Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 11, 2026, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228691 7.5 危険 xecms - xeCMS の view.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2007-6508 2012-12-20 18:34 2007-12-21 Show GitHub Exploit DB Packet Storm
228692 10 危険 トレンドマイクロ - Windows 用の Trend Micro ServerProtect における "ファイルシステムの全アクセス権限" を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2007-6507 2012-12-20 18:34 2007-07-27 Show GitHub Exploit DB Packet Storm
228693 4.9 警告 plain black - Plain Black WebGUI における管理アカウントを作成される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2007-6487 2012-12-20 18:34 2007-12-20 Show GitHub Exploit DB Packet Storm
228694 6.8 警告 phprpg - phpRPG の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-6484 2012-12-20 18:34 2007-12-20 Show GitHub Exploit DB Packet Storm
228695 7.8 危険 サン・マイクロシステムズ - Sun Ray Server Software の utdevmgrd におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2007-6482 2012-12-20 18:34 2007-12-18 Show GitHub Exploit DB Packet Storm
228696 6.4 警告 サン・マイクロシステムズ - Sun Ray Server Software の utdevmgrd における任意のディレクトリを削除される脆弱性 CWE-DesignError
CVE-2007-6481 2012-12-20 18:34 2007-12-18 Show GitHub Exploit DB Packet Storm
228697 9.4 危険 サン・マイクロシステムズ - Sun MC の Oracle データベースコンポーネントにおける任意のコードを実行される脆弱性 CWE-DesignError
CVE-2007-6480 2012-12-20 18:34 2007-12-18 Show GitHub Exploit DB Packet Storm
228698 6.8 警告 rosoftengineering - Rosoft Media Player におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2007-6478 2012-12-20 18:34 2007-12-20 Show GitHub Exploit DB Packet Storm
228699 5.8 警告 texas imperial software - Texas Imperial Software WFTPD Pro Explorer におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2007-6473 2012-12-20 18:34 2007-12-20 Show GitHub Exploit DB Packet Storm
228700 7.5 危険 phpmyrealty - PMR における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-6472 2012-12-20 18:34 2007-12-20 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 11, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
196121 7.5 HIGH
Network
solarwinds n-central SolarWinds N-central before 12.1 SP1 HF5 and 12.2 before SP1 HF2 allows remote attackers to retrieve cleartext domain admin credentials from the Agent & Probe settings, and obtain other sensitive inf… CWE-319
Cleartext Transmission of Sensitive Information
CVE-2020-7984 2024-11-21 14:38 2020-01-27 Show GitHub Exploit DB Packet Storm
196122 9.8 CRITICAL
Network
rubygeocoder geocoder sql.rb in Geocoder before 1.6.1 allows Boolean-based SQL injection when within_bounding_box is used in conjunction with untrusted sw_lat, sw_lng, ne_lat, or ne_lng data. CWE-89
SQL Injection
CVE-2020-7981 2024-11-21 14:38 2020-01-26 Show GitHub Exploit DB Packet Storm
196123 9.8 CRITICAL
Network
intelliantech aptus_web Intellian Aptus Web 1.24 allows remote attackers to execute arbitrary OS commands via the Q field within JSON data to the cgi-bin/libagent.cgi URI. NOTE: a valid sid cookie for a login to the intelli… CWE-78
OS Command 
CVE-2020-7980 2024-11-21 14:38 2020-01-26 Show GitHub Exploit DB Packet Storm
196124 5.3 MEDIUM
Network
mirumee saleor An issue was discovered in Mirumee Saleor 2.x before 2.9.1. Incorrect access control in the checkoutCustomerAttach mutations allows attackers to attach their checkouts to any user ID and consequently… CWE-306
Missing Authentication for Critical Function
CVE-2020-7964 2024-11-21 14:38 2020-01-25 Show GitHub Exploit DB Packet Storm
196125 9.8 CRITICAL
Network
plone plone A privilege escalation issue in plone.app.contenttypes in Plone 4.3 through 5.2.1 allows users to PUT (overwrite) some content without needing write permission. NVD-CWE-noinfo
CVE-2020-7941 2024-11-21 14:38 2020-01-24 Show GitHub Exploit DB Packet Storm
196126 7.5 HIGH
Network
plone plone Missing password strength checks on some forms in Plone 4.3 through 5.2.0 allow users to set weak passwords, leading to easier cracking. CWE-521
Weak Password Requirements 
CVE-2020-7940 2024-11-21 14:38 2020-01-24 Show GitHub Exploit DB Packet Storm
196127 8.8 HIGH
Network
plone plone SQL Injection in DTML or in connection objects in Plone 4.0 through 5.2.1 allows users to perform unwanted SQL queries. (This is a problem in Zope.) CWE-89
SQL Injection
CVE-2020-7939 2024-11-21 14:38 2020-01-24 Show GitHub Exploit DB Packet Storm
196128 8.8 HIGH
Network
plone plone plone.restapi in Plone 5.2.0 through 5.2.1 allows users with a certain privilege level to escalate their privileges up to the highest level. NVD-CWE-noinfo
CVE-2020-7938 2024-11-21 14:38 2020-01-24 Show GitHub Exploit DB Packet Storm
196129 5.4 MEDIUM
Network
plone plone An XSS issue in the title field in Plone 5.0 through 5.2.1 allows users with a certain privilege level to insert JavaScript that will be executed when other users access the site. CWE-79
Cross-site Scripting
CVE-2020-7937 2024-11-21 14:38 2020-01-24 Show GitHub Exploit DB Packet Storm
196130 6.1 MEDIUM
Network
plone plone An open redirect on the login form (and possibly other places) in Plone 4.0 through 5.2.1 allows an attacker to craft a link to a Plone Site that, when followed, and possibly after login, will redire… CWE-601
Open Redirect
CVE-2020-7936 2024-11-21 14:38 2020-01-24 Show GitHub Exploit DB Packet Storm