Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 18, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
226141 3.5 注意 uniformserver - The Uniform Server におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2010-2113 2012-12-20 19:29 2010-05-28 Show GitHub Exploit DB Packet Storm
226142 10 危険 timo gaik - Webby Webserver におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2010-2102 2012-12-20 19:29 2010-05-27 Show GitHub Exploit DB Packet Storm
226143 7.5 危険 UnrealIRCd - UnrealIRCd における任意のコマンドを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2010-2075 2012-12-20 19:29 2010-06-15 Show GitHub Exploit DB Packet Storm
226144 5 警告 radovan garabik - Pyftpd の auth_db_config.py における FTP サーバから任意のファイルを読まれる脆弱性 CWE-255
証明書・パスワード管理
CVE-2010-2073 2012-12-20 19:29 2010-06-13 Show GitHub Exploit DB Packet Storm
226145 3.6 注意 radovan garabik - Pyftpd におけるサービス運用妨害 (DoS) の脆弱性 CWE-310
暗号の問題
CVE-2010-2072 2012-12-20 19:29 2010-06-13 Show GitHub Exploit DB Packet Storm
226146 7.5 危険 wildbit - beanstalkd の put command 機能における任意の Beanstalk コマンドを実行される脆弱性 CWE-Other
その他
CVE-2010-2060 2012-12-20 19:29 2010-06-7 Show GitHub Exploit DB Packet Storm
226147 2.1 注意 prelude-technologies - Prewikka の setup.py における SQL データベースパスワードを取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2010-2058 2012-12-20 19:29 2010-06-7 Show GitHub Exploit DB Packet Storm
226148 10 危険 Standards Based Linux Instrumentation (SBLIM) - SBLIM SFCB の httpAdapter における整数オーバーフローの脆弱性 CWE-189
数値処理の問題
CVE-2010-2054 2012-12-20 19:29 2010-05-14 Show GitHub Exploit DB Packet Storm
226149 7.5 危険 shopex - ECShop の search.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-2042 2012-12-20 19:29 2010-05-25 Show GitHub Exploit DB Packet Storm
226150 4.3 警告 php-calendar project - PHP-Calendar の index.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-2041 2012-12-20 19:29 2010-05-25 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 18, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
213371 2.2 LOW
Network
freerdp
canonical
debian
freerdp
ubuntu_linux
debian_linux
In FreeRDP greater than 1.2 and before 2.0.0, a double free in update_read_cache_bitmap_v3_order crashes the client application if corrupted data from a manipulated server is parsed. This has been pa… - CVE-2020-11044 2024-11-21 13:56 2020-05-8 Show GitHub Exploit DB Packet Storm
213372 5.9 MEDIUM
Network
freerdp
debian
canonical
freerdp
debian_linux
ubuntu_linux
In FreeRDP greater than 1.1 and before 2.0.0, there is an out-of-bounds read in update_read_icon_info. It allows reading a attacker-defined amount of client memory (32bit unsigned -> 4GB) to an inter… - CVE-2020-11042 2024-11-21 13:56 2020-05-8 Show GitHub Exploit DB Packet Storm
213373 7.5 HIGH
Network
wavlink wl-wn575a3_firmware
wl-wn579g3_firmware
wn531a6_firmware
wn535g3_firmware
wn530h4_firmware
wn57x93_firmware
wn572hg3_firmware
wn575a4_firmware
wn578a2_firmware
wn579g3_firm…
An issue was discovered affecting a backup feature where a crafted POST request returns the current configuration of the device in cleartext, including the administrator password. No authentication i… CWE-306
Missing Authentication for Critical Function
CVE-2020-10974 2024-11-21 13:56 2020-05-8 Show GitHub Exploit DB Packet Storm
213374 7.5 HIGH
Network
wavlink wn530hg4_firmware
wn531g3_firmware
wn533a8_firmware
wn551k1_firmware
An issue was discovered in Wavlink WN530HG4, Wavlink WN531G3, Wavlink WN533A8, and Wavlink WN551K1 affecting /cgi-bin/ExportAllSettings.sh where a crafted POST request returns the current configurati… CWE-306
Missing Authentication for Critical Function
CVE-2020-10973 2024-11-21 13:56 2020-05-8 Show GitHub Exploit DB Packet Storm
213375 7.5 HIGH
Network
wavlink wn530hg4_firmware
wn531g3_firmware
wn572hg3_firmware
An issue was discovered where a page is exposed that has the current administrator password in cleartext in the source code of the page. No authentication is required in order to reach the page (a ce… CWE-306
CWE-522
Missing Authentication for Critical Function
 Insufficiently Protected Credentials
CVE-2020-10972 2024-11-21 13:56 2020-05-8 Show GitHub Exploit DB Packet Storm
213376 8.8 HIGH
Network
wavlink wl-wn575a3_firmware
wl-wn530hg4_firmware
wl-wn579g3_firmware
An issue was discovered on Wavlink Jetstream devices where a crafted POST request can be sent to adm.cgi that will result in the execution of the supplied command if there is an active session at the… CWE-20
 Improper Input Validation 
CVE-2020-10971 2024-11-21 13:56 2020-05-8 Show GitHub Exploit DB Packet Storm
213377 5.4 MEDIUM
Network
glpi-project glpi In GLPI before version 9.4.6 there are multiple related stored XSS vulnerabilities. The package is vulnerable to Stored XSS in the comments of items in the Knowledge base. Adding a comment with conte… CWE-79
Cross-site Scripting
CVE-2020-11036 2024-11-21 13:56 2020-05-6 Show GitHub Exploit DB Packet Storm
213378 9.3 CRITICAL
Network
glpi-project
fedoraproject
glpi
fedora
In GLPI after version 0.83.3 and before version 9.4.6, the CSRF tokens are generated using an insecure algorithm. The implementation uses rand and uniqid and MD5 which does not provide secure values.… CWE-327
 Use of a Broken or Risky Cryptographic Algorithm
CVE-2020-11035 2024-11-21 13:56 2020-05-6 Show GitHub Exploit DB Packet Storm
213379 6.1 MEDIUM
Network
glpi-project glpi In GLPI before version 9.4.6, there is a vulnerability that allows bypassing the open redirect protection based which is based on a regexp. This is fixed in version 9.4.6. CWE-601
Open Redirect
CVE-2020-11034 2024-11-21 13:56 2020-05-6 Show GitHub Exploit DB Packet Storm
213380 7.2 HIGH
Network
glpi-project glpi In GLPI before version 9.4.6, there is a SQL injection vulnerability for all helpdesk instances. Exploiting this vulnerability requires a technician account. This is fixed in version 9.4.6. CWE-89
SQL Injection
CVE-2020-11032 2024-11-21 13:56 2020-05-6 Show GitHub Exploit DB Packet Storm