Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":April 28, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228681 7.5 危険 supermod - YaBBSM 用の SuperMod における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-5413 2012-12-20 18:02 2006-10-20 Show GitHub Exploit DB Packet Storm
228682 6.2 警告 東芝 - 複数製品に使用される Toshiba Bluetooth ワイアレスデバイスドライバにおけるサービス運用妨害 (DoS) の脆弱性 - CVE-2006-5405 2012-12-20 18:02 2006-10-18 Show GitHub Exploit DB Packet Storm
228683 2.6 注意 シマンテック - Norton AntiVirus などの Symantec Automated Support Assistant で使用される ActiveX コントロールにおける重要な情報を取得される脆弱性 - CVE-2006-5404 2012-12-20 18:02 2006-10-5 Show GitHub Exploit DB Packet Storm
228684 5.1 警告 シマンテック - Norton AntiVirus などの Symantec Automated Support Assistant で使用される ActiveX コントロールにおけるスタックベースのバッファオーバーフローの脆弱性 - CVE-2006-5403 2012-12-20 18:02 2006-10-5 Show GitHub Exploit DB Packet Storm
228685 7.5 危険 phpmybibli - PHPmybibli における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2006-5402 2012-12-20 18:02 2006-10-18 Show GitHub Exploit DB Packet Storm
228686 7.5 危険 phprecipebook - PHPRecipeBook の classes/Import_MM.class.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2006-5399 2012-12-20 18:02 2006-10-18 Show GitHub Exploit DB Packet Storm
228687 7.5 危険 simplog - Simplog の comments.php における SQL インジェクションの脆弱性 - CVE-2006-5398 2012-12-20 18:02 2006-10-18 Show GitHub Exploit DB Packet Storm
228688 2.1 注意 X.Org Foundation - X.Org libX11 の Xinput モジュールにおける XCOMPOSEFILE 環境変数によって使用されるファイルが読み込まれる脆弱性 - CVE-2006-5397 2012-12-20 18:02 2006-11-2 Show GitHub Exploit DB Packet Storm
228689 5 警告 xfire - Xfire におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2006-5391 2012-12-20 18:02 2006-10-18 Show GitHub Exploit DB Packet Storm
228690 6.8 警告 phpBB - phpBB 用の MMW モジュールにおける PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2006-5390 2012-12-20 18:02 2006-10-18 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 29, 2026, 4:51 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
199351 5.4 MEDIUM
Network
churchcrm churchcrm Cross Site Scripting (XSS) vulnerability in ChurchCRM version 4.2.1, allows remote attckers to execute arbitrary code and gain sensitive information via crafted payload in Add New Deposit field in Vi… CWE-79
Cross-site Scripting
CVE-2020-28849 2024-11-21 14:23 2023-08-11 Show GitHub Exploit DB Packet Storm
199352 8.8 HIGH
Network
churchcrm churchcrm CSV Injection vulnerability in ChurchCRM version 4.2.0, allows remote attackers to execute arbitrary code via crafted CSV file. CWE-74
Injection
CVE-2020-28848 2024-11-21 14:23 2023-08-11 Show GitHub Exploit DB Packet Storm
199353 7.8 HIGH
Local
matthiaswandel jhead Buffer Overflow vulnerability in jpgfile.c in Matthias-Wandel jhead version 3.04, allows local attackers to execute arbitrary code and cause a denial of service (DoS). CWE-120
Classic Buffer Overflow
CVE-2020-28840 2024-11-21 14:23 2023-08-11 Show GitHub Exploit DB Packet Storm
199354 6.1 MEDIUM
Network
kindsoft kindeditor Cross Site Scripting (XSS) vulnerability in content1 parameter in demo.jsp in kindsoft kindeditor version 4.1.12, allows attackers to execute arbitrary code. CWE-79
Cross-site Scripting
CVE-2020-28717 2024-11-21 14:23 2023-08-11 Show GitHub Exploit DB Packet Storm
199355 9.8 CRITICAL
Network
mediawiki score The Score extension through 0.3.0 for MediaWiki has a remote code execution vulnerability due to improper sandboxing of the GNU LilyPond executable. This allows any user with an ability to edit artic… CWE-94
Code Injection
CVE-2020-29007 2024-11-21 14:23 2023-04-16 Show GitHub Exploit DB Packet Storm
199356 9.8 CRITICAL
Network
zend zend_framework An issue found in Zend Framework v.3.1.3 and before allow a remote attacker to execute arbitrary code via the unserialize function. Note: This has been disputed by third parties as incomplete and inc… CWE-502
 Deserialization of Untrusted Data
CVE-2020-29312 2024-11-21 14:23 2023-04-5 Show GitHub Exploit DB Packet Storm
199357 9.8 CRITICAL
Network
online_doctor_appointment_booking_system_php_and_mysql_project online_doctor_appointment_booking_system_php_and_mysql SQL Injection vulnerability in Projectworlds Online Doctor Appointment Booking System, allows attackers to gain sensitive information via the q parameter to the getuser.php endpoint. CWE-89
SQL Injection
CVE-2020-29168 2024-11-21 14:23 2023-02-18 Show GitHub Exploit DB Packet Storm
199358 9.8 CRITICAL
Network
online_food_ordering_system_project online_food_ordering_system Multiple SQL Injection vulnerabilities in tourist5 Online-food-ordering-system 1.0. CWE-89
SQL Injection
CVE-2020-29297 2024-11-21 14:23 2023-01-21 Show GitHub Exploit DB Packet Storm
199359 7.5 HIGH
Network
libvncserver_project
debian
libvncserver
debian_linux
libvncclient v0.9.13 was discovered to contain a memory leak via the function rfbClientCleanup(). CWE-400
 Uncontrolled Resource Consumption
CVE-2020-29260 2024-11-21 14:23 2022-09-3 Show GitHub Exploit DB Packet Storm
199360 7.5 HIGH
Network
powerjob powerjob An issue was discovered in PowerJob through 3.2.2, allows attackers to change arbitrary user passwords via the id parameter to /appinfo/save. CWE-522
 Insufficiently Protected Credentials
CVE-2020-28865 2024-11-21 14:23 2022-06-17 Show GitHub Exploit DB Packet Storm