Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 12, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
226471 4.3 警告 tangocms - TangoCMS の application/libraries/Html.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-2376 2012-12-20 19:10 2009-07-8 Show GitHub Exploit DB Packet Storm
226472 6.8 警告 wxwidgets - wxWidgets の src/common/image.cpp における整数オーバーフローの脆弱性 CWE-189
数値処理の問題
CVE-2009-2369 2012-12-20 19:10 2009-07-8 Show GitHub Exploit DB Packet Storm
226473 9.3 危険 yukudr - KUDRSOFT AudioPLUS におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-2363 2012-12-20 19:10 2009-07-8 Show GitHub Exploit DB Packet Storm
226474 9.3 危険 yukudr - KUDRSOFT AudioPLUS におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-2362 2012-12-20 19:10 2009-07-8 Show GitHub Exploit DB Packet Storm
226475 7.5 危険 yasinkaplan - TekRADIUS における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-2359 2012-12-20 19:10 2009-07-7 Show GitHub Exploit DB Packet Storm
226476 4.6 警告 yasinkaplan - TekRADIUS における難読化したデータベース資格情報を取得される脆弱性 CWE-255
証明書・パスワード管理
CVE-2009-2358 2012-12-20 19:10 2009-07-7 Show GitHub Exploit DB Packet Storm
226477 10 危険 yasinkaplan - TekRADIUS のデフォルト設定におけるデータベースへのアクセス権限を取得される脆弱性 CWE-16
環境設定
CVE-2009-2357 2012-12-20 19:10 2009-07-7 Show GitHub Exploit DB Packet Storm
226478 4 警告 dan cahill - NullLogic Groupware のフォーラムモジュールにおけるサービス運用妨害 (DoS) の脆弱性 CWE-189
数値処理の問題
CVE-2009-2355 2012-12-20 19:10 2009-07-7 Show GitHub Exploit DB Packet Storm
226479 9 危険 Sourcefire - Sourcefire DC および 3D Sensor の Web ベースの管理インターフェースにおける権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2009-2344 2012-12-20 19:10 2009-07-7 Show GitHub Exploit DB Packet Storm
226480 4.3 警告 Zoph - Zoph の people.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-2343 2012-12-20 19:10 2009-07-7 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 12, 2026, 5:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
196781 9.8 CRITICAL
Network
karma-mojo_project karma-mojo karma-mojo through 1.0.1 is vulnerable to Command Injection. It allows execution of arbitrary commands via the config argument. CWE-78
OS Command 
CVE-2020-7626 2024-11-21 14:37 2020-04-3 Show GitHub Exploit DB Packet Storm
196782 9.8 CRITICAL
Network
op-browser_project op-browser op-browser through 1.0.6 is vulnerable to Command Injection. It allows execution of arbitrary commands via the url function. CWE-78
OS Command 
CVE-2020-7625 2024-11-21 14:37 2020-04-3 Show GitHub Exploit DB Packet Storm
196783 9.8 CRITICAL
Network
effect_project effect effect through 1.0.4 is vulnerable to Command Injection. It allows execution of arbitrary command via the options argument. CWE-78
OS Command 
CVE-2020-7624 2024-11-21 14:37 2020-04-3 Show GitHub Exploit DB Packet Storm
196784 9.8 CRITICAL
Network
jscover_project jscover jscover through 1.0.0 is vulnerable to Command Injection. It allows execution of arbitrary command via the source argument. CWE-78
OS Command 
CVE-2020-7623 2024-11-21 14:37 2020-04-3 Show GitHub Exploit DB Packet Storm
196785 9.8 CRITICAL
Network
ibm strongloop_nginx_controller strong-nginx-controller through 1.0.2 is vulnerable to Command Injection. It allows execution of arbitrary command as part of the '_nginxCmd()' function. CWE-78
OS Command 
CVE-2020-7621 2024-11-21 14:37 2020-04-3 Show GitHub Exploit DB Packet Storm
196786 9.8 CRITICAL
Network
netease pomelo-monitor pomelo-monitor through 0.3.7 is vulnerable to Command Injection.It allows injection of arbitrary commands as part of 'pomelo-monitor' params. CWE-78
OS Command 
CVE-2020-7620 2024-11-21 14:37 2020-04-3 Show GitHub Exploit DB Packet Storm
196787 9.8 CRITICAL
Network
get-git-data_project get-git-data get-git-data through 1.3.1 is vulnerable to Command Injection. It is possible to inject arbitrary commands as part of the arguments provided to get-git-data. CWE-78
OS Command 
CVE-2020-7619 2024-11-21 14:37 2020-04-3 Show GitHub Exploit DB Packet Storm
196788 9.8 CRITICAL
Network
ini-parser_project ini-parser ini-parser through 0.0.2 is vulnerable to Prototype Pollution.The library could be tricked into adding or modifying properties of Object.prototype using a '__proto__' payload. CWE-1321
 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVE-2020-7617 2024-11-21 14:37 2020-04-3 Show GitHub Exploit DB Packet Storm
196789 9.8 CRITICAL
Network
objectcomputing micronaut All versions of io.micronaut:micronaut-http-client before 1.2.11 and all versions from 1.3.0 before 1.3.2 are vulnerable to HTTP Request Header Injection due to not validating request headers passed … CWE-444
HTTP Request Smuggling
CVE-2020-7611 2024-11-21 14:37 2020-03-31 Show GitHub Exploit DB Packet Storm
196790 9.8 CRITICAL
Network
mongodb bson All versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted Data. The package will ignore an unknown value for an object's _bsotype, leading to cases where an object is serialize… CWE-502
 Deserialization of Untrusted Data
CVE-2020-7610 2024-11-21 14:37 2020-03-31 Show GitHub Exploit DB Packet Storm