Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 8, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228821 7.5 危険 precisionid barcode - PrecisionID_Barcode.dll の PrecisionID Barcode ActiveX コントロールにおけるスタックベースのバッファオーバーフローの脆弱性 - CVE-2007-2744 2012-12-20 18:19 2007-05-17 Show GitHub Exploit DB Packet Storm
228822 6.8 警告 xajax-project - xajax における脆弱性 - CVE-2007-2740 2012-12-20 18:19 2007-05-17 Show GitHub Exploit DB Packet Storm
228823 4.3 警告 xajax-project - xajax におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-2739 2012-12-20 18:19 2007-05-17 Show GitHub Exploit DB Packet Storm
228824 7.5 危険 XOOPS - XOOPS 用の Glossaire モジュールにおける SQL インジェクションの脆弱性 - CVE-2007-2738 2012-12-20 18:19 2007-05-17 Show GitHub Exploit DB Packet Storm
228825 7.5 危険 XOOPS - Xoops 用の MyConference モジュールにおける SQL インジェクションの脆弱性 - CVE-2007-2737 2012-12-20 18:19 2007-05-17 Show GitHub Exploit DB Packet Storm
228826 7.5 危険 touteresa - Xoops 用の ResManager モジュールにおける SQL インジェクションの脆弱性 - CVE-2007-2735 2012-12-20 18:19 2007-05-17 Show GitHub Exploit DB Packet Storm
228827 10 危険 snaps gallery - Snaps! Gallery の Admin/users.php における任意のユーザ名を変更される脆弱性 - CVE-2007-2715 2012-12-20 18:19 2007-05-16 Show GitHub Exploit DB Packet Storm
228828 10 危険 tinyirc - TinyIdentD におけるスタックベースのバッファオーバーフローの脆弱性 - CVE-2007-2711 2012-12-20 18:19 2007-05-16 Show GitHub Exploit DB Packet Storm
228829 6.8 警告 simple php scripts gallery - sphp の Ivan Peevski gallery における任意の PHP コードを実行される脆弱性 - CVE-2007-2679 2012-12-20 18:19 2007-05-14 Show GitHub Exploit DB Packet Storm
228830 7.5 危険 phpchess - phpChess Community Edition における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-2677 2012-12-20 18:19 2007-05-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 8, 2026, 4:54 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
200611 5.4 MEDIUM
Network
jenkins custom_job_icon Jenkins Custom Job Icon Plugin 0.2 and earlier does not escape the job descriptions in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Confi… CWE-79
Cross-site Scripting
CVE-2020-2264 2024-11-21 14:25 2020-09-16 Show GitHub Exploit DB Packet Storm
200612 5.4 MEDIUM
Network
jenkins radiator_view Jenkins Radiator View Plugin 1.29 and earlier does not escape the full name of the jobs in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/C… CWE-79
Cross-site Scripting
CVE-2020-2263 2024-11-21 14:25 2020-09-16 Show GitHub Exploit DB Packet Storm
200613 5.4 MEDIUM
Network
jenkins android_lint Jenkins Android Lint Plugin 2.6 and earlier does not escape the annotation message in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide… CWE-79
Cross-site Scripting
CVE-2020-2262 2024-11-21 14:25 2020-09-16 Show GitHub Exploit DB Packet Storm
200614 8.8 HIGH
Network
jenkins perfecto Jenkins Perfecto Plugin 1.17 and earlier executes a command on the Jenkins controller, allowing attackers with Job/Configure permission to run arbitrary commands on the Jenkins controller CWE-78
OS Command 
CVE-2020-2261 2024-11-21 14:25 2020-09-16 Show GitHub Exploit DB Packet Storm
200615 4.3 MEDIUM
Network
jenkins perfecto A missing permission check in Jenkins Perfecto Plugin 1.17 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified HTTP URL using attacker-specified credentials. CWE-862
 Missing Authorization
CVE-2020-2260 2024-11-21 14:25 2020-09-16 Show GitHub Exploit DB Packet Storm
200616 5.4 MEDIUM
Network
jenkins computer_queue Jenkins computer-queue-plugin Plugin 1.5 and earlier does not escape the agent name in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Con… CWE-79
Cross-site Scripting
CVE-2020-2259 2024-11-21 14:25 2020-09-16 Show GitHub Exploit DB Packet Storm
200617 4.3 MEDIUM
Network
jenkins health_advisor_by_cloudbees Jenkins Health Advisor by CloudBees Plugin 3.2.0 and earlier does not correctly perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to view that HTTP endpo… CWE-863
 Incorrect Authorization
CVE-2020-2258 2024-11-21 14:25 2020-09-16 Show GitHub Exploit DB Packet Storm
200618 5.4 MEDIUM
Network
jenkins validating_string_parameter Jenkins Validating String Parameter Plugin 2.4 and earlier does not escape various user-controlled fields, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with… CWE-79
Cross-site Scripting
CVE-2020-2257 2024-11-21 14:25 2020-09-16 Show GitHub Exploit DB Packet Storm
200619 5.4 MEDIUM
Network
jenkins pipeline_maven_integration Jenkins Pipeline Maven Integration Plugin 3.9.2 and earlier does not escape the upstream job's display name shown as part of a build cause, resulting in a stored cross-site scripting (XSS) vulnerabil… CWE-79
Cross-site Scripting
CVE-2020-2256 2024-11-21 14:25 2020-09-16 Show GitHub Exploit DB Packet Storm
200620 4.3 MEDIUM
Network
jenkins blue_ocean A missing permission check in Jenkins Blue Ocean Plugin 1.23.2 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL. CWE-862
 Missing Authorization
CVE-2020-2255 2024-11-21 14:25 2020-09-16 Show GitHub Exploit DB Packet Storm