Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 15, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
258641 6.8 警告 アップル
SquirrelMail Project
- SquirrelMail におけるセッション固定の脆弱性 CWE-287
不適切な認証
CVE-2009-1580 2010-07-6 19:18 2009-05-11 Show GitHub Exploit DB Packet Storm
258642 6.8 警告 アップル
サイバートラスト株式会社
レッドハット
SquirrelMail Project
- SquirrelMail における任意のコマンドを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2009-1579 2010-07-6 19:18 2009-05-10 Show GitHub Exploit DB Packet Storm
258643 4.3 警告 アップル
サイバートラスト株式会社
レッドハット
SquirrelMail Project
- SquirrelMail におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-1578 2010-07-6 19:18 2009-05-8 Show GitHub Exploit DB Packet Storm
258644 8.5 危険 マイクロソフト - Microsoft IIS における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2010-1256 2010-07-5 17:52 2010-06-8 Show GitHub Exploit DB Packet Storm
258645 4 警告 マイクロソフト - Microsoft Windows SharePoint Services におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2010-1264 2010-07-5 17:52 2010-06-8 Show GitHub Exploit DB Packet Storm
258646 6.9 警告 マイクロソフト - Open XML File Format Converter のインストールにおける任意のコードを実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2010-1254 2010-07-5 17:52 2010-06-8 Show GitHub Exploit DB Packet Storm
258647 9.3 危険 マイクロソフト - 複数の Microsoft 製品の Excel ファイルにおける任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2010-1252 2010-07-5 17:51 2010-06-8 Show GitHub Exploit DB Packet Storm
258648 9.3 危険 マイクロソフト - 複数の Microsoft 製品の Excel ファイルにおける任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2010-1251 2010-07-5 17:51 2010-06-8 Show GitHub Exploit DB Packet Storm
258649 9.3 危険 マイクロソフト - 複数の Microsoft 製品の Excel ファイルにおけるヒープベースのバッファオーバーフローの脆弱性 CWE-94
コード・インジェクション
CVE-2010-1250 2010-07-5 17:51 2010-06-8 Show GitHub Exploit DB Packet Storm
258650 4.3 警告 アップル
サイバートラスト株式会社
レッドハット
ターボリナックス
CUPS
- CUPS の cupsd におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2010-0302 2010-07-5 17:03 2010-03-3 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 15, 2026, 4:10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
211181 5.4 MEDIUM
Network
yourls yourls Multiple Stored Cross Site Scripting (XSS) vulnerabilities exist in the YOURLS Admin Panel, Versions 1.5 - 1.7.10. An authenticated user must modify a PHP plugin with a malicious payload and upload i… CWE-79
Cross-site Scripting
CVE-2020-27388 2024-11-21 14:21 2020-10-24 Show GitHub Exploit DB Packet Storm
211182 4.7 MEDIUM
Local
linux
fedoraproject
debian
linux_kernel
fedora
debian_linux
An issue was discovered in the Linux kernel through 5.9.1, as used with Xen through 4.14.x. drivers/xen/events/events_base.c allows event-channel removal during the event-handling loop (a race condit… CWE-362
CWE-476
CWE-416
Race Condition
 NULL Pointer Dereference
 Use After Free
CVE-2020-27675 2024-11-21 14:21 2020-10-23 Show GitHub Exploit DB Packet Storm
211183 5.3 MEDIUM
Local
xen
fedoraproject
debian
xen
fedora
debian_linux
An issue was discovered in Xen through 4.14.x allowing x86 PV guest OS users to gain guest OS privileges by modifying kernel memory contents, because invalidation of TLB entries is mishandled during … CWE-787
 Out-of-bounds Write
CVE-2020-27674 2024-11-21 14:21 2020-10-23 Show GitHub Exploit DB Packet Storm
211184 5.5 MEDIUM
Local
linux
debian
opensuse
xen
linux_kernel
debian_linux
leap
xen
An issue was discovered in the Linux kernel through 5.9.1, as used with Xen through 4.14.x. Guest OS users can cause a denial of service (host OS hang) via a high rate of events to dom0, aka CID-e995… NVD-CWE-noinfo
CVE-2020-27673 2024-11-21 14:21 2020-10-23 Show GitHub Exploit DB Packet Storm
211185 7.0 HIGH
Local
xen
fedoraproject
opensuse
debian
xen
fedora
leap
debian_linux
An issue was discovered in Xen through 4.14.x allowing x86 guest OS users to cause a host OS denial of service, achieve data corruption, or possibly gain privileges by exploiting a race condition tha… CWE-362
CWE-416
Race Condition
 Use After Free
CVE-2020-27672 2024-11-21 14:21 2020-10-23 Show GitHub Exploit DB Packet Storm
211186 7.8 HIGH
Local
xen
opensuse
debian
fedoraproject
xen
leap
debian_linux
fedora
An issue was discovered in Xen through 4.14.x allowing x86 HVM and PVH guest OS users to cause a denial of service (data corruption), cause a data leak, or possibly gain privileges because coalescing… NVD-CWE-noinfo
CVE-2020-27671 2024-11-21 14:21 2020-10-23 Show GitHub Exploit DB Packet Storm
211187 7.8 HIGH
Local
xen
opensuse
fedoraproject
debian
xen
leap
fedora
debian_linux
An issue was discovered in Xen through 4.14.x allowing x86 guest OS users to cause a denial of service (data corruption), cause a data leak, or possibly gain privileges because an AMD IOMMU page-tabl… CWE-345
 Insufficient Verification of Data Authenticity
CVE-2020-27670 2024-11-21 14:21 2020-10-23 Show GitHub Exploit DB Packet Storm
211188 5.4 MEDIUM
Network
strapi strapi Strapi before 3.2.5 has stored XSS in the wysiwyg editor's preview feature. CWE-79
Cross-site Scripting
CVE-2020-27666 2024-11-21 14:21 2020-10-23 Show GitHub Exploit DB Packet Storm
211189 7.5 HIGH
Network
strapi strapi In Strapi before 3.2.5, there is no admin::hasPermissions restriction for CTB (aka content-type-builder) routes. CWE-276
Incorrect Default Permissions 
CVE-2020-27665 2024-11-21 14:21 2020-10-23 Show GitHub Exploit DB Packet Storm
211190 9.8 CRITICAL
Network
strapi strapi admin/src/containers/InputModalStepperProvider/index.js in Strapi before 3.2.5 has unwanted /proxy?url= functionality. NVD-CWE-noinfo
CVE-2020-27664 2024-11-21 14:21 2020-10-23 Show GitHub Exploit DB Packet Storm