Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 12, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
226121 7.5 危険 PowerDNS - PowerDNS Recursor における DNS データを偽装される脆弱性 CWE-noinfo
情報不足
CVE-2009-4010 2012-12-20 19:28 2010-01-6 Show GitHub Exploit DB Packet Storm
226122 10 危険 PowerDNS - PowerDNS Recursor におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-4009 2012-12-20 19:28 2010-01-6 Show GitHub Exploit DB Packet Storm
226123 9.3 危険 XnSoft - XnView における整数オーバーフローの脆弱性 CWE-189
数値処理の問題
CVE-2009-4001 2012-12-20 19:28 2010-03-15 Show GitHub Exploit DB Packet Storm
226124 5 警告 phpMyBackupPro - phpMyBackupPro の get_file.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2009-4050 2012-12-20 19:28 2009-11-23 Show GitHub Exploit DB Packet Storm
226125 5 警告 usebb - UseBB におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2009-4041 2012-12-20 19:28 2009-10-25 Show GitHub Exploit DB Packet Storm
226126 4.3 警告 phpMyFAQ - phpMyFAQ におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4040 2012-12-20 19:28 2009-09-1 Show GitHub Exploit DB Packet Storm
226127 4.3 警告 Piwigo - Piwigo におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4039 2012-12-20 19:28 2009-11-20 Show GitHub Exploit DB Packet Storm
226128 10 危険 Rhino Software - RhinoSoft Serv-U FTP サーバの TEA デコードアルゴリズムにおけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-4006 2012-12-20 19:28 2009-11-20 Show GitHub Exploit DB Packet Storm
226129 7.5 危険 turnkeyarcade - Turnkey Arcade Script の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-3973 2012-12-20 19:28 2009-11-18 Show GitHub Exploit DB Packet Storm
226130 7.5 危険 qproje - Joomla! 用の siirler コンポーネントにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-3972 2012-12-20 19:28 2009-11-18 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 13, 2026, 5:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
197271 6.7 MEDIUM
Local
siemens simatic_pcs_7
simatic_wincc
simatic_wincc_runtime_advanced
sinema_server
simatic_net_pc
simatic_prosave
simatic_pcs_neo
simatic_automatic_tool
simatic_step_7
simatic_wincc_…
A vulnerability has been identified in SIMATIC Automation Tool (All versions < V4 SP2), SIMATIC NET PC Software V14 (All versions < V14 SP1 Update 14), SIMATIC NET PC Software V15 (All versions), SIM… - CVE-2020-7580 2024-11-21 14:37 2020-06-11 Show GitHub Exploit DB Packet Storm
197272 8.6 HIGH
Network
mosc_project mosc mosc through 1.0.0 is vulnerable to Arbitrary Code Execution. User input provided to `properties` argument is executed by the `eval` function, resulting in code execution. CWE-94
Code Injection
CVE-2020-7672 2024-11-21 14:37 2020-06-11 Show GitHub Exploit DB Packet Storm
197273 7.5 HIGH
Network
goliath_project goliath goliath through 1.0.6 allows request smuggling attacks where goliath is used as a backend and a frontend proxy also being vulnerable. It is possible to conduct HTTP request smuggling attacks by sendi… CWE-444
HTTP Request Smuggling
CVE-2020-7671 2024-11-21 14:37 2020-06-11 Show GitHub Exploit DB Packet Storm
197274 7.5 HIGH
Network
ohler agoo agoo prior to 2.14.0 allows request smuggling attacks where agoo is used as a backend and a frontend proxy also being vulnerable. HTTP pipelining issues and request smuggling attacks might be possibl… CWE-444
HTTP Request Smuggling
CVE-2020-7670 2024-11-21 14:37 2020-06-11 Show GitHub Exploit DB Packet Storm
197275 6.8 MEDIUM
Physics
freebsd
netapp
freebsd
clustered_data_ontap
In FreeBSD 12.1-STABLE before r361918, 12.1-RELEASE before p6, 11.4-STABLE before r361919, 11.3-RELEASE before p10, and 11.4-RC2 before p1, an invalid memory location may be used for HID items if the… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2020-7456 2024-11-21 14:37 2020-06-10 Show GitHub Exploit DB Packet Storm
197276 5.4 MEDIUM
Network
angularjs angular.js angular.js prior to 1.8.0 allows cross site scripting. The regex-based input HTML replacement may turn sanitized code into unsanitized one. Wrapping "<option>" elements in "<select>" ones changes par… CWE-79
Cross-site Scripting
CVE-2020-7676 2024-11-21 14:37 2020-06-8 Show GitHub Exploit DB Packet Storm
197277 7.5 HIGH
Network
url-regex_project url-regex all versions of url-regex are vulnerable to Regular Expression Denial of Service. An attacker providing a very long string in String.test can cause a Denial of Service. CWE-400
 Uncontrolled Resource Consumption
CVE-2020-7661 2024-11-21 14:37 2020-06-5 Show GitHub Exploit DB Packet Storm
197278 7.5 HIGH
Network
websocket-extensions_project
debian
canonical
websocket-extensions
debian_linux
ubuntu_linux
websocket-extensions ruby module prior to 0.1.5 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing an unclosed string… NVD-CWE-Other
CVE-2020-7663 2024-11-21 14:37 2020-06-3 Show GitHub Exploit DB Packet Storm
197279 7.5 HIGH
Network
websocket-extensions_project websocket-extensions websocket-extensions npm module prior to 0.1.4 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing an unclosed string … NVD-CWE-Other
CVE-2020-7662 2024-11-21 14:37 2020-06-3 Show GitHub Exploit DB Packet Storm
197280 8.1 HIGH
Network
verizon serialize-javascript serialize-javascript prior to 3.1.0 allows remote attackers to inject arbitrary code via the function "deleteFunctions" within "index.js". CWE-502
 Deserialization of Untrusted Data
CVE-2020-7660 2024-11-21 14:37 2020-06-2 Show GitHub Exploit DB Packet Storm