Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 29, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
227841 7.5 危険 systemsoftware - Systemsoftware Community Black Forum の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-1341 2012-12-20 19:29 2010-04-9 Show GitHub Exploit DB Packet Storm
227842 4.3 警告 robertotto - WoltLab Burning Board 用の Teamsite Hack プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-1339 2012-12-20 19:29 2010-04-9 Show GitHub Exploit DB Packet Storm
227843 7.5 危険 robertotto - WoltLab Burning Board 用の Teamsite Hack プラグインにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-1338 2012-12-20 19:29 2010-04-9 Show GitHub Exploit DB Packet Storm
227844 6 警告 PulseCMS - Pulse CMS における任意のコードを実行される脆弱性 CWE-Other
その他
CVE-2010-1334 2012-12-20 19:29 2010-04-9 Show GitHub Exploit DB Packet Storm
227845 6.8 警告 TYPO3 Association - TYPO3 の autoloader における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2010-1153 2012-12-20 19:29 2010-04-20 Show GitHub Exploit DB Packet Storm
227846 6 警告 roshan singh - Open Direct Connect Hub におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2010-1147 2012-12-20 19:29 2010-04-6 Show GitHub Exploit DB Packet Storm
227847 7.5 危険 Tiki Software Community Association - TikiWiki CMS/Groupware の Standard Remember メソッドにおけるアクセスの制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2010-1136 2012-12-20 19:29 2010-03-5 Show GitHub Exploit DB Packet Storm
227848 7.5 危険 Tiki Software Community Association - TikiWiki CMS/Groupware の user_logout 関数におけるアクセス権を取得される脆弱性 CWE-255
証明書・パスワード管理
CVE-2010-1135 2012-12-20 19:29 2010-03-5 Show GitHub Exploit DB Packet Storm
227849 7.5 危険 Tiki Software Community Association - TikiWiki CMS/Groupware の searchlib.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-1134 2012-12-20 19:29 2010-03-5 Show GitHub Exploit DB Packet Storm
227850 7.5 危険 Tiki Software Community Association - TikiWiki CMS/Groupware における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-1133 2012-12-20 19:29 2010-03-5 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 29, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
215401 6.1 MEDIUM
Network
cross_domain_local_storage_project cross_domain_local_storage An issue was discovered in xdLocalStorage through 2.0.5. The buildMessage() function in xdLocalStorage.js specifies the wildcard (*) as the targetOrigin when calling the postMessage() function on the… CWE-601
Open Redirect
CVE-2020-11611 2024-11-21 13:58 2020-04-8 Show GitHub Exploit DB Packet Storm
215402 8.8 HIGH
Network
cross_domain_local_storage_project cross_domain_local_storage An issue was discovered in xdLocalStorage through 2.0.5. The postData() function in xdLocalStoragePostMessageApi.js specifies the wildcard (*) as the targetOrigin when calling the postMessage() funct… CWE-668
 Exposure of Resource to Wrong Sphere
CVE-2020-11610 2024-11-21 13:58 2020-04-8 Show GitHub Exploit DB Packet Storm
215403 4.3 MEDIUM
Physics
linux
canonical
linux_kernel
ubuntu_linux
An issue was discovered in the stv06xx subsystem in the Linux kernel before 5.6.1. drivers/media/usb/gspca/stv06xx/stv06xx.c and drivers/media/usb/gspca/stv06xx/stv06xx_pb0100.c mishandle invalid des… CWE-476
 NULL Pointer Dereference
CVE-2020-11609 2024-11-21 13:58 2020-04-8 Show GitHub Exploit DB Packet Storm
215404 7.8 HIGH
Local
nchsoftware express_invoice NCH Express Invoice 7.25 allows local users to discover the cleartext password by reading the configuration file. CWE-522
 Insufficiently Protected Credentials
CVE-2020-11560 2024-11-21 13:58 2020-04-8 Show GitHub Exploit DB Packet Storm
215405 6.1 MEDIUM
Network
rankmath seo The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to create new URIs (that redirect to an external web site) via the unsecured rankmath/v1/updateRedirection … CWE-601
Open Redirect
CVE-2020-11515 2024-11-21 13:58 2020-04-8 Show GitHub Exploit DB Packet Storm
215406 9.8 CRITICAL
Network
rankmath seo The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to update arbitrary WordPress metadata, including the ability to escalate or revoke administrative privileg… CWE-862
 Missing Authorization
CVE-2020-11514 2024-11-21 13:58 2020-04-8 Show GitHub Exploit DB Packet Storm
215407 5.4 MEDIUM
Network
idxbroker impress_for_idx_broker Stored XSS in the IMPress for IDX Broker WordPress plugin before 2.6.2 allows authenticated attackers with minimal (subscriber-level) permissions to save arbitrary JavaScript in the plugin's settings… CWE-79
Cross-site Scripting
CVE-2020-11512 2024-11-21 13:58 2020-04-8 Show GitHub Exploit DB Packet Storm
215408 5.4 MEDIUM
Network
contact-form-7-datepicker_project contact-form-7-datepicker Stored XSS in the Contact Form 7 Datepicker plugin through 2.6.0 for WordPress allows authenticated attackers with minimal permissions to save arbitrary JavaScript to the plugin's settings via the un… CWE-79
Cross-site Scripting
CVE-2020-11516 2024-11-21 13:58 2020-04-8 Show GitHub Exploit DB Packet Storm
215409 8.8 HIGH
Network
nchsoftware express_invoice In NCH Express Invoice 7.25, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functionalities such as the "Add New Item" screen. CWE-425
 Direct Request ('Forced Browsing')
CVE-2020-11561 2024-11-21 13:58 2020-04-8 Show GitHub Exploit DB Packet Storm
215410 4.3 MEDIUM
Physics
linux
canonical
linux_kernel
ubuntu_linux
An issue was discovered in the Linux kernel before 5.6.1. drivers/media/usb/gspca/ov519.c allows NULL pointer dereferences in ov511_mode_init_regs and ov518_mode_init_regs when there are zero endpoin… CWE-476
 NULL Pointer Dereference
CVE-2020-11608 2024-11-21 13:58 2020-04-7 Show GitHub Exploit DB Packet Storm