Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 8, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
257461 4.7 警告 サイバートラスト株式会社
Linux
レッドハット
- Linux Kernel の gfs2_lock または gfs_lock 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2010-0727 2010-07-20 18:02 2010-03-16 Show GitHub Exploit DB Packet Storm
257462 4.3 警告 サン・マイクロシステムズ
サイバートラスト株式会社
Pango.org
レッドハット
- Pango の hb_ot_layout_build_glyph_classes 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2010-0421 2010-07-20 18:01 2010-03-15 Show GitHub Exploit DB Packet Storm
257463 4 警告 Samba Project
アップル
サイバートラスト株式会社
サン・マイクロシステムズ
ターボリナックス
レッドハット
- Samba の smbd におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2009-2906 2010-07-20 18:01 2009-10-7 Show GitHub Exploit DB Packet Storm
257464 1.9 注意 レッドハット
サイバートラスト株式会社
ターボリナックス
Samba Project
- Samba の mount.cifs における重要な情報を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2009-2948 2010-07-20 18:01 2009-10-7 Show GitHub Exploit DB Packet Storm
257465 6 警告 Samba Project
アップル
サイバートラスト株式会社
サン・マイクロシステムズ
ターボリナックス
ヒューレット・パッカード
レッドハット
- Apple Mac OS の SMB サブシステムにおけるファイル共有の制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2009-2813 2010-07-20 18:01 2009-09-10 Show GitHub Exploit DB Packet Storm
257466 5 警告 S2 Security - S2 Netbox に脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2010-2466 2010-07-16 18:41 2010-06-28 Show GitHub Exploit DB Packet Storm
257467 4.3 警告 シスコシステムズ - Cisco Adaptive Security Appliances デバイスの WebVPN における CRLF インジェクションの脆弱性 CWE-20
不適切な入力確認
CVE-2008-7257 2010-07-16 18:41 2010-06-29 Show GitHub Exploit DB Packet Storm
257468 7.5 危険 IBM - z/OS 上で稼働する IBM WebSphere Application Server における link インジェクションの脆弱性 CWE-noinfo
情報不足
CVE-2010-2324 2010-07-16 18:40 2010-06-2 Show GitHub Exploit DB Packet Storm
257469 5 警告 IBM - z/OS 上で稼働する IBM WebSphere Application Server における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2010-2323 2010-07-16 18:40 2010-03-22 Show GitHub Exploit DB Packet Storm
257470 10 危険 IBM - IBM Lotus Domino のサーバにおけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2010-0358 2010-07-16 15:35 2010-01-20 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 8, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
211231 6.1 MEDIUM
Network
hapifhir testpage_overlay Users of the HAPI FHIR Testpage Overlay 5.0.0 and below can use a specially crafted URL to exploit an XSS vulnerability in this module, allowing arbitrary JavaScript to be executed in the user's brow… CWE-79
Cross-site Scripting
CVE-2020-24301 2024-11-21 14:14 2020-10-8 Show GitHub Exploit DB Packet Storm
211232 7.5 HIGH
Network
peplink balance_20x_firmware
balance_310x_firmware
mbx_firmware
epx_firmware
sdx_firmware
balance_30_lte_firmware
balance_20_firmware
balance_30_firmware
balance_30_pro_firmware
ba…
Peplink Balance before 8.1.0rc1 allows an unauthenticated attacker to download PHP configuration files (/filemanager/php/connector.php) from Web Admin. NVD-CWE-noinfo
CVE-2020-24246 2024-11-21 14:14 2020-10-8 Show GitHub Exploit DB Packet Storm
211233 7.5 HIGH
Network
szuray iptv\/h.264_video_encoder_firmware
iptv\/h.265_video_encoder_firmware
An issue was discovered on URayTech IPTV/H.264/H.265 video encoders through 1.97. Attackers can send crafted unauthenticated HTTP requests to exploit path traversal and pattern-matching programming f… CWE-22
