Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 17, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
227401 5 警告 swannsecurity - Swann DVR4-SecuraNet の HTTP インターフェースにおける昇格したアクセス権を取得される脆弱性 CWE-255
証明書・パスワード管理
CVE-2009-0644 2012-12-20 19:10 2009-02-18 Show GitHub Exploit DB Packet Storm
227402 5 警告 swannsecurity - Swann DVR4-SecuraNet の管理 Web サーバにおけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2009-0640 2012-12-20 19:10 2009-02-20 Show GitHub Exploit DB Packet Storm
227403 7.5 危険 phpyabs - phpyabs の moduli/libri/index.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2009-0639 2012-12-20 19:10 2009-02-18 Show GitHub Exploit DB Packet Storm
227404 7.5 危険 wikkitikkitavi - WikkiTikkiTavi の upload.php における任意のコードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2009-0602 2012-12-20 19:10 2009-02-16 Show GitHub Exploit DB Packet Storm
227405 7.5 危険 phpmesfilms - PhpMesFilms の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-0598 2012-12-20 19:10 2009-02-16 Show GitHub Exploit DB Packet Storm
227406 6.8 警告 w3bcms - w3b>cms の admin/index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-0597 2012-12-20 19:10 2009-02-16 Show GitHub Exploit DB Packet Storm
227407 6.8 警告 phpskelsite - phpSkelSite の skysilver/login.tpl.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2009-0596 2012-12-20 19:10 2009-02-16 Show GitHub Exploit DB Packet Storm
227408 5.1 警告 phpskelsite - phpSkelSite の skysilver/login.tpl.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2009-0595 2012-12-20 19:10 2009-02-16 Show GitHub Exploit DB Packet Storm
227409 6.5 警告 plxwebdev - plx Auto Reminder の members.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-0593 2012-12-20 19:10 2009-02-16 Show GitHub Exploit DB Packet Storm
227410 7.5 危険 pnphpbb - PNphpBB2 におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2009-0592 2012-12-20 19:10 2009-02-16 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 17, 2026, 4:15 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
209331 6.8 MEDIUM
Network
istio istio In Istio 1.5.0 though 1.5.8 and Istio 1.6.0 through 1.6.7, when users specify an AuthorizationPolicy resource with DENY actions using wildcard suffixes (e.g. *-some-suffix) for source principals or n… NVD-CWE-noinfo
CVE-2020-16844 2024-11-21 14:07 2020-10-2 Show GitHub Exploit DB Packet Storm
209332 6.1 MEDIUM
Network
ge s2020_firmware
s2024_firmware
The affected Reason S20 Ethernet Switch is vulnerable to cross-site scripting (XSS), which may allow an attacker to trick application users into performing critical application actions that include, … - CVE-2020-16242 2024-11-21 14:07 2020-09-26 Show GitHub Exploit DB Packet Storm
209333 7.8 HIGH
Local
pango hotspot_shield Improper directory permissions in the Hotspot Shield VPN client software for Windows 10.3.0 and earlier may allow an authorized user to potentially enable escalation of privilege via local access. Th… CWE-59
CWE-732
Link Following
 Incorrect Permission Assignment for Critical Resource
CVE-2020-17365 2024-11-21 14:07 2020-09-25 Show GitHub Exploit DB Packet Storm
209334 7.2 HIGH
Network
ge asset_performance_management_classic GE Digital APM Classic, Versions 4.4 and prior. Salt is not used for hash calculation of passwords, making it possible to decrypt passwords. This design flaw, along with the IDOR vulnerability, puts … NVD-CWE-Other
CVE-2020-16244 2024-11-21 14:07 2020-09-23 Show GitHub Exploit DB Packet Storm
209335 5.3 MEDIUM
Network
ge asset_performance_management_classic GE Digital APM Classic, Versions 4.4 and prior. An insecure direct object reference (IDOR) vulnerability allows user account data to be downloaded in JavaScript object notation (JSON) format by users… - CVE-2020-16240 2024-11-21 14:07 2020-09-23 Show GitHub Exploit DB Packet Storm
209336 7.1 HIGH
Local
philips clinical_collaboration_platform Philips Clinical Collaboration Platform, Versions 12.2.1 and prior. The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource. CWE-668
 Exposure of Resource to Wrong Sphere
CVE-2020-16247 2024-11-21 14:07 2020-09-19 Show GitHub Exploit DB Packet Storm
209337 4.2 MEDIUM
Network
microsoft edge <p>A remote code execution vulnerability exists in the way that the IEToEdge Browser Helper Object (BHO) plugin on Internet Explorer handles objects in memory. The vulnerability could corrupt memory … CWE-787
 Out-of-bounds Write
CVE-2020-16884 2024-11-21 14:07 2020-09-12 Show GitHub Exploit DB Packet Storm
209338 7.8 HIGH
Local
microsoft visual_studio_code <p>A remote code execution vulnerability exists in Visual Studio Code when a user is tricked into opening a malicious 'package.json' file. An attacker who successfully exploited the vulnerability cou… NVD-CWE-noinfo
CVE-2020-16881 2024-11-21 14:07 2020-09-12 Show GitHub Exploit DB Packet Storm
209339 5.5 MEDIUM
Local
microsoft windows_server_2019
windows_10
windows_server_2016
<p>An information disclosure vulnerability exists when a Windows Projected Filesystem improperly handles file redirections. An attacker who successfully exploited this vulnerability could obtain info… NVD-CWE-noinfo
CVE-2020-16879 2024-11-21 14:07 2020-09-12 Show GitHub Exploit DB Packet Storm
209340 5.4 MEDIUM
Network
microsoft dynamics_365 <p>A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server. An authenticated at… CWE-79
Cross-site Scripting
CVE-2020-16878 2024-11-21 14:07 2020-09-12 Show GitHub Exploit DB Packet Storm