Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 2, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228411 7.5 危険 PreProject.com - Pre Shopping Mall の detail.php における SQL インジェクションの脆弱性 - CVE-2007-2674 2012-12-20 18:19 2007-05-14 Show GitHub Exploit DB Packet Storm
228412 7.5 危険 thinc4orce marketing group - PHP Coupon Script の index.php における SQL インジェクションの脆弱性 - CVE-2007-2672 2012-12-20 18:19 2007-05-14 Show GitHub Exploit DB Packet Storm
228413 6.8 警告 webdesproxy - webdesproxy におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2007-2668 2012-12-20 18:19 2007-05-14 Show GitHub Exploit DB Packet Storm
228414 7.5 危険 tomasz rekawek - Yaap の includes/common.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-2664 2012-12-20 18:19 2007-05-14 Show GitHub Exploit DB Packet Storm
228415 7.8 危険 precisionid barcode - PrecisionID_DataMatrix.DLL の PrecisionID Barcode ActiveX コントロールにおけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-2657 2012-12-20 18:19 2007-05-14 Show GitHub Exploit DB Packet Storm
228416 4.4 警告 SUSE
xfsdump
- xfsdump の xfs_fsr における xfs ファイルシステム上で任意のファイルを上書きされる脆弱性 CWE-362
CWE-Other
CVE-2007-2654 2012-12-20 18:19 2007-05-11 Show GitHub Exploit DB Packet Storm
228417 7.5 危険 voodoo circle - VooDoo cIRCle におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-2651 2012-12-20 18:19 2007-05-14 Show GitHub Exploit DB Packet Storm
228418 7.8 危険 t-com - T-com Speedport W 700v における遅延を回避される脆弱性 - CVE-2007-2649 2012-12-20 18:19 2007-05-14 Show GitHub Exploit DB Packet Storm
228419 6.8 警告 yenc32 - yEnc32 におけるヒープベースのバッファオーバーフローの脆弱性 - CVE-2007-2646 2012-12-20 18:19 2007-05-14 Show GitHub Exploit DB Packet Storm
228420 5 警告 pinkcrow designs - PinkCrow Designs Gallery または maGAZIn の phpThumb.php におけるディレクトリトラバーサルの脆弱性 - CVE-2007-2643 2012-12-20 18:19 2007-05-13 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 2, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
210501 9.1 CRITICAL
Network
cpanel cpanel cPanel before 84.0.20 allows a demo account to modify files via Branding API calls (SEC-543). NVD-CWE-noinfo
CVE-2020-10118 2024-11-21 13:54 2020-03-18 Show GitHub Exploit DB Packet Storm
210502 9.1 CRITICAL
Network
cpanel cpanel cPanel before 84.0.20 mishandles enforcement of demo checks in the Market UAPI namespace (SEC-542). NVD-CWE-noinfo
CVE-2020-10117 2024-11-21 13:54 2020-03-18 Show GitHub Exploit DB Packet Storm
210503 5.3 MEDIUM
Network
cpanel cpanel cPanel before 84.0.20 allows attackers to bypass intended restrictions on features and demo accounts via WebDisk UAPI calls (SEC-541). CWE-862
 Missing Authorization
CVE-2020-10116 2024-11-21 13:54 2020-03-18 Show GitHub Exploit DB Packet Storm
210504 7.2 HIGH
Network
cpanel cpanel cPanel before 84.0.20, when PowerDNS is used, allows arbitrary code execution as root via dnsadmin. (SEC-537). NVD-CWE-noinfo
CVE-2020-10115 2024-11-21 13:54 2020-03-18 Show GitHub Exploit DB Packet Storm
210505 6.1 MEDIUM
Network
cpanel cpanel cPanel before 84.0.20 allows stored self-XSS via the HTML file editor (SEC-535). CWE-79
Cross-site Scripting
CVE-2020-10114 2024-11-21 13:54 2020-03-18 Show GitHub Exploit DB Packet Storm
210506 6.1 MEDIUM
Network
cpanel cpanel cPanel before 84.0.20 allows self XSS via a temporary character-set specification (SEC-515). CWE-79
Cross-site Scripting
CVE-2020-10113 2024-11-21 13:54 2020-03-18 Show GitHub Exploit DB Packet Storm
210507 9.8 CRITICAL
Network
gitlab gitlab GitLab EE 3.0 through 12.8.1 allows SSRF. An internal investigation revealed that a particular deprecated service was creating a server side request forgery risk. CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2020-10077 2024-11-21 13:54 2020-03-14 Show GitHub Exploit DB Packet Storm
210508 6.1 MEDIUM
Network
gitlab gitlab GitLab 12.1 through 12.8.1 allows XSS. A stored cross-site scripting vulnerability was discovered when displaying merge requests. CWE-79
Cross-site Scripting
CVE-2020-10076 2024-11-21 13:54 2020-03-14 Show GitHub Exploit DB Packet Storm
210509 6.1 MEDIUM
Network
gitlab gitlab GitLab 12.5 through 12.8.1 allows HTML Injection. A particular error header was potentially susceptible to injection or potentially other vulnerabilities via unescaped input. CWE-79
Cross-site Scripting
CVE-2020-10075 2024-11-21 13:54 2020-03-14 Show GitHub Exploit DB Packet Storm
210510 9.8 CRITICAL
Network
gitlab gitlab GitLab 10.1 through 12.8.1 has Incorrect Access Control. A scenario was discovered in which a GitLab account could be taken over through an expired link. NVD-CWE-noinfo
CVE-2020-10074 2024-11-21 13:54 2020-03-14 Show GitHub Exploit DB Packet Storm