Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 11, 2026, 12:16 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
226511 6.8 警告 sebastian-thiele - ST-Gallery の st_admin/gallery_output.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-1799 2012-12-20 19:10 2009-05-28 Show GitHub Exploit DB Packet Storm
226512 4.3 警告 サン・マイクロシステムズ - Sun Java System Portal Server におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-1796 2012-12-20 19:10 2009-05-22 Show GitHub Exploit DB Packet Storm
226513 9.3 危険 stonetrip - StoneTrip Ston3D StandalonePlayer および WebPlayer の system.openURL 関数における任意のコマンドを実行される脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2009-1792 2012-12-20 19:10 2009-05-29 Show GitHub Exploit DB Packet Storm
226514 7.5 危険 phpdirsubmit - PHP Dir Submit における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-1787 2012-12-20 19:10 2009-05-26 Show GitHub Exploit DB Packet Storm
226515 4.3 警告 ulteo - Ulteo Open Virtual Desktop におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-1785 2012-12-20 19:10 2009-05-22 Show GitHub Exploit DB Packet Storm
226516 6.8 警告 roboform - Frax.dk Php Recommend の admin.php における phpre_config.php へ任意の PHP コードを挿入される脆弱性 CWE-94
コード・インジェクション
CVE-2009-1781 2012-12-20 19:10 2009-05-22 Show GitHub Exploit DB Packet Storm
226517 7.5 危険 roboform - Frax.dk Php Recommend の admin.php における管理者権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2009-1780 2012-12-20 19:10 2009-05-22 Show GitHub Exploit DB Packet Storm
226518 6.8 警告 roboform - Frax.dk Php Recommend の admin.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2009-1779 2012-12-20 19:10 2009-05-22 Show GitHub Exploit DB Packet Storm
226519 4.3 警告 ulteo - Ulteo Open Virtual Desktop におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-1775 2012-12-20 19:10 2009-05-22 Show GitHub Exploit DB Packet Storm
226520 9.3 危険 strawberry - Strawberry の plugins/ddb/foot.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2009-1774 2012-12-20 19:10 2009-05-22 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 11, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
196881 9.8 CRITICAL
Network
cacagoo tv-288zd-2mp_firmware CACAGOO Cloud Storage Intelligent Camera TV-288ZD-2MP with firmware 3.4.2.0919 has weak authentication of TELNET access, leading to root privileges without any password required. CWE-307
mproper Restriction of Excessive Authentication Attempts
CVE-2020-6852 2024-11-21 14:36 2020-04-3 Show GitHub Exploit DB Packet Storm
196882 6.1 MEDIUM
Network
auth0 login_by_auth0 The Login by Auth0 plugin before 4.0.0 for WordPress allows stored XSS on multiple pages, a different issue than CVE-2020-5392. CWE-79
Cross-site Scripting
CVE-2020-6753 2024-11-21 14:36 2020-04-1 Show GitHub Exploit DB Packet Storm
196883 6.7 MEDIUM
Local
mcafee endpoint_security Improper access control vulnerability in ESconfigTool.exe in McAfee Endpoint Security (ENS) for Windows all current versions allows local administrator to alter ENS configuration up to and including … CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2020-7263 2024-11-21 14:36 2020-04-1 Show GitHub Exploit DB Packet Storm
196884 4.3 MEDIUM
Network
php
tenable
opensuse
debian
php
tenable.sc
leap
debian_linux
In PHP versions 7.2.x below 7.2.29, 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using get_headers() with user-supplied URL, if the URL contains zero (\0) character, the URL will be silently trunc… NVD-CWE-Other
CVE-2020-7066 2024-11-21 14:36 2020-04-1 Show GitHub Exploit DB Packet Storm
196885 8.8 HIGH
Network
php
debian
canonical
tenable
php
debian_linux
ubuntu_linux
tenable.sc
In PHP versions 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using mb_strtolower() function with UTF-32LE encoding, certain invalid strings could cause PHP to overwrite stack-allocated buffer. Thi… CWE-787
 Out-of-bounds Write
CVE-2020-7065 2024-11-21 14:36 2020-04-1 Show GitHub Exploit DB Packet Storm
196886 5.4 MEDIUM
Network
php
debian
canonical
opensuse
tenable
php
debian_linux
ubuntu_linux
leap
tenable.sc
In PHP versions 7.2.x below 7.2.9, 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while parsing EXIF data with exif_read_data() function, it is possible for malicious data to cause PHP to read one byte of… CWE-125
Out-of-bounds Read
CVE-2020-7064 2024-11-21 14:36 2020-04-1 Show GitHub Exploit DB Packet Storm
196887 8.8 HIGH
Network
elastic elasticsearch Elasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 contain a privilege escalation flaw if an attacker is able to create API keys. An attacker who is able to generate an API key can… CWE-269
 Improper Privilege Management
CVE-2020-7009 2024-11-21 14:36 2020-04-1 Show GitHub Exploit DB Packet Storm
196888 7.8 HIGH
Local
mcafee application_and_change_control DLL Side Loading vulnerability in the installer for McAfee Application and Change Control (MACC) prior to 8.3 allows local users to execute arbitrary code via execution from a compromised folder. CWE-426
 Untrusted Search Path
CVE-2020-7260 2024-11-21 14:36 2020-03-26 Show GitHub Exploit DB Packet Storm
196889 6.5 MEDIUM
Network
moxa mds-g516e_firmware In Moxa EDS-G516E Series firmware, Version 5.2 or lower, some of the parameters in the setting pages do not ensure text is the correct size for its buffer. CWE-120
Classic Buffer Overflow
CVE-2020-6999 2024-11-21 14:36 2020-03-26 Show GitHub Exploit DB Packet Storm
196890 9.8 CRITICAL
Network
mozilla firefox Mozilla developers reported memory safety and script safety bugs present in Firefox 73. Some of these bugs showed evidence of memory corruption or escalation of privilege and we presume that with eno… CWE-787
 Out-of-bounds Write
CVE-2020-6815 2024-11-21 14:36 2020-03-26 Show GitHub Exploit DB Packet Storm