Path Traversal
CVE-2020-24219 2024-11-21 14:14 2020-10-6 Show GitHub Exploit DB Packet Storm
211234 9.8 CRITICAL
Network
szuray iptv\/h.264_video_encoder_firmware
iptv\/h.265_video_encoder_firmware
An issue was discovered on URayTech IPTV/H.264/H.265 video encoders through 1.97. Attackers can log in as root via the password that is hard-coded in the executable file. CWE-798
 Use of Hard-coded Credentials
CVE-2020-24218 2024-11-21 14:14 2020-10-6 Show GitHub Exploit DB Packet Storm
211235 9.8 CRITICAL
Network
szuray
jtechdigital
provideoinstruments
iptv\/h.264_video_encoder_firmware
iptv\/h.265_video_encoder_firmware
h.264_iptv_encoder_1080p\@60hz_firmware
vecaster-hd-h264_firmware
vecaster-hd-hevc_firmware
vecaster-4k-hevc_firmw…
An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. The file-upload endpoint does not enforce authentication. Attackers can send an unauthenticated HTTP… CWE-306
Missing Authentication for Critical Function
CVE-2020-24217 2024-11-21 14:14 2020-10-6 Show GitHub Exploit DB Packet Storm
211236 7.5 HIGH
Network
szuray
jtechdigital
provideoinstruments
iptv\/h.264_video_encoder_firmware
iptv\/h.265_video_encoder_firmware
h.264_iptv_encoder_1080p\@60hz_firmware
vecaster-hd-h264_firmware
vecaster-hd-hevc_firmware
vecaster-4k-hevc_firmw…
An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. When the administrator configures a secret URL for RTSP streaming, the stream is still available via… NVD-CWE-noinfo
CVE-2020-24216 2024-11-21 14:14 2020-10-6 Show GitHub Exploit DB Packet Storm
211237 6.1 MEDIUM
Network
car_rental_management_system_project car_rental_management_system A Persistent Cross-Site Scripting (XSS) vulnerability in message_admin.php in Projectworlds Car Rental Management System v1.0 allows unauthenticated remote attackers to harvest an admin login session… CWE-79
Cross-site Scripting
CVE-2020-23832 2024-11-21 14:14 2020-10-6 Show GitHub Exploit DB Packet Storm
211238 9.8 CRITICAL
Network
szuray
jtechdigital
provideoinstruments
iptv\/h.264_video_encoder_firmware
iptv\/h.265_video_encoder_firmware
h.264_iptv_encoder_1080p\@60hz_firmware
vecaster-hd-h264_firmware
vecaster-hd-hevc_firmware
vecaster-4k-hevc_firmw…
An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can use hard-coded credentials in HTTP requests to perform any administrative task on the … CWE-798
 Use of Hard-coded Credentials
CVE-2020-24215 2024-11-21 14:14 2020-10-6 Show GitHub Exploit DB Packet Storm
211239 9.8 CRITICAL
Network
szuray
jtechdigital
provideoinstruments
iptv\/h.264_video_encoder_firmware
iptv\/h.265_video_encoder_firmware
h.264_iptv_encoder_1080p\@60hz_firmware
vecaster-hd-h264_firmware
vecaster-hd-hevc_firmware
vecaster-4k-hevc_firmw…
An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can send a crafted unauthenticated RTSP request to cause a buffer overflow and application… NVD-CWE-Other
CVE-2020-24214 2024-11-21 14:14 2020-10-6 Show GitHub Exploit DB Packet Storm
211240 9.8 CRITICAL
Network
jumpmind symmetricds Symmetric DS <3.12.0 uses mx4j to provide access to JMX over HTTP. mx4j, by default, has no auth and is available on all interfaces. An attacker can interact with JMX: get system info, and invoke MBe… NVD-CWE-noinfo
CVE-2020-24231 2024-11-21 14:14 2020-10-6 Show GitHub Exploit DB Packet Storm