Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 3, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
227901 7.5 危険 sisfo kampus - Sisfo Kampus 2006 の blanko.preview.php における絶対パストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2007-4820 2012-12-20 18:33 2007-09-11 Show GitHub Exploit DB Packet Storm
227902 4.3 警告 txx cms - Txx CMS におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-4819 2012-12-20 18:33 2007-09-11 Show GitHub Exploit DB Packet Storm
227903 7.5 危険 txx cms - Txx CMS における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2007-4818 2012-12-20 18:33 2007-09-11 Show GitHub Exploit DB Packet Storm
227904 7.5 危険 tlm cms - TLM CMS における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-4808 2012-12-20 18:33 2007-09-11 Show GitHub Exploit DB Packet Storm
227905 5 警告 ソフォス - Sophos Anti-Virus のウィルス検出エンジンにおけるマルウェアの検出を回避される脆弱性 CWE-20
不適切な入力確認
CVE-2007-4787 2012-12-20 18:33 2007-09-10 Show GitHub Exploit DB Packet Storm
227906 7.5 危険 tim jackson - PHPOF の dbmodules/DB_adodb.class.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2007-4763 2012-12-20 18:33 2007-09-8 Show GitHub Exploit DB Packet Storm
227907 7.5 危険 phpmytourney - phpMytourney の menu.php における PHP リモートファイルインクルージョンの脆弱性 CWE-20
不適切な入力確認
CVE-2007-4757 2012-12-20 18:33 2007-09-8 Show GitHub Exploit DB Packet Storm
227908 5 警告 Thomson - Thomson ST 2030 SIP 電話機におけるサービス運用妨害 (DoS) の脆弱性 CWE-DesignError
CVE-2007-4753 2012-12-20 18:33 2007-09-7 Show GitHub Exploit DB Packet Storm
227909 6.8 警告 ppstream - PPStream の PowerPlayer.dll ActiveX コントロールにおけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2007-4748 2012-12-20 18:33 2007-09-6 Show GitHub Exploit DB Packet Storm
227910 9.3 危険 telecom italy - Telecom Italy Alice Messenger の Hp.Revolution.RegistryManager.dll 1 におけるレジストリキーを作成される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2007-4740 2012-12-20 18:33 2007-09-6 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 3, 2026, 4:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
200331 9.8 CRITICAL
Network
online_doctor_appointment_booking_system_php_and_mysql_project online_doctor_appointment_booking_system_php_and_mysql An SQL injection vulnerability was discovered in Online Doctor Appointment Booking System PHP and Mysql via the q parameter to getuser.php. CWE-89
SQL Injection
CVE-2020-29283 2024-11-21 14:23 2020-12-3 Show GitHub Exploit DB Packet Storm
200332 9.8 CRITICAL
Network
bloodx_project bloodx SQL injection vulnerability in BloodX 1.0 allows attackers to bypass authentication. CWE-89
SQL Injection
CVE-2020-29282 2024-11-21 14:23 2020-12-3 Show GitHub Exploit DB Packet Storm
200333 9.8 CRITICAL
Network
victor_cms_project victor_cms The Victor CMS v1.0 application is vulnerable to SQL injection via the 'search' parameter on the search.php page. CWE-89
SQL Injection
CVE-2020-29280 2024-11-21 14:23 2020-12-3 Show GitHub Exploit DB Packet Storm
200334 9.8 CRITICAL
Network
74cms 74cms PHP remote file inclusion in the assign_resume_tpl method in Application/Common/Controller/BaseController.class.php in 74CMS before 6.0.48 allows remote code execution. NVD-CWE-noinfo
CVE-2020-29279 2024-11-21 14:23 2020-12-3 Show GitHub Exploit DB Packet Storm
200335 9.8 CRITICAL
Network
docker crux_linux_docker_image The official Crux Linux Docker images 3.0 through 3.4 contain a blank password for a root user. System using the Crux Linux Docker container deployed by affected versions of the Docker image may allo… CWE-306
Missing Authentication for Critical Function
CVE-2020-29389 2024-11-21 14:23 2020-12-3 Show GitHub Exploit DB Packet Storm
200336 4.8 MEDIUM
Network
lepton-cms leptoncms Lepton-CMS 4.7.0 is affected by cross-site scripting (XSS). An attacker can inject the XSS payload in the URL field of the admin page and each time an admin visits the Menu-Pages-Pages Overview secti… CWE-79
Cross-site Scripting
CVE-2020-29240 2024-11-21 14:23 2020-12-3 Show GitHub Exploit DB Packet Storm
200337 6.1 MEDIUM
Network
janobe online_voting_system Online Birth Certificate System Project V 1.0 is affected by cross-site scripting (XSS). This vulnerability can result in an attacker injecting the XSS payload in the User Registration section. When … CWE-79
Cross-site Scripting
CVE-2020-29239 2024-11-21 14:23 2020-12-3 Show GitHub Exploit DB Packet Storm
200338 5.4 MEDIUM
Network
thinkadmin thinkadmin ThinkAdmin version v1 v6 has a stored XSS vulnerability which allows remote attackers to inject an arbitrary web script or HTML. CWE-79
Cross-site Scripting
CVE-2020-29315 2024-11-21 14:23 2020-12-2 Show GitHub Exploit DB Packet Storm
200339 7.5 HIGH
Network
atx minicmts200a_firmware A Directory Traversal vulnerability exists in ATX miniCMTS200a Broadband Gateway through 2.0 and Pico CMTS through 2.0. Successful exploitation of this vulnerability would allow an unauthenticated at… CWE-22
Path Traversal
CVE-2020-28993 2024-11-21 14:23 2020-12-2 Show GitHub Exploit DB Packet Storm
200340 9.8 CRITICAL
Network
westerndigital my_cloud_os_5 An issue was discovered on Western Digital My Cloud OS 5 devices before 5.06.115. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to execute privileged commands on… CWE-287
Improper Authentication
CVE-2020-28971 2024-11-21 14:23 2020-12-2 Show GitHub Exploit DB Packet Storm