Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 20, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
226901 7.5 危険 rocky.nu - Modelbook の casting_view.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-1705 2012-12-20 19:29 2010-05-4 Show GitHub Exploit DB Packet Storm
226902 7.5 危険 WHMCS Limited - WHMCS の submitticket.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-1702 2012-12-20 19:29 2010-05-4 Show GitHub Exploit DB Packet Storm
226903 7.5 危険 rocky.nu - PHP Video Battle Script の browse.html における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-1701 2012-12-20 19:29 2010-05-4 Show GitHub Exploit DB Packet Storm
226904 5 警告 webkul - Joomla! 用の Ultimate Portfolio コンポーネントにおけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2010-1659 2012-12-20 19:29 2010-05-3 Show GitHub Exploit DB Packet Storm
226905 5 警告 recly - Joomla! 用の SmartSite コンポーネントにおけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2010-1657 2012-12-20 19:29 2010-05-3 Show GitHub Exploit DB Packet Storm
226906 4.3 警告 powereasy - PowerEasy などの User/User_ChkLogin.asp におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-1655 2012-12-20 19:29 2010-05-3 Show GitHub Exploit DB Packet Storm
226907 5 警告 Samba Project - Samba の smbd におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2010-1642 2012-12-20 19:29 2010-05-14 Show GitHub Exploit DB Packet Storm
226908 4 警告 SquirrelMail Project - SquirrelMail の Mail Fetch プラグインにおけるファイアウォール制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2010-1637 2012-12-20 19:29 2010-06-21 Show GitHub Exploit DB Packet Storm
226909 5 警告 Samba Project - Samba の smbd におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2010-1635 2012-12-20 19:29 2010-05-14 Show GitHub Exploit DB Packet Storm
226910 7.5 危険 phpBB - phpBB の posting.php における脆弱性 CWE-noinfo
情報不足
CVE-2010-1630 2012-12-20 19:29 2010-05-19 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 20, 2026, 4:14 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
214471 6.1 MEDIUM
Network
gitlab gitlab GitLab 12.1 through 12.8.1 allows XSS. A stored cross-site scripting vulnerability was discovered when displaying merge requests. CWE-79
Cross-site Scripting
CVE-2020-10076 2024-11-21 13:54 2020-03-14 Show GitHub Exploit DB Packet Storm
214472 6.1 MEDIUM
Network
gitlab gitlab GitLab 12.5 through 12.8.1 allows HTML Injection. A particular error header was potentially susceptible to injection or potentially other vulnerabilities via unescaped input. CWE-79
Cross-site Scripting
CVE-2020-10075 2024-11-21 13:54 2020-03-14 Show GitHub Exploit DB Packet Storm
214473 9.8 CRITICAL
Network
gitlab gitlab GitLab 10.1 through 12.8.1 has Incorrect Access Control. A scenario was discovered in which a GitLab account could be taken over through an expired link. NVD-CWE-noinfo
CVE-2020-10074 2024-11-21 13:54 2020-03-14 Show GitHub Exploit DB Packet Storm
214474 7.5 HIGH
Network
gitlab gitlab GitLab EE 12.4.2 through 12.8.1 allows Denial of Service. It was internally discovered that a potential denial of service involving permissions checks could impact a project home page. NVD-CWE-noinfo
CVE-2020-10073 2024-11-21 13:54 2020-03-14 Show GitHub Exploit DB Packet Storm
214475 6.5 MEDIUM
Network
sapplica sentrifugo A Blind SQL Injection issue was discovered in Sapplica Sentrifugo 3.2 via the index.php/holidaygroups/add id parameter because of the HolidaydatesController.php addAction function. CWE-89
SQL Injection
CVE-2020-10218 2024-11-21 13:54 2020-03-14 Show GitHub Exploit DB Packet Storm
214476 6.1 MEDIUM
Network
gitlab gitlab GitLab 12.1 through 12.8.1 allows XSS. A cross-site scripting vulnerability was present in a particular view relating to the Grafana integration. CWE-79
Cross-site Scripting
CVE-2020-10092 2024-11-21 13:54 2020-03-14 Show GitHub Exploit DB Packet Storm
214477 6.1 MEDIUM
Network
gitlab gitlab GitLab 9.3 through 12.8.1 allows XSS. A cross-site scripting vulnerability was found when viewing particular file types. CWE-79
Cross-site Scripting
CVE-2020-10091 2024-11-21 13:54 2020-03-14 Show GitHub Exploit DB Packet Storm
214478 5.3 MEDIUM
Network
gitlab gitlab GitLab 11.7 through 12.8.1 allows Information Disclosure. Under certain group conditions, group epic information was unintentionally being disclosed. CWE-200
Information Exposure
CVE-2020-10090 2024-11-21 13:54 2020-03-14 Show GitHub Exploit DB Packet Storm
214479 7.5 HIGH
Network
gitlab gitlab GitLab 8.11 through 12.8.1 allows a Denial of Service when using several features to recursively request eachother, CWE-674
 Uncontrolled Recursion
CVE-2020-10089 2024-11-21 13:54 2020-03-14 Show GitHub Exploit DB Packet Storm
214480 8.1 HIGH
Network
gitlab gitlab GitLab 12.5 through 12.8.1 has Insecure Permissions. Depending on particular group settings, it was possible for invited groups to be given the incorrect permission level. CWE-269
 Improper Privilege Management
CVE-2020-10088 2024-11-21 13:54 2020-03-14 Show GitHub Exploit DB Packet Storm