Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":April 30, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228231 6.8 警告 tecnick.com - TCExam の shared/config/tce_config.php におけるクロスサイトスクリプティング攻撃 (XSS) を実行される脆弱性 - CVE-2007-2431 2012-12-20 18:19 2007-05-1 Show GitHub Exploit DB Packet Storm
228232 7.8 危険 tecnick.com - TCExam の shared/code/tce_tmx.php における cache/ 配下の任意の PHP ファイルを作成される脆弱性 - CVE-2007-2430 2012-12-20 18:19 2007-05-1 Show GitHub Exploit DB Packet Storm
228233 7.5 危険 pnflashgames - PostNuke 用の pnFlashGames モジュールの index.php における SQL インジェクションの脆弱性 - CVE-2007-2427 2012-12-20 18:19 2007-05-1 Show GitHub Exploit DB Packet Storm
228234 7.5 危険 wildbits - WordPress 用の myGallery プラグインにおける PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-2426 2012-12-20 18:19 2007-05-1 Show GitHub Exploit DB Packet Storm
228235 7.5 危険 the merchant project - themerchant の help/index.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-2424 2012-12-20 18:19 2007-05-1 Show GitHub Exploit DB Packet Storm
228236 10 危険 RSAセキュリティ
Progress Software Corporation
- 複数の RSA 製品で使用される Progress Software Progress および OpenEdge におけるヒープベースのバッファオーバーフローの脆弱性 - CVE-2007-2417 2012-12-20 18:19 2007-07-15 Show GitHub Exploit DB Packet Storm
228237 5 警告 pi3web - Pi3Web Web Server におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2007-2415 2012-12-20 18:19 2007-05-1 Show GitHub Exploit DB Packet Storm
228238 4 警告 Samba Project - Apple Mac OS X 上で稼動している Samba サーバにおける割り当てを超えるディスクスペースを使用される脆弱性 - CVE-2007-2407 2012-12-20 18:19 2007-07-31 Show GitHub Exploit DB Packet Storm
228239 5 警告 Yahoo! - Yahoo! UI フレームワークにおけるデータを取得される脆弱性 - CVE-2007-2385 2012-12-20 18:19 2007-04-30 Show GitHub Exploit DB Packet Storm
228240 7.8 危険 script.aculo.us - Script.aculo.us フレームワークにおけるデータを取得される脆弱性 - CVE-2007-2384 2012-12-20 18:19 2007-04-30 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 30, 2026, 4:58 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
199921 7.3 HIGH
Network
yandex yandex_browser Yandex Browser for Android 20.8.4 allows remote attackers to perform SOP bypass and addresss bar spoofing CWE-346
 Origin Validation Error
CVE-2020-27969 2024-11-21 14:22 2021-09-13 Show GitHub Exploit DB Packet Storm
199922 7.8 HIGH
Local
apple mac_os_x A logic issue was addressed with improved state management. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave. Processing a maliciously crafted font file may l… NVD-CWE-noinfo
CVE-2020-27942 2024-11-21 14:22 2021-09-9 Show GitHub Exploit DB Packet Storm
199923 4.3 MEDIUM
Network
apple apple_tv This issue was addressed with improved file handling. This issue is fixed in Apple TV app for Fire OS 6.1.0.6A142:7.1.0. An attacker with file system access may modify scripts used by the app. NVD-CWE-noinfo
CVE-2020-27940 2024-11-21 14:22 2021-09-9 Show GitHub Exploit DB Packet Storm
199924 6.1 MEDIUM
Network
eyoucms eyoucms Cross Site Scripting (XSS) vulnerability exists in Eyoucms v1.4.7 and earlier via the addonfieldext parameter. CWE-79
Cross-site Scripting
CVE-2020-28146 2024-11-21 14:22 2021-08-19 Show GitHub Exploit DB Packet Storm
199925 7.8 HIGH
Local
prusa3d prusaslicer A use-after-free vulnerability exists in the _3MF_Importer::_handle_end_model() functionality of Prusa Research PrusaSlicer 2.2.0 and Master (commit 4b040b856). A specially crafted 3MF file can lead … CWE-416
 Use After Free
CVE-2020-28594 2024-11-21 14:22 2021-08-18 Show GitHub Exploit DB Packet Storm
199926 9.8 CRITICAL
Network
easycorp zentao The EasyCorp ZenTao PMS 12.4.2 application suffers from an arbitrary file upload vulnerability. An attacker can upload arbitrary webshell to the server by using the downloadZipPackage() function. CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2020-28165 2024-11-21 14:22 2021-08-12 Show GitHub Exploit DB Packet Storm
199927 8.8 HIGH
Network
tinyobjloader_project tinyobjloader An improper array index validation vulnerability exists in the LoadObj functionality of tinyobjloader v2.0-rc1 and tinyobjloader development commit 79d4421. A specially crafted file could lead to cod… CWE-129
 Improper Validation of Array Index
CVE-2020-28589 2024-11-21 14:22 2021-08-11 Show GitHub Exploit DB Packet Storm
199928 5.3 MEDIUM
Network
siemens cpu_1504d_tf_firmware
cpu_1507d_tf_firmware
cpu_1515sp_pc2_tf_firmware
simatic_s7_plcsim_advanced_firmware
simatic_s7-1500_software_controller
tim_1531_irc_firmware
cpu_1211c_firmwa…
A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions < V21.9), SIMATIC… CWE-863
 Incorrect Authorization
CVE-2020-28397 2024-11-21 14:22 2021-08-10 Show GitHub Exploit DB Packet Storm
199929 9.8 CRITICAL
Network
jeecg jeecg_boot An arbitrary file upload vulnerability in /jeecg-boot/sys/common/upload of jeecg-boot CMS 2.3 allows attackers to execute arbitrary code. CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2020-28088 2024-11-21 14:22 2021-08-7 Show GitHub Exploit DB Packet Storm
199930 7.5 HIGH
Network
jeecg jeecg_boot A SQL injection vulnerability in /jeecg boot/sys/dict/loadtreedata of jeecg-boot CMS 2.3 allows attackers to access sensitive database information. CWE-89
SQL Injection
CVE-2020-28087 2024-11-21 14:22 2021-08-7 Show GitHub Exploit DB Packet Storm