Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 19, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
226631 10 危険 Standards Based Linux Instrumentation (SBLIM) - SBLIM SFCB の httpAdapter における整数オーバーフローの脆弱性 CWE-189
数値処理の問題
CVE-2010-2054 2012-12-20 19:29 2010-05-14 Show GitHub Exploit DB Packet Storm
226632 7.5 危険 shopex - ECShop の search.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-2042 2012-12-20 19:29 2010-05-25 Show GitHub Exploit DB Packet Storm
226633 4.3 警告 php-calendar project - PHP-Calendar の index.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-2041 2012-12-20 19:29 2010-05-25 Show GitHub Exploit DB Packet Storm
226634 4.3 警告 V-EVA - V-EVA Shopzilla Affiliate Script PHP の search.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-2040 2012-12-20 19:29 2010-05-25 Show GitHub Exploit DB Packet Storm
226635 1.9 注意 wolfram research - Mathematica における任意のファイルを上書きされる脆弱性 CWE-59
リンク解釈の問題
CVE-2010-2027 2012-12-20 19:29 2010-05-24 Show GitHub Exploit DB Packet Storm
226636 6.8 警告 sebrac.webcindario - MigasCMS の function.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-2012 2012-12-20 19:29 2010-05-24 Show GitHub Exploit DB Packet Storm
226637 4.3 警告 proxy2 - Advanced Poll の misc/get_admin.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-2003 2012-12-20 19:29 2010-05-20 Show GitHub Exploit DB Packet Storm
226638 2.1 注意 ron jerome - Drupal 用の Bibliography モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-2000 2012-12-20 19:29 2010-05-12 Show GitHub Exploit DB Packet Storm
226639 2.1 注意 Saurused Ltd. - Saurus CMS の admin/edit.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-1997 2012-12-20 19:29 2010-05-20 Show GitHub Exploit DB Packet Storm
226640 2.1 注意 tomatocms - TomatoCMS の index.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-1996 2012-12-20 19:29 2010-05-20 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 19, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
209951 6.5 MEDIUM
Network
librenms librenms In LibreNMS before 1.65.1, an authenticated attacker can achieve SQL Injection via the customoid.inc.php device_id POST parameter to ajax_form.php. CWE-89
SQL Injection
CVE-2020-15873 2024-11-21 14:06 2020-07-22 Show GitHub Exploit DB Packet Storm
209952 3.3 LOW
Local
qemu
debian
qemu
debian_linux
QEMU 4.2.0 has a use-after-free in hw/net/e1000e_core.c because a guest OS user can trigger an e1000e packet with the data's address set to the e1000e's MMIO address. CWE-416
 Use After Free
CVE-2020-15859 2024-11-21 14:06 2020-07-22 Show GitHub Exploit DB Packet Storm
209953 9.8 CRITICAL
Network
mruby
debian
mruby
debian_linux
mruby through 2.1.2-rc has a heap-based buffer overflow in the mrb_yield_with_class function in vm.c because of incorrect VM stack handling. It can be triggered via the stack_copy function. CWE-787
 Out-of-bounds Write
CVE-2020-15866 2024-11-21 14:06 2020-07-22 Show GitHub Exploit DB Packet Storm
209954 7.8 HIGH
Local
linux
xen
netapp
linux_kernel
xen
cloud_backup
steelstore_cloud_integrated_storage
solidfire_baseboard_management_controller
An issue was discovered in the Linux kernel 5.5 through 5.7.9, as used in Xen through 4.13.x for x86 PV guests. An attacker may be granted the I/O port permissions of an unrelated task. This occurs b… CWE-276
Incorrect Default Permissions 
CVE-2020-15852 2024-11-21 14:06 2020-07-21 Show GitHub Exploit DB Packet Storm
209955 8.1 HIGH
Network
liferay liferay_portal
dxp
Liferay Portal before 7.3.0, and Liferay DXP 7.0 before fix pack 90, 7.1 before fix pack 17, and 7.2 before fix pack 5, allows man-in-the-middle attackers to execute arbitrary code via crafted serial… CWE-502
 Deserialization of Untrusted Data
CVE-2020-15842 2024-11-21 14:06 2020-07-20 Show GitHub Exploit DB Packet Storm
209956 8.8 HIGH
Network
liferay liferay_portal
dxp
Liferay Portal before 7.3.0, and Liferay DXP 7.0 before fix pack 89, 7.1 before fix pack 17, and 7.2 before fix pack 4, does not safely test a connection to a LDAP server, which allows remote attacke… NVD-CWE-noinfo
CVE-2020-15841 2024-11-21 14:06 2020-07-20 Show GitHub Exploit DB Packet Storm
209957 8.8 HIGH
Network
westerndigital wd_discovery In Western Digital WD Discovery before 4.0.251.0, a malicious application running with standard user permissions could potentially execute code in the application's process through library injection … CWE-668
 Exposure of Resource to Wrong Sphere
CVE-2020-15816 2024-11-21 14:06 2020-07-18 Show GitHub Exploit DB Packet Storm
209958 6.5 MEDIUM
Network
gnu libredwg GNU LibreDWG before 0.11 allows NULL pointer dereferences via crafted input files. CWE-476
 NULL Pointer Dereference
CVE-2020-15807 2024-11-21 14:06 2020-07-18 Show GitHub Exploit DB Packet Storm
209959 8.1 HIGH
Network
graylog graylog Graylog before 3.3.3 lacks SSL Certificate Validation for LDAP servers. It allows use of an external user/group database stored in LDAP. The connection configuration allows the usage of unencrypted, … CWE-295
Improper Certificate Validation 
CVE-2020-15813 2024-11-21 14:06 2020-07-18 Show GitHub Exploit DB Packet Storm
209960 6.1 MEDIUM
Network
zabbix
fedoraproject
debian
opensuse
zabbix
fedora
debian_linux
leap
backports
Zabbix before 3.0.32rc1, 4.x before 4.0.22rc1, 4.1.x through 4.4.x before 4.4.10rc1, and 5.x before 5.0.2rc1 allows stored XSS in the URL Widget. CWE-79
Cross-site Scripting
CVE-2020-15803 2024-11-21 14:06 2020-07-17 Show GitHub Exploit DB Packet Storm