Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 27, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
255851 6.8 警告 w3m project
ターボリナックス
サイバートラスト株式会社
レッドハット
- w3m のistream.c における X.509 証明書の処理に関する任意の SSL サーバになりすまされる脆弱性 CWE-20
不適切な入力確認
CVE-2010-2074 2010-09-27 16:24 2010-06-16 Show GitHub Exploit DB Packet Storm
255852 6.8 警告 レッドハット
サイバートラスト株式会社
ターボリナックス
OpenLDAP Foundation
- OpenLDAP における任意の SSL サーバになりすまされる脆弱性 CWE-310
暗号の問題
CVE-2009-3767 2010-09-27 16:23 2009-10-23 Show GitHub Exploit DB Packet Storm
255853 4.3 警告 Opera Software ASA - Opera におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2010-3021 2010-09-27 16:21 2010-08-12 Show GitHub Exploit DB Packet Storm
255854 5 警告 Opera Software ASA - Opera の news-feed プレビュー機能における任意のフィードの購読を強制される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2010-3020 2010-09-27 16:21 2010-08-12 Show GitHub Exploit DB Packet Storm
255855 9.3 危険 Opera Software ASA - Opera におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2010-3019 2010-09-27 16:21 2010-08-12 Show GitHub Exploit DB Packet Storm
255856 9.3 危険 Opera Software ASA - Windows および Mac OS X 上で稼働する Opera における任意のコードを実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2010-2666 2010-09-27 16:20 2010-06-21 Show GitHub Exploit DB Packet Storm
255857 4.3 警告 Opera Software ASA - Opera における URI の処理に関するクロスサイトスクリプティングの脆弱性\ CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-2665 2010-09-27 16:20 2010-06-21 Show GitHub Exploit DB Packet Storm
255858 4.3 警告 Opera Software ASA - Opera の HTML コンテンツにおけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2010-2664 2010-09-27 16:20 2010-07-1 Show GitHub Exploit DB Packet Storm
255859 4.3 警告 Opera Software ASA - Opera におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2010-2663 2010-09-27 16:20 2010-07-1 Show GitHub Exploit DB Packet Storm
255860 4.3 警告 Opera Software ASA - Opera におけるポップアップブロッカーを回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2010-2662 2010-09-27 16:20 2010-07-1 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 27, 2026, 4:52 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
213421 8.8 HIGH
Network
edx open_edx_platform Studio in Open edX Ironwood 2.5 allows CSV injection because an added cohort in Course>Instructor>Cohorts may contain a formula that is exported via the "Course>Data Downloads>Reports>Download profil… CWE-1236
 Improper Neutralization of Formula Elements in a CSV File
CVE-2020-13146 2024-11-21 14:00 2020-05-19 Show GitHub Exploit DB Packet Storm
213422 5.4 MEDIUM
Network
edx open_edx_platform Studio in Open edX Ironwood 2.5 allows users to upload SVG files via the "Content>File Uploads" screen. These files can contain JavaScript code and thus lead to Stored XSS. CWE-79
Cross-site Scripting
CVE-2020-13145 2024-11-21 14:00 2020-05-19 Show GitHub Exploit DB Packet Storm
213423 8.8 HIGH
Network
edx open_edx_platform Studio in Open edX Ironwood 2.5, when CodeJail is not used, allows a user to go to the "Create New course>New section>New subsection>New unit>Add new component>Problem button>Advanced tab>Custom Pyth… CWE-94
CWE-862
Code Injection
 Missing Authorization
CVE-2020-13144 2024-11-21 14:00 2020-05-19 Show GitHub Exploit DB Packet Storm
213424 6.5 MEDIUM
Network
linux
opensuse
debian
canonical
netapp
linux_kernel
leap
debian_linux
ubuntu_linux
cloud_backup
element_software
steelstore_cloud_integrated_storage
solidfire
hci_management_node
active_iq_unified_manager
sol…
gadget_dev_desc_UDC_store in drivers/usb/gadget/configfs.c in the Linux kernel 3.16 through 5.6.13 relies on kstrdup without considering the possibility of an internal '\0' value, which allows attack… CWE-125
Out-of-bounds Read
CVE-2020-13143 2024-11-21 14:00 2020-05-19 Show GitHub Exploit DB Packet Storm
213425 7.5 HIGH
Network
dlink dsp-w215_firmware D-Link DSP-W215 1.26b03 devices send an obfuscated hash that can be retrieved and understood by a network sniffer. NVD-CWE-noinfo
CVE-2020-13136 2024-11-21 14:00 2020-05-19 Show GitHub Exploit DB Packet Storm
213426 6.5 MEDIUM
Adjacent
dlink dsp-w215_firmware D-Link DSP-W215 1.26b03 devices allow information disclosure by intercepting messages on the local network, as demonstrated by a Squid Proxy. CWE-327
 Use of a Broken or Risky Cryptographic Algorithm
CVE-2020-13135 2024-11-21 14:00 2020-05-19 Show GitHub Exploit DB Packet Storm
213427 5.3 MEDIUM
Network
libreoffice
opensuse
libreoffice
leap
If LibreOffice has an encrypted document open and crashes, that document is auto-saved encrypted. On restart, LibreOffice offers to restore the document and prompts for the password to decrypt it. If… CWE-312
 Cleartext Storage of Sensitive Information
CVE-2020-12801 2024-11-21 14:00 2020-05-19 Show GitHub Exploit DB Packet Storm
213428 7.2 HIGH
Network
heinekingmedia stashcat An issue was discovered in the stashcat app through 3.9.1 for macOS, Windows, Android, iOS, and possibly other platforms. The GET method is used with client_key and device_id data in the query string… CWE-200
Information Exposure
CVE-2020-13129 2024-11-21 14:00 2020-05-18 Show GitHub Exploit DB Packet Storm
213429 5.3 MEDIUM
Network
health covidsafe COVIDSafe through v1.0.17 allows a remote attacker to access phone name and model information because a BLE device can have four roles and COVIDSafe uses all of them. This allows for re-identificatio… CWE-269
 Improper Privilege Management
CVE-2020-12860 2024-11-21 14:00 2020-05-18 Show GitHub Exploit DB Packet Storm
213430 5.3 MEDIUM
Network
health covidsafe Unnecessary fields in the OpenTrace/BlueTrace protocol in COVIDSafe through v1.0.17 allow a remote attacker to identify a device model by observing cleartext payload data. This allows re-identificati… CWE-312
 Cleartext Storage of Sensitive Information
CVE-2020-12859 2024-11-21 14:00 2020-05-18 Show GitHub Exploit DB Packet Storm