Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 3, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228251 7.5 危険 phpecho cms - PHPEcho CMS の管理パネルにおける SQL インジェクションの脆弱性 - CVE-2007-3335 2012-12-20 18:19 2007-06-21 Show GitHub Exploit DB Packet Storm
228252 5 警告 PHPNUKE - PHP-Nuke 用の Satel Lite におけるディレクトリトラバーサルの脆弱性 - CVE-2007-3332 2012-12-20 18:19 2007-06-21 Show GitHub Exploit DB Packet Storm
228253 5 警告 stphp - STphp EasyNews におけるクロスサイトリクエストフォージェリの脆弱性 - CVE-2007-3331 2012-12-20 18:19 2007-06-21 Show GitHub Exploit DB Packet Storm
228254 4.3 警告 stphp - STphp EasyNews におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-3330 2012-12-20 18:19 2007-06-21 Show GitHub Exploit DB Packet Storm
228255 6.8 警告 xvid - Xvid の src/bitstream/mbcoding.c における任意のコードを実行される脆弱性 CWE-DesignError
CVE-2007-3329 2012-12-20 18:19 2007-04-28 Show GitHub Exploit DB Packet Storm
228256 9.3 危険 VideoLAN - VideoLAN VLC Media Player のプラグインにおけるフォーマットストリングの脆弱性 - CVE-2007-3316 2012-12-20 18:19 2007-06-12 Show GitHub Exploit DB Packet Storm
228257 6.8 警告 yourfreescreamer - YourFreeScreamer における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-3315 2012-12-20 18:19 2007-06-21 Show GitHub Exploit DB Packet Storm
228258 7.5 危険 XOOPS - Xoops 用の Articles モジュールにおける SQL インジェクションの脆弱性 - CVE-2007-3311 2012-12-20 18:19 2007-06-21 Show GitHub Exploit DB Packet Storm
228259 4.3 警告 tdizin - TDizin の arama.asp におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-3310 2012-12-20 18:19 2007-06-20 Show GitHub Exploit DB Packet Storm
228260 7.5 危険 Simple Machines - SMF におけるメッセージの作成時に任意の PHP コードを実行され脆弱性 - CVE-2007-3309 2012-12-20 18:19 2007-06-20 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 4, 2026, 4:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
210181 9.8 CRITICAL
Network
the_school_manage_system_project the_school_manage_system The School Manage System before 2020, developed by ALLE INFORMATION CO., LTD., contains a vulnerability of SQL Injection, an attacker can use a union based injection query string to get databases sch… CWE-89
SQL Injection
CVE-2020-10505 2024-11-21 13:55 2020-04-15 Show GitHub Exploit DB Packet Storm
210182 7.8 HIGH
Local
mbconnectline mymbconnect24
mbconnect24
An issue was discovered in the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software in all versions through 2.6.1. There is a local privilege escalation from the www-data account to the root accoun… CWE-269
 Improper Privilege Management
CVE-2020-10384 2024-11-21 13:55 2020-04-15 Show GitHub Exploit DB Packet Storm
210183 9.8 CRITICAL
Network
mbconnectline mymbconnect24
mbconnect24
An issue was discovered in the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software in all versions through 2.5.0. There is an unauthenticated remote code execution in the com_mb24sysapi module. NVD-CWE-noinfo
CVE-2020-10383 2024-11-21 13:55 2020-04-15 Show GitHub Exploit DB Packet Storm
210184 8.8 HIGH
Network
mbconnectline mymbconnect24
mbconnect24
An issue was discovered in the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software in all versions through 2.5.0. There is an authenticated remote code execution in the backup-scheduler. NVD-CWE-noinfo
CVE-2020-10382 2024-11-21 13:55 2020-04-15 Show GitHub Exploit DB Packet Storm
210185 5.3 MEDIUM
Network
mbconnectline mymbconnect24
mbconnect24
An issue was discovered in the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software in all versions through 2.5.0. There is an unauthenticated SQL injection in DATA24, allowing attackers to discove… CWE-89
SQL Injection
CVE-2020-10381 2024-11-21 13:55 2020-04-15 Show GitHub Exploit DB Packet Storm
210186 7.8 HIGH
Local
fujielectric v-server Fuji Electric V-Server Lite all versions prior to 4.0.9.0 contains a heap based buffer overflow. The buffer allocated to read data, when parsing VPR files, is too small. CWE-787
 Out-of-bounds Write
CVE-2020-10646 2024-11-21 13:55 2020-04-14 Show GitHub Exploit DB Packet Storm
210187 7.8 HIGH
Local
rockwellautomation rslinx_classic In Rockwell Automation RSLinx Classic versions 4.11.00 and prior, an authenticated local attacker could modify a registry key, which could lead to the execution of malicious code using system privile… - CVE-2020-10642 2024-11-21 13:55 2020-04-14 Show GitHub Exploit DB Packet Storm
210188 9.8 CRITICAL
Network
advantech webaccess\/nms An attacker could use a specially crafted URL to delete or read files outside the WebAccess/NMS's (versions prior to 3.0.2) control. CWE-22
Path Traversal
CVE-2020-10631 2024-11-21 13:55 2020-04-9 Show GitHub Exploit DB Packet Storm
210189 7.5 HIGH
Network
advantech webaccess\/nms WebAccess/NMS (versions prior to 3.0.2) does not sanitize XML input. Specially crafted XML input could allow an attacker to read sensitive files. CWE-611
XXE
CVE-2020-10629 2024-11-21 13:55 2020-04-9 Show GitHub Exploit DB Packet Storm
210190 9.8 CRITICAL
Network
advantech webaccess\/nms WebAccess/NMS (versions prior to 3.0.2) allows an unauthenticated remote user to create a new admin account. CWE-306
Missing Authentication for Critical Function
CVE-2020-10625 2024-11-21 13:55 2020-04-9 Show GitHub Exploit DB Packet Storm