Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 6, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228751 7.5 危険 rediff - redifftoolbar.dll の Rediff Toolbar ActiveX コントロールにおけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-1402 2012-12-20 18:19 2007-03-10 Show GitHub Exploit DB Packet Storm
228752 6.9 警告 plesh - Plash における任意のコマンドを実行される脆弱性 - CVE-2007-1400 2012-12-20 18:19 2007-03-10 Show GitHub Exploit DB Packet Storm
228753 7.1 危険 Snort.org - Snort の frag3 プリプロセッサにおけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-1398 2012-12-20 18:19 2007-03-10 Show GitHub Exploit DB Packet Storm
228754 4.3 警告 The phpMyAdmin Project - phpMyAdmin の index.php におけるクロスサイトスクリプティング (XSS) 攻撃を実行される脆弱性 - CVE-2007-1395 2012-12-20 18:19 2007-03-10 Show GitHub Exploit DB Packet Storm
228755 10 危険 webo - Leo West WEBO の modules/abook/foldertree.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-1391 2012-12-20 18:19 2007-03-10 Show GitHub Exploit DB Packet Storm
228756 4.3 警告 Snitz - Snitz Forums 2000 の pop_profile.asp におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-1374 2012-12-20 18:19 2007-03-9 Show GitHub Exploit DB Packet Storm
228757 10 危険 Pegasus Mail - Mercury/32 におけるスタックベースのバッファオーバーフローの脆弱性 - CVE-2007-1373 2012-12-20 18:19 2007-03-9 Show GitHub Exploit DB Packet Storm
228758 10 危険 postguestbook - PHP-Nuke 用の PostGuestbook モジュールにおける PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-1372 2012-12-20 18:19 2007-03-9 Show GitHub Exploit DB Packet Storm
228759 6.9 警告 Jon Trulson - Conquest におけるバッファオーバーフローの脆弱性 - CVE-2007-1371 2012-12-20 18:19 2007-03-9 Show GitHub Exploit DB Packet Storm
228760 6.2 警告 Zend Technologies Ltd. - Zend Platform におけるルート権限を取得される脆弱性 - CVE-2007-1370 2012-12-20 18:19 2007-03-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 7, 2026, 4:22 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
209941 7.5 HIGH
Network
jetbrains goland In JetBrains GoLand before 2019.3.2, the plugin repository was accessed via HTTP instead of HTTPS. CWE-319
Cleartext Transmission of Sensitive Information
CVE-2020-11685 2024-11-21 13:58 2020-04-22 Show GitHub Exploit DB Packet Storm
209942 8.1 HIGH
Adjacent
titan sf_rush_smart_band_firmware An issue was discovered on Tata Sonata Smart SF Rush 1.12 devices. It has been identified that the smart band has no pairing (mode 0 Bluetooth LE security level) The data being transmitted over the a… CWE-347
CWE-306
CWE-319
 Improper Verification of Cryptographic Signature
Missing Authentication for Critical Function
Cleartext Transmission of Sensitive Information
CVE-2020-11539 2024-11-21 13:58 2020-04-22 Show GitHub Exploit DB Packet Storm
209943 5.3 MEDIUM
Network
joomla joomla\! An issue was discovered in Joomla! before 3.9.17. Incorrect ACL checks in the access level section of com_users allow the unauthorized editing of usergroups. NVD-CWE-noinfo
CVE-2020-11891 2024-11-21 13:58 2020-04-22 Show GitHub Exploit DB Packet Storm
209944 5.3 MEDIUM
Network
joomla joomla\! An issue was discovered in Joomla! before 3.9.17. Improper input validations in the usergroup table class could lead to a broken ACL configuration. CWE-20
 Improper Input Validation 
CVE-2020-11890 2024-11-21 13:58 2020-04-22 Show GitHub Exploit DB Packet Storm
209945 5.3 MEDIUM
Network
joomla joomla\! An issue was discovered in Joomla! before 3.9.17. Incorrect ACL checks in the access level section of com_users allow the unauthorized deletion of usergroups. NVD-CWE-noinfo
CVE-2020-11889 2024-11-21 13:58 2020-04-22 Show GitHub Exploit DB Packet Storm
209946 7.5 HIGH
Network
oppo coloros In ColorOS (oppo mobile phone operating system, based on AOSP frameworks/native code position/services/surfaceflinger surfaceflinger.CPP), RGB is defined on the stack but uninitialized, so when the s… CWE-908
 Use of Uninitialized Resource
CVE-2020-11828 2024-11-21 13:58 2020-04-21 Show GitHub Exploit DB Packet Storm
209947 7.8 HIGH
Local
re2c
canonical
re2c
ubuntu_linux
re2c 1.3 has a heap-based buffer overflow in Scanner::fill in parse/scanner.cc via a long lexeme. CWE-787
 Out-of-bounds Write
CVE-2020-11958 2024-11-21 13:58 2020-04-21 Show GitHub Exploit DB Packet Storm
209948 9.8 CRITICAL
Network
evenroute iqrouter_firmware IQrouter through 3.3.1, when unconfigured, has multiple remote code execution vulnerabilities in the web-panel because of Bash Shell Metacharacter Injection. Note: The vendor claims that this vulnera… CWE-78
OS Command 
CVE-2020-11963 2024-11-21 13:58 2020-04-21 Show GitHub Exploit DB Packet Storm
209949 6.1 MEDIUM
Network
bitcoin-abe_project bitcoin-abe Abe (aka bitcoin-abe) through 0.7.2, and 0.8pre, allows XSS in __call__ in abe.py because the PATH_INFO environment variable is mishandled during a PageNotFound exception. CWE-79
Cross-site Scripting
CVE-2020-11944 2024-11-21 13:58 2020-04-21 Show GitHub Exploit DB Packet Storm
209950 7.5 HIGH
Network
zohocorp manageengine_opmanager Zoho ManageEngine OpManager before 125120 allows an unauthenticated user to retrieve an API key via a servlet call. CWE-306
Missing Authentication for Critical Function
CVE-2020-11946 2024-11-21 13:58 2020-04-21 Show GitHub Exploit DB Packet Storm