Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 7, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
229251 7.5 危険 scipter.ch - Sinapis Gastebuch の sinagb.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-1130 2012-12-20 18:19 2007-02-26 Show GitHub Exploit DB Packet Storm
229252 5 警告 watersweb shops - shopkitplus における重要な情報を取得される脆弱性 - CVE-2007-1128 2012-12-20 18:19 2007-02-26 Show GitHub Exploit DB Packet Storm
229253 6.4 警告 watersweb shops - shopkitplus の enc/stylecss.php におけるディレクトリトラバーサルの脆弱性 - CVE-2007-1127 2012-12-20 18:19 2007-02-26 Show GitHub Exploit DB Packet Storm
229254 5 警告 xt:Commerce - xtcommerce の index.php におけるディレクトリトラバーサルの脆弱性 - CVE-2007-1126 2012-12-20 18:19 2007-02-26 Show GitHub Exploit DB Packet Storm
229255 4.3 警告 xeroxer - XeroXer Simple one-file gallery の gallery.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-1125 2012-12-20 18:19 2007-02-26 Show GitHub Exploit DB Packet Storm
229256 5 警告 xeroxer - XeroXer Simple one-file gallery の gallery.php におけるディレクトリトラバーサルの脆弱性 - CVE-2007-1124 2012-12-20 18:19 2007-02-26 Show GitHub Exploit DB Packet Storm
229257 7.5 危険 ZPanel Project - ZPanel における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-1123 2012-12-20 18:19 2007-02-26 Show GitHub Exploit DB Packet Storm
229258 6.4 警告 zephyrsoft toolbox - Mathis Dirksen-Thedens ZephyrSoft Toolbox ABC における SQL インジェクションの脆弱性 - CVE-2007-1122 2012-12-20 18:19 2007-02-26 Show GitHub Exploit DB Packet Storm
229259 6.4 警告 zephyrsoft toolbox - Mathis Dirksen-Thedens ZephyrSoft Toolbox ABC における SQL インジェクションの脆弱性 - CVE-2007-1121 2012-12-20 18:19 2007-02-26 Show GitHub Exploit DB Packet Storm
229260 9.3 危険 steema software - TeeChart Pro ActiveX コントロールにおける .tee ファイルをダウンロードされる脆弱性 - CVE-2007-1120 2012-12-20 18:19 2007-02-26 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 7, 2026, 4:22 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
200291 4.3 MEDIUM
Network
jenkins mongodb A missing permission check in Jenkins MongoDB Plugin 1.3 and earlier allows attackers with Overall/Read permission to gain access to some metadata of any arbitrary files on the Jenkins controller. CWE-862
 Missing Authorization
CVE-2020-2267 2024-11-21 14:25 2020-09-16 Show GitHub Exploit DB Packet Storm
200292 5.4 MEDIUM
Network
jenkins description_column Jenkins Description Column Plugin 1.3 and earlier does not escape the job description in the column tooltip, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers wi… CWE-79
Cross-site Scripting
CVE-2020-2266 2024-11-21 14:25 2020-09-16 Show GitHub Exploit DB Packet Storm
200293 5.4 MEDIUM
Network
jenkins coverage\/complexity_scatter_plot Jenkins Coverage/Complexity Scatter Plot Plugin 1.1.1 and earlier does not escape the method information in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by att… CWE-79
Cross-site Scripting
CVE-2020-2265 2024-11-21 14:25 2020-09-16 Show GitHub Exploit DB Packet Storm
200294 5.4 MEDIUM
Network
jenkins custom_job_icon Jenkins Custom Job Icon Plugin 0.2 and earlier does not escape the job descriptions in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Confi… CWE-79
Cross-site Scripting
CVE-2020-2264 2024-11-21 14:25 2020-09-16 Show GitHub Exploit DB Packet Storm
200295 5.4 MEDIUM
Network
jenkins radiator_view Jenkins Radiator View Plugin 1.29 and earlier does not escape the full name of the jobs in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/C… CWE-79
Cross-site Scripting
CVE-2020-2263 2024-11-21 14:25 2020-09-16 Show GitHub Exploit DB Packet Storm
200296 5.4 MEDIUM
Network
jenkins android_lint Jenkins Android Lint Plugin 2.6 and earlier does not escape the annotation message in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide… CWE-79
Cross-site Scripting
CVE-2020-2262 2024-11-21 14:25 2020-09-16 Show GitHub Exploit DB Packet Storm
200297 8.8 HIGH
Network
jenkins perfecto Jenkins Perfecto Plugin 1.17 and earlier executes a command on the Jenkins controller, allowing attackers with Job/Configure permission to run arbitrary commands on the Jenkins controller CWE-78
OS Command 
CVE-2020-2261 2024-11-21 14:25 2020-09-16 Show GitHub Exploit DB Packet Storm
200298 4.3 MEDIUM
Network
jenkins perfecto A missing permission check in Jenkins Perfecto Plugin 1.17 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified HTTP URL using attacker-specified credentials. CWE-862
 Missing Authorization
CVE-2020-2260 2024-11-21 14:25 2020-09-16 Show GitHub Exploit DB Packet Storm
200299 5.4 MEDIUM
Network
jenkins computer_queue Jenkins computer-queue-plugin Plugin 1.5 and earlier does not escape the agent name in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Con… CWE-79
Cross-site Scripting
CVE-2020-2259 2024-11-21 14:25 2020-09-16 Show GitHub Exploit DB Packet Storm
200300 4.3 MEDIUM
Network
jenkins health_advisor_by_cloudbees Jenkins Health Advisor by CloudBees Plugin 3.2.0 and earlier does not correctly perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to view that HTTP endpo… CWE-863
 Incorrect Authorization
CVE-2020-2258 2024-11-21 14:25 2020-09-16 Show GitHub Exploit DB Packet Storm