Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 11, 2026, 12:16 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
229271 4.3 警告 SquirrelMail Project - Squirrelmail 用の GPG Plugin の gpg_pop_init.php における PHP ローカルファイルインクルージョンの脆弱性 - CVE-2007-3779 2012-12-20 18:33 2007-07-15 Show GitHub Exploit DB Packet Storm
229272 7.5 危険 SquirrelMail Project - Squirrelmail 用の GPG Plugin における任意のコマンドを実行される脆弱性 - CVE-2007-3778 2012-12-20 18:33 2007-07-15 Show GitHub Exploit DB Packet Storm
229273 6.4 警告 psnews - PsNews の news/show.php におけるディレクトリトラバーサルの脆弱性 - CVE-2007-3772 2012-12-20 18:33 2007-07-15 Show GitHub Exploit DB Packet Storm
229274 4.6 警告 シマンテック - Symantec AntiVirus Corporate Edition および Client Security におけるスタックベースのバッファオーバーフローの脆弱性 - CVE-2007-3771 2012-12-20 18:33 2007-07-11 Show GitHub Exploit DB Packet Storm
229275 5 警告 silcnet - SILC Client および SILC Toolkit の lib/silcclient/client_notify.c におけるバッファオーバーフローの脆弱性 - CVE-2007-3728 2012-12-20 18:33 2007-07-12 Show GitHub Exploit DB Packet Storm
229276 7.5 危険 Wafer - Webmatic における脆弱性 - CVE-2007-3727 2012-12-20 18:33 2007-07-12 Show GitHub Exploit DB Packet Storm
229277 4.3 警告 RARLAB - unrar の rarvm.cpp における整数符号エラーの脆弱性 - CVE-2007-3726 2012-12-20 18:33 2007-07-12 Show GitHub Exploit DB Packet Storm
229278 2.1 注意 サン・マイクロシステムズ - Sun Solaris カーネルのプロセススケジューラにおけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-3723 2012-12-20 18:33 2007-07-12 Show GitHub Exploit DB Packet Storm
229279 6.9 警告 サン・マイクロシステムズ - Sun Solaris の rcp における権限を取得される脆弱性 - CVE-2007-3717 2012-12-20 18:33 2007-07-10 Show GitHub Exploit DB Packet Storm
229280 6.8 警告 zenturi - Zenturi ProgramChecker の sasatl.dll におけるスタックベースのバッファオーバーフローの脆弱性 - CVE-2007-3703 2012-12-20 18:33 2007-07-11 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 11, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
200631 7.4 HIGH
Network
saltstack
fedoraproject
debian
salt
fedora
debian_linux
In SaltStack Salt before 3002.5, when authenticating to services using certain modules, the SSL certificate is not always validated. CWE-295
Improper Certificate Validation 
CVE-2020-35662 2024-11-21 14:27 2021-02-27 Show GitHub Exploit DB Packet Storm
200632 6.1 MEDIUM
Network
acronis cyber_protect An issue was discovered in Acronis Cyber Protect before 15 Update 1 build 26172. There is cross-site scripting (XSS) in the console. CWE-79
Cross-site Scripting
CVE-2020-35664 2024-11-21 14:27 2021-02-22 Show GitHub Exploit DB Packet Storm
200633 6.1 MEDIUM
Network
mantisbt mantisbt An issue was discovered in MantisBT through 2.24.3. In the helper_ensure_confirmed call in manage_custom_field_update.php, the custom field name is not sanitized. This may be problematic depending on… CWE-79
Cross-site Scripting
CVE-2020-35571 2024-11-21 14:27 2021-02-22 Show GitHub Exploit DB Packet Storm
200634 7.5 HIGH
Network
acronis cyber_protect An issue was discovered in Acronis Cyber Protect before 15 Update 1 build 26172. Because the local notification service misconfigures CORS, information disclosure can occur. NVD-CWE-noinfo
CVE-2020-35556 2024-11-21 14:27 2021-02-22 Show GitHub Exploit DB Packet Storm
200635 7.4 HIGH
Network
djangoproject channels Django Channels 3.x before 3.0.3 allows remote attackers to obtain sensitive information from a different request scope. The legacy channels.http.AsgiHandler class, used for handling HTTP type reques… CWE-200
Information Exposure
CVE-2020-35681 2024-11-21 14:27 2021-02-22 Show GitHub Exploit DB Packet Storm
200636 6.7 MEDIUM
Local
linux linux_kernel A NULL pointer dereference flaw in Linux kernel versions prior to 5.11 may be seen if sco_sock_getsockopt function in net/bluetooth/sco.c do not have a sanity check for a socket connection, when usin… CWE-476
 NULL Pointer Dereference
CVE-2020-35499 2024-11-21 14:27 2021-02-20 Show GitHub Exploit DB Packet Storm
200637 5.4 MEDIUM
Network
pi-hole pi-hole Pi-hole 5.0, 5.1, and 5.1.1 allows XSS via the Options header to the admin/ URI. A remote user is able to inject arbitrary web script or HTML due to incorrect sanitization of user-supplied data and a… CWE-79
Cross-site Scripting
CVE-2020-35592 2024-11-21 14:27 2021-02-19 Show GitHub Exploit DB Packet Storm
200638 5.4 MEDIUM
Network
pi-hole pi-hole Pi-hole 5.0, 5.1, and 5.1.1 allows Session Fixation. The application does not generate a new session cookie after the user is logged in. A malicious user is able to create a new session cookie value … CWE-384
 Session Fixation
CVE-2020-35591 2024-11-21 14:27 2021-02-19 Show GitHub Exploit DB Packet Storm
200639 6.5 MEDIUM
Network
endalia selection_portal In Endalia Selection Portal before 4.205.0, an Insecure Direct Object Reference (IDOR) allows any authenticated user to download every file uploaded to the platform by changing the value of the file … NVD-CWE-Other
CVE-2020-35577 2024-11-21 14:27 2021-02-18 Show GitHub Exploit DB Packet Storm
200640 9.8 CRITICAL
Network
74cms 74cms In 74cms version 5.0.1, there is a remote code execution vulnerability in /Application/Admin/Controller/ConfigController.class.php and /ThinkPHP/Common/functions.php where attackers can obtain server… CWE-94
Code Injection
CVE-2020-35339 2024-11-21 14:27 2021-02-18 Show GitHub Exploit DB Packet Storm