Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 10, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228891 7.5 危険 シマンテック - Symantec Norton Ghost の RemoteCommand.DLL におけるバッファオーバーフローの脆弱性 - CVE-2007-3666 2012-12-20 18:33 2007-07-10 Show GitHub Exploit DB Packet Storm
228892 5 警告 シマンテック - Symantec Norton Ghost の FileBackup.DLL におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-3665 2012-12-20 18:33 2007-07-10 Show GitHub Exploit DB Packet Storm
228893 7.5 危険 Wafer - Webmatic における SQL インジェクションの脆弱性 - CVE-2007-3648 2012-12-20 18:33 2007-07-10 Show GitHub Exploit DB Packet Storm
228894 10 危険 ZoneO-soft - phpTrafficA の Php/login.inc.php における認証を回避される脆弱性 - CVE-2007-3647 2012-12-20 18:33 2007-07-10 Show GitHub Exploit DB Packet Storm
228895 4 警告 WordPress.org - WordPress における重要な情報を取得される脆弱性 - CVE-2007-3639 2012-12-20 18:33 2007-07-9 Show GitHub Exploit DB Packet Storm
228896 6 警告 Yahoo! - Yahoo! Messenger におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2007-3638 2012-12-20 18:33 2007-07-9 Show GitHub Exploit DB Packet Storm
228897 7.5 危険 SquirrelMail Project - Squirrelmail 用の GPG Plugin における任意のコマンドを実行される脆弱性 - CVE-2007-3636 2012-12-20 18:33 2007-07-9 Show GitHub Exploit DB Packet Storm
228898 4.3 警告 SquirrelMail Project - Squirrelmail 用の GPG Plugin における特定のコマンドを挿入される脆弱性 CWE-noinfo
情報不足
CVE-2007-3635 2012-12-20 18:33 2007-07-9 Show GitHub Exploit DB Packet Storm
228899 6.5 警告 SquirrelMail Project - Squirrelmail 用の GPG Plugin における任意のコマンドを実行される脆弱性 CWE-noinfo
情報不足
CVE-2007-3634 2012-12-20 18:33 2007-07-9 Show GitHub Exploit DB Packet Storm
228900 10 危険 SAP - SAP Message Server の Message HTTP Server におけるヒープベースのバッファオーバーフローの脆弱性 - CVE-2007-3624 2012-12-20 18:33 2007-07-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 11, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
209661 5.3 MEDIUM
Network
gitlab gitlab Private group info is leaked leaked in GitLab CE/EE version 10.2 and above, when the project is moved from private to public group. Affected versions are: >=10.2, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.… NVD-CWE-noinfo
CVE-2020-13352 2024-11-21 14:01 2020-11-17 Show GitHub Exploit DB Packet Storm
209662 5.4 MEDIUM
Network
ivanti endpoint_manager Ivanti Endpoint Manager through 2020.1.1 allows XSS via /LDMS/frm_splitfrm.aspx, /LDMS/licensecheck.aspx, /LDMS/frm_splitcollapse.aspx, /LDMS/alert_log.aspx, /LDMS/ServerList.aspx, /LDMS/frm_coremain… CWE-79
Cross-site Scripting
CVE-2020-13773 2024-11-21 14:01 2020-11-17 Show GitHub Exploit DB Packet Storm
209663 5.3 MEDIUM
Network
ivanti endpoint_manager In /ldclient/ldprov.cgi in Ivanti Endpoint Manager through 2020.1.1, an attacker is able to disclose information about the server operating system, local pathnames, and environment variables with no … NVD-CWE-noinfo
CVE-2020-13772 2024-11-21 14:01 2020-11-17 Show GitHub Exploit DB Packet Storm
209664 8.8 HIGH
Network
ivanti endpoint_manager LDMS/alert_log.aspx in Ivanti Endpoint Manager through 2020.1 allows SQL Injection via a /remotecontrolauth/api/device request. CWE-89
SQL Injection
CVE-2020-13769 2024-11-21 14:01 2020-11-17 Show GitHub Exploit DB Packet Storm
209665 9.8 CRITICAL
Network
rconfig rconfig lib/crud/userprocess.php in rConfig 3.9.x before 3.9.7 has an authentication bypass, leading to administrator account creation. This issue has been fixed in 3.9.7. CWE-269
 Improper Privilege Management
CVE-2020-13638 2024-11-21 14:01 2020-11-14 Show GitHub Exploit DB Packet Storm
209666 9.9 CRITICAL
Network
ivanti endpoint_manager An unrestricted file-upload issue in EditLaunchPadDialog.aspx in Ivanti Endpoint Manager 2019.1 and 2020.1 allows an authenticated attacker to gain remote code execution by uploading a malicious aspx… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2020-13774 2024-11-21 14:01 2020-11-13 Show GitHub Exploit DB Packet Storm
209667 7.8 HIGH
Local
ivanti endpoint_manager Various components in Ivanti Endpoint Manager through 2020.1.1 rely on Windows search order when loading a (nonexistent) library file, allowing (under certain conditions) one to gain code execution (… CWE-427
 Uncontrolled Search Path Element
CVE-2020-13771 2024-11-21 14:01 2020-11-13 Show GitHub Exploit DB Packet Storm
209668 7.8 HIGH
Local
ivanti endpoint_manager Several services are accessing named pipes in Ivanti Endpoint Manager through 2020.1.1 with default or overly permissive security attributes; as these services run as user ‘NT AUTHORITY\SYSTEM’, the … CWE-276
Incorrect Default Permissions 
CVE-2020-13770 2024-11-21 14:01 2020-11-13 Show GitHub Exploit DB Packet Storm
209669 7.8 HIGH
Local
moxa mxview An exploitable local privilege elevation vulnerability exists in the file system permissions of Moxa MXView series 3.1.8 installation. Depending on the vector chosen, an attacker can either add code … CWE-276
Incorrect Default Permissions 
CVE-2020-13537 2024-11-21 14:01 2020-11-6 Show GitHub Exploit DB Packet Storm
209670 7.8 HIGH
Local
moxa mxview An exploitable local privilege elevation vulnerability exists in the file system permissions of Moxa MXView series 3.1.8 installation. Depending on the vector chosen, an attacker can either add code … CWE-276
Incorrect Default Permissions 
CVE-2020-13536 2024-11-21 14:01 2020-11-6 Show GitHub Exploit DB Packet Storm