Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":April 28, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228791 5 警告 walter beschmout - Walter Beschmout PhpQuiz の back/upload_img.php などにおける任意の PHP コードをアップロードされる脆弱性 - CVE-2006-4977 2012-12-20 18:02 2006-09-24 Show GitHub Exploit DB Packet Storm
228792 2.6 注意 Yahoo! - WAP 用の Yahoo! Messenger における任意の Web スクリプトまたは HTML を挿入される脆弱性 - CVE-2006-4975 2012-12-20 18:02 2006-09-24 Show GitHub Exploit DB Packet Storm
228793 7.5 危険 wahm e-commerce - WAHM E-Commerce Pie Cart Pro の enc/content.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-4970 2012-12-20 18:02 2006-09-24 Show GitHub Exploit DB Packet Storm
228794 7.5 危険 wahm e-commerce - WAHM E-Commerce Pie Cart Pro における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-4969 2012-12-20 18:02 2006-09-24 Show GitHub Exploit DB Packet Storm
228795 7.5 危険 postnuke software foundation - PNphpBB の includes/functions_admin.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-4968 2012-12-20 18:02 2006-09-24 Show GitHub Exploit DB Packet Storm
228796 5 警告 サン・マイクロシステムズ - SSGD におけるホスト名などを含む重要な情報を取得される脆弱性 - CVE-2006-4959 2012-12-20 18:02 2006-09-23 Show GitHub Exploit DB Packet Storm
228797 6.8 警告 サン・マイクロシステムズ - SSGD におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-4958 2012-12-20 18:02 2006-09-23 Show GitHub Exploit DB Packet Storm
228798 7.5 危険 the myreview system - MyReview の functions.php における SQL インジェクションの脆弱性 - CVE-2006-4957 2012-12-20 18:02 2006-09-23 Show GitHub Exploit DB Packet Storm
228799 7.5 危険 prosysinfo - ProSysInfo TFTP Server TFTPDWIN の tftpd.exe におけるスタックベースのバッファオーバーフローの脆弱性 - CVE-2006-4948 2012-12-20 18:02 2006-09-22 Show GitHub Exploit DB Packet Storm
228800 4.6 警告 シマンテック - Symantec AntiVirus などの製品で使用される NAVENG などのデバイスドライバにおける権限を取得される脆弱性 - CVE-2006-4927 2012-12-20 18:02 2006-10-4 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 29, 2026, 4:51 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
198121 7.5 HIGH
Network
searchblox searchblox A local file inclusion vulnerability in the FileServlet in all SearchBlox before 9.2.2 allows remote, unauthenticated users to read arbitrary files from the operating system via a /searchblox/servlet… CWE-22
Path Traversal
CVE-2020-35580 2024-11-21 14:27 2021-05-21 Show GitHub Exploit DB Packet Storm
198122 6.1 MEDIUM
Network
kamalkhan kk_star_ratings Cross Site Scripting (XSS) vulnerability in the kk Star Ratings plugin before 4.1.5. CWE-79
Cross-site Scripting
CVE-2020-35438 2024-11-21 14:27 2021-05-11 Show GitHub Exploit DB Packet Storm
198123 7.8 HIGH
Local
linux
netapp
linux_kernel
cloud_backup
solidfire_baseboard_management_controller_firmware
h300s_firmware
h500s_firmware
h700s_firmware
h300e_firmware
h500e_firmware
h700e_firmware
h410s…
An out-of-bounds (OOB) memory access flaw was found in x25_bind in net/x25/af_x25.c in the Linux kernel version v5.12-rc5. A bounds check failure allows a local attacker with a user account on the sy… - CVE-2020-35519 2024-11-21 14:27 2021-05-7 Show GitHub Exploit DB Packet Storm
198124 9.8 CRITICAL
Network
inxedu inxedu SQL Injection in com/inxedu/OS/edu/controller/letter/AdminMsgSystemController in Inxedu v2.0.6 via the ids parameter to admin/letter/delsystem. CWE-89
SQL Injection
CVE-2020-35430 2024-11-21 14:27 2021-04-30 Show GitHub Exploit DB Packet Storm
198125 5.4 MEDIUM
Network
unisys data_exchange_management_studio Unisys Data Exchange Management Studio through 5.0.34 doesn't sanitize the input to a HTML document field. This could be used for an XSS attack. CWE-79
Cross-site Scripting
CVE-2020-35542 2024-11-21 14:27 2021-04-27 Show GitHub Exploit DB Packet Storm
198126 9.8 CRITICAL
Network
wondercms wondercms A remote code execution vulnerability in the installUpdateThemePluginAction function in index.php in WonderCMS 3.1.3, allows remote attackers to upload a custom plugin which can contain arbitrary cod… CWE-78
OS Command 
CVE-2020-35314 2024-11-21 14:27 2021-04-21 Show GitHub Exploit DB Packet Storm
198127 9.8 CRITICAL
Network
wondercms wondercms A server-side request forgery (SSRF) vulnerability in the addCustomThemePluginRepository function in index.php in WonderCMS 3.1.3 allows remote attackers to execute arbitrary code via a crafted URL t… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2020-35313 2024-11-21 14:27 2021-04-21 Show GitHub Exploit DB Packet Storm
198128 5.4 MEDIUM
Network
monicahq monica Cross Site Scripting (XSS) in Monica before 2.19.1 via the journal page. CWE-79
Cross-site Scripting
CVE-2020-35660 2024-11-21 14:27 2021-04-15 Show GitHub Exploit DB Packet Storm
198129 6.1 MEDIUM
Network
group-office group_office Cross Site Scripting (XSS) in Group Office CRM 6.4.196 via the SET_LANGUAGE parameter. CWE-79
Cross-site Scripting
CVE-2020-35419 2024-11-21 14:27 2021-04-15 Show GitHub Exploit DB Packet Storm
198130 5.4 MEDIUM
Network
group-office group_office Cross Site Scripting (XSS) in the contact page of Group Office CRM 6.4.196 by uploading a crafted svg file. CWE-79
Cross-site Scripting
CVE-2020-35418 2024-11-21 14:27 2021-04-15 Show GitHub Exploit DB Packet Storm