Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 10, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
258761 9.3 危険 マイクロソフト - Microsoft Windows の Web Services on Devices API (WSDAPI) における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2009-2512 2010-01-4 15:23 2009-11-10 Show GitHub Exploit DB Packet Storm
258762 10 危険 アップル
VMware
サン・マイクロシステムズ
- Sun Java SE の Provider クラスにおける詳細不明な脆弱性 CWE-noinfo
情報不足
CVE-2009-2722 2010-01-4 14:56 2009-08-10 Show GitHub Exploit DB Packet Storm
258763 10 危険 アップル
VMware
サン・マイクロシステムズ
- Sun Java SE の Provider クラスにおける詳細不明な脆弱性 CWE-noinfo
情報不足
CVE-2009-2723 2010-01-4 14:55 2009-08-10 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 11, 2026, 5:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
217901 7.5 HIGH
Network
nlnetlabs
debian
opensuse
canonical
fedoraproject
unbound
debian_linux
leap
ubuntu_linux
fedora
Unbound before 1.10.1 has an infinite loop via malformed DNS answers received from upstream servers. CWE-835
 Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2020-12663 2024-11-21 14:00 2020-05-19 Show GitHub Exploit DB Packet Storm
217902 7.5 HIGH
Network
nlnetlabs
debian
opensuse
canonical
fedoraproject
unbound
debian_linux
leap
ubuntu_linux
fedora
Unbound before 1.10.1 has Insufficient Control of Network Message Volume, aka an "NXNSAttack" issue. This is triggered by random subdomains in the NSDNAME in NS records. CWE-400
 Uncontrolled Resource Consumption
CVE-2020-12662 2024-11-21 14:00 2020-05-19 Show GitHub Exploit DB Packet Storm
217903 7.5 HIGH
Network
nic knot_resolver Knot Resolver before 5.1.1 allows traffic amplification via a crafted DNS answer from an attacker-controlled server, aka an "NXNSAttack" issue. This is triggered by random subdomains in the NSDNAME i… CWE-400
 Uncontrolled Resource Consumption
CVE-2020-12667 2024-11-21 14:00 2020-05-19 Show GitHub Exploit DB Packet Storm
217904 6.5 MEDIUM
Network
zohocorp manageengine_servicedesk_plus Zoho ManageEngine Service Plus before 11.1 build 11112 allows low-privilege authenticated users to discover the File Protection password via a getFileProtectionSettings call to AjaxServlet. CWE-862
 Missing Authorization
CVE-2020-13154 2024-11-21 14:00 2020-05-19 Show GitHub Exploit DB Packet Storm
217905 6.1 MEDIUM
Network
misp misp app/View/Events/resolved_attributes.ctp in MISP before 2.4.126 has XSS in the resolved attributes view. CWE-79
Cross-site Scripting
CVE-2020-13153 2024-11-21 14:00 2020-05-19 Show GitHub Exploit DB Packet Storm
217906 5.4 MEDIUM
Network
dolibarr dolibarr Dolibarr before 11.0.4 allows XSS. CWE-79
Cross-site Scripting
CVE-2020-13094 2024-11-21 14:00 2020-05-19 Show GitHub Exploit DB Packet Storm
217907 7.8 HIGH
Local
msi dragon_center Weak permissions on the "%PROGRAMDATA%\MSI\Dragon Center" folder in Dragon Center before 2.6.2003.2401, shipped with Micro-Star MSI Gaming laptops, allows local authenticated users to overwrite syste… CWE-276
Incorrect Default Permissions 
CVE-2020-13149 2024-11-21 14:00 2020-05-19 Show GitHub Exploit DB Packet Storm
217908 8.8 HIGH
Network
edx open_edx_platform Studio in Open edX Ironwood 2.5 allows CSV injection because an added cohort in Course>Instructor>Cohorts may contain a formula that is exported via the "Course>Data Downloads>Reports>Download profil… CWE-1236
 Improper Neutralization of Formula Elements in a CSV File
CVE-2020-13146 2024-11-21 14:00 2020-05-19 Show GitHub Exploit DB Packet Storm
217909 5.4 MEDIUM
Network
edx open_edx_platform Studio in Open edX Ironwood 2.5 allows users to upload SVG files via the "Content>File Uploads" screen. These files can contain JavaScript code and thus lead to Stored XSS. CWE-79
Cross-site Scripting
CVE-2020-13145 2024-11-21 14:00 2020-05-19 Show GitHub Exploit DB Packet Storm
217910 8.8 HIGH
Network
edx open_edx_platform Studio in Open edX Ironwood 2.5, when CodeJail is not used, allows a user to go to the "Create New course>New section>New subsection>New unit>Add new component>Problem button>Advanced tab>Custom Pyth… CWE-94
CWE-862
Code Injection
 Missing Authorization
CVE-2020-13144 2024-11-21 14:00 2020-05-19 Show GitHub Exploit DB Packet Storm