.8 HIGH
Local
huawei fusionaccess FusionAccess version 6.5.1 has an improper authorization vulnerability. A command is authorized with incorrect privilege. Attackers with other privilege can execute the command to exploit this vulner… NVD-CWE-noinfo
CVE-2020-9090 2024-11-21 14:40 2020-10-12 Show GitHub Exploit DB Packet Storm
202824 6.7 MEDIUM
Local
huawei taurus-an00b_firmware Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2) have an insufficient input validation vulnerability. Due to the input validation logic is incorrect, an attacker can exploit this vulnerabil… CWE-20
 Improper Input Validation 
CVE-2020-9105 2024-11-21 14:40 2020-10-9 Show GitHub Exploit DB Packet Storm
202825 7.5 HIGH
Network
apache nifi In Apache NiFi 1.2.0 to 1.11.4, the NiFi UI and API were protected by mandating TLS v1.2, as well as listening connections established by processors like ListenHTTP, HandleHttpRequest, etc. However i… CWE-327
 Use of a Broken or Risky Cryptographic Algorithm
CVE-2020-9491 2024-11-21 14:40 2020-10-2 Show GitHub Exploit DB Packet Storm
202826 7.5 HIGH
Network
apache nifi In Apache NiFi 1.0.0 to 1.11.4, the NiFi download token (one-time password) mechanism used a fixed cache size and did not authenticate a request to create a download token, only when attempting to us… CWE-306
Missing Authentication for Critical Function
CVE-2020-9487 2024-11-21 14:40 2020-10-2 Show GitHub Exploit DB Packet Storm
202827 7.5 HIGH
Network
apache nifi In Apache NiFi 1.10.0 to 1.11.4, the NiFi stateless execution engine produced log output which included sensitive property values. When a flow was triggered, the flow definition configuration JSON wa… CWE-532
 Inclusion of Sensitive Information in Log Files
CVE-2020-9486 2024-11-21 14:40 2020-10-2 Show GitHub Exploit DB Packet Storm
202828 5.4 MEDIUM
Network
tibco spotfire_server
spotfire_desktop
spotfire_analytics_platform
spotfire_analyst
The Spotfire client component of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Desktop, and TIBCO Spotfire Server contains a vuln… CWE-79
Cross-site Scripting
CVE-2020-9416 2024-11-21 14:40 2020-09-16 Show GitHub Exploit DB Packet Storm
202829 5.5 MEDIUM
Local
huawei bla-a09_firmware
bla-tl00b_firmware
berkeley-l09_firmware
duke-l09_firmware
p20_firmware
p20_pro_firmware
jimmy-al00a_firmware
lon-l29d_firmware
neo-al00d_firmware
stanford…
Huawei smartphones BLA-A09 versions 8.0.0.123(C212),versions earlier than 8.0.0.123(C567),versions earlier than 8.0.0.123(C797);BLA-TL00B versions earlier than 8.1.0.326(C01);Berkeley-L09 versions ea… CWE-20
 Improper Input Validation 
CVE-2020-9239 2024-11-21 14:40 2020-09-11 Show GitHub Exploit DB Packet Storm
202830 6.8 MEDIUM
Adjacent
huawei b2368-22_firmware
b2368-57_firmware
b2368-66_firmware
B2368-22 V100R001C00;B2368-57 V100R001C00;B2368-66 V100R001C00 have a command injection vulnerability. An attacker with high privileges may exploit this vulnerability through some operations on the L… CWE-77
Command Injection
CVE-2020-9199 2024-11-21 14:40 2020-09-4 Show GitHub Exploit DB Packet Storm