Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 3, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
227731 7.2 危険 VMware - VMware Server における権限を取得される脆弱性 CWE-noinfo
情報不足
CVE-2007-5619 2012-12-20 18:33 2007-10-21 Show GitHub Exploit DB Packet Storm
227732 7.2 危険 VMware - VMware Playerなどの製品における Authorization などのサービスにおける権限を取得される脆弱性 CWE-noinfo
情報不足
CVE-2007-5618 2012-12-20 18:33 2007-10-21 Show GitHub Exploit DB Packet Storm
227733 10 危険 VMware - VMware Player および Workstation における脆弱性 CWE-noinfo
情報不足
CVE-2007-5617 2012-12-20 18:33 2007-10-21 Show GitHub Exploit DB Packet Storm
227734 9.3 危険 SonicWALL - SonicWall SSL-VPN NetExtender NELaunchCtrl ActiveX コントロールにおけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2007-5603 2012-12-20 18:33 2007-11-5 Show GitHub Exploit DB Packet Storm
227735 10 危険 swiftview - SwiftView Viewer におけるスタックベースのバッファーオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2007-5602 2012-12-20 18:33 2007-10-2 Show GitHub Exploit DB Packet Storm
227736 4.3 警告 The phpMyAdmin Project - phpMyAdmin におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-5589 2012-12-20 18:33 2007-10-17 Show GitHub Exploit DB Packet Storm
227737 5 警告 XScreenSaver project - xscreensaver におけるロックされたセッションへのアクセス権を取得される脆弱性 CWE-399
リソース管理の問題
CVE-2007-5585 2012-12-20 18:33 2007-10-19 Show GitHub Exploit DB Packet Storm
227738 7.5 危険 Pligg - Pligg CMS の login.php におけるユーザのパスワードを再設定される脆弱性 CWE-255
証明書・パスワード管理
CVE-2007-5579 2012-12-20 18:33 2007-10-18 Show GitHub Exploit DB Packet Storm
227739 7.5 危険 Secure Ideas - BASE における認証を回避される脆弱性 CWE-287
不適切な認証
CVE-2007-5578 2012-12-20 18:33 2007-10-18 Show GitHub Exploit DB Packet Storm
227740 4.3 警告 treble designs - 1024 CMS におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2007-5575 2012-12-20 18:33 2007-10-18 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 3, 2026, 4:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
200481 7.3 HIGH
Network
yandex yandex_browser Yandex Browser for Android 20.8.4 allows remote attackers to perform SOP bypass and addresss bar spoofing CWE-346
 Origin Validation Error
CVE-2020-27969 2024-11-21 14:22 2021-09-13 Show GitHub Exploit DB Packet Storm
200482 7.8 HIGH
Local
apple mac_os_x A logic issue was addressed with improved state management. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave. Processing a maliciously crafted font file may l… NVD-CWE-noinfo
CVE-2020-27942 2024-11-21 14:22 2021-09-9 Show GitHub Exploit DB Packet Storm
200483 4.3 MEDIUM
Network
apple apple_tv This issue was addressed with improved file handling. This issue is fixed in Apple TV app for Fire OS 6.1.0.6A142:7.1.0. An attacker with file system access may modify scripts used by the app. NVD-CWE-noinfo
CVE-2020-27940 2024-11-21 14:22 2021-09-9 Show GitHub Exploit DB Packet Storm
200484 6.1 MEDIUM
Network
eyoucms eyoucms Cross Site Scripting (XSS) vulnerability exists in Eyoucms v1.4.7 and earlier via the addonfieldext parameter. CWE-79
Cross-site Scripting
CVE-2020-28146 2024-11-21 14:22 2021-08-19 Show GitHub Exploit DB Packet Storm
200485 7.8 HIGH
Local
prusa3d prusaslicer A use-after-free vulnerability exists in the _3MF_Importer::_handle_end_model() functionality of Prusa Research PrusaSlicer 2.2.0 and Master (commit 4b040b856). A specially crafted 3MF file can lead … CWE-416
 Use After Free
CVE-2020-28594 2024-11-21 14:22 2021-08-18 Show GitHub Exploit DB Packet Storm
200486 9.8 CRITICAL
Network
easycorp zentao The EasyCorp ZenTao PMS 12.4.2 application suffers from an arbitrary file upload vulnerability. An attacker can upload arbitrary webshell to the server by using the downloadZipPackage() function. CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2020-28165 2024-11-21 14:22 2021-08-12 Show GitHub Exploit DB Packet Storm
200487 8.8 HIGH
Network
tinyobjloader_project tinyobjloader An improper array index validation vulnerability exists in the LoadObj functionality of tinyobjloader v2.0-rc1 and tinyobjloader development commit 79d4421. A specially crafted file could lead to cod… CWE-129
 Improper Validation of Array Index
CVE-2020-28589 2024-11-21 14:22 2021-08-11 Show GitHub Exploit DB Packet Storm
200488 5.3 MEDIUM
Network
siemens cpu_1504d_tf_firmware
cpu_1507d_tf_firmware
cpu_1515sp_pc2_tf_firmware
simatic_s7_plcsim_advanced_firmware
simatic_s7-1500_software_controller
tim_1531_irc_firmware
cpu_1211c_firmwa…
A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions < V21.9), SIMATIC… CWE-863
 Incorrect Authorization
CVE-2020-28397 2024-11-21 14:22 2021-08-10 Show GitHub Exploit DB Packet Storm
200489 9.8 CRITICAL
Network
jeecg jeecg_boot An arbitrary file upload vulnerability in /jeecg-boot/sys/common/upload of jeecg-boot CMS 2.3 allows attackers to execute arbitrary code. CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2020-28088 2024-11-21 14:22 2021-08-7 Show GitHub Exploit DB Packet Storm
200490 7.5 HIGH
Network
jeecg jeecg_boot A SQL injection vulnerability in /jeecg boot/sys/dict/loadtreedata of jeecg-boot CMS 2.3 allows attackers to access sensitive database information. CWE-89
SQL Injection
CVE-2020-28087 2024-11-21 14:22 2021-08-7 Show GitHub Exploit DB Packet Storm