Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 15, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
255511 6.8 警告 VMware - 複数の VMware 製品の VNnc コーデックにおけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-0910 2010-03-23 14:11 2010-04-3 Show GitHub Exploit DB Packet Storm
255512 9.3 危険 VMware - 複数の VMware 製品の VNnc コーデックにおけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-0909 2010-03-23 14:10 2010-04-3 Show GitHub Exploit DB Packet Storm
255513 6.4 警告 VMware - VMware ACE の ACE 共有フォルダ実装における無効にされた共有フォルダを有効にされる脆弱性 CWE-noinfo
情報不足
CVE-2009-0908 2010-03-23 14:10 2010-04-3 Show GitHub Exploit DB Packet Storm
255514 2.1 注意 VMware - 複数の VMware 製品の VI Client におけるパスワードを取得される脆弱性 CWE-200
情報漏えい
CVE-2009-0518 2010-03-23 14:10 2010-04-3 Show GitHub Exploit DB Packet Storm
255515 4.4 警告 KVM
レッドハット
- KVM の x86 エミュレータにおける権限昇格の脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2010-0419 2010-03-23 14:09 2010-03-1 Show GitHub Exploit DB Packet Storm
255516 9.3 危険 マイクロソフト - 複数の Microsoft 製品における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2010-0263 2010-03-19 10:28 2010-03-9 Show GitHub Exploit DB Packet Storm
255517 9.3 危険 マイクロソフト - 複数の Microsoft 製品における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2010-0262 2010-03-19 10:28 2010-03-9 Show GitHub Exploit DB Packet Storm
255518 9.3 危険 マイクロソフト - 複数の Microsoft 製品におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2010-0261 2010-03-19 10:28 2010-03-9 Show GitHub Exploit DB Packet Storm
255519 9.3 危険 マイクロソフト - 複数の Microsoft 製品におけるヒープベースのバッファオーバーフローの脆弱性 CWE-94
コード・インジェクション
CVE-2010-0260 2010-03-19 10:28 2010-03-9 Show GitHub Exploit DB Packet Storm
255520 9.3 危険 マイクロソフト - 複数の Microsoft 製品における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2010-0258 2010-03-19 10:27 2010-03-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 16, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
211611 6.5 MEDIUM
Network
zohocorp manageengine_servicedesk_plus Zoho ManageEngine Service Plus before 11.1 build 11112 allows low-privilege authenticated users to discover the File Protection password via a getFileProtectionSettings call to AjaxServlet. CWE-862
 Missing Authorization
CVE-2020-13154 2024-11-21 14:00 2020-05-19 Show GitHub Exploit DB Packet Storm
211612 6.1 MEDIUM
Network
misp misp app/View/Events/resolved_attributes.ctp in MISP before 2.4.126 has XSS in the resolved attributes view. CWE-79
Cross-site Scripting
CVE-2020-13153 2024-11-21 14:00 2020-05-19 Show GitHub Exploit DB Packet Storm
211613 5.4 MEDIUM
Network
dolibarr dolibarr Dolibarr before 11.0.4 allows XSS. CWE-79
Cross-site Scripting
CVE-2020-13094 2024-11-21 14:00 2020-05-19 Show GitHub Exploit DB Packet Storm
211614 7.8 HIGH
Local
msi dragon_center Weak permissions on the "%PROGRAMDATA%\MSI\Dragon Center" folder in Dragon Center before 2.6.2003.2401, shipped with Micro-Star MSI Gaming laptops, allows local authenticated users to overwrite syste… CWE-276
Incorrect Default Permissions 
CVE-2020-13149 2024-11-21 14:00 2020-05-19 Show GitHub Exploit DB Packet Storm
211615 8.8 HIGH
Network
edx open_edx_platform Studio in Open edX Ironwood 2.5 allows CSV injection because an added cohort in Course>Instructor>Cohorts may contain a formula that is exported via the "Course>Data Downloads>Reports>Download profil… CWE-1236
 Improper Neutralization of Formula Elements in a CSV File
CVE-2020-13146 2024-11-21 14:00 2020-05-19 Show GitHub Exploit DB Packet Storm
211616 5.4 MEDIUM
Network
edx open_edx_platform Studio in Open edX Ironwood 2.5 allows users to upload SVG files via the "Content>File Uploads" screen. These files can contain JavaScript code and thus lead to Stored XSS. CWE-79
Cross-site Scripting
CVE-2020-13145 2024-11-21 14:00 2020-05-19 Show GitHub Exploit DB Packet Storm
211617 8.8 HIGH
Network
edx open_edx_platform Studio in Open edX Ironwood 2.5, when CodeJail is not used, allows a user to go to the "Create New course>New section>New subsection>New unit>Add new component>Problem button>Advanced tab>Custom Pyth… CWE-94
CWE-862
Code Injection
 Missing Authorization
CVE-2020-13144 2024-11-21 14:00 2020-05-19 Show GitHub Exploit DB Packet Storm
211618 6.5 MEDIUM
Network
linux
opensuse
debian
canonical
netapp
linux_kernel
leap
debian_linux
ubuntu_linux
cloud_backup
element_software
steelstore_cloud_integrated_storage
solidfire
hci_management_node
active_iq_unified_manager
sol…
gadget_dev_desc_UDC_store in drivers/usb/gadget/configfs.c in the Linux kernel 3.16 through 5.6.13 relies on kstrdup without considering the possibility of an internal '\0' value, which allows attack… CWE-125
Out-of-bounds Read
CVE-2020-13143 2024-11-21 14:00 2020-05-19 Show GitHub Exploit DB Packet Storm
211619 7.5 HIGH
Network
dlink dsp-w215_firmware D-Link DSP-W215 1.26b03 devices send an obfuscated hash that can be retrieved and understood by a network sniffer. NVD-CWE-noinfo
CVE-2020-13136 2024-11-21 14:00 2020-05-19 Show GitHub Exploit DB Packet Storm
211620 6.5 MEDIUM
Adjacent
dlink dsp-w215_firmware D-Link DSP-W215 1.26b03 devices allow information disclosure by intercepting messages on the local network, as demonstrated by a Squid Proxy. CWE-327
 Use of a Broken or Risky Cryptographic Algorithm
CVE-2020-13135 2024-11-21 14:00 2020-05-19 Show GitHub Exploit DB Packet Storm