Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 6, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
229281 10 危険 short url
url tracker script
- Yourfreeworld.com Short Url & Url Tracker Script における重要な情報を取得される脆弱性 - CVE-2006-6460 2012-12-20 18:02 2006-12-11 Show GitHub Exploit DB Packet Storm
229282 6.8 警告 phpBB - PhpBB Toplist の toplist.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-6459 2012-12-20 18:02 2006-12-11 Show GitHub Exploit DB Packet Storm
229283 5 警告 Tiki Software Community Association - Tikiwiki の tiki-wiki_rss.php における重要な情報 (MySQL ユーザ名およびパスワード) を取得される脆弱性 CWE-200
情報漏えい
CVE-2006-6457 2012-12-20 18:02 2006-12-11 Show GitHub Exploit DB Packet Storm
229284 6.8 警告 swsoft - SWsoft Plesk におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-6451 2012-12-20 18:02 2006-12-10 Show GitHub Exploit DB Packet Storm
229285 6.4 警告 vt-forum - Vt-Forum Lite におけるデータベースをダウンロードされる脆弱性 - CVE-2006-6449 2012-12-20 18:02 2006-12-10 Show GitHub Exploit DB Packet Storm
229286 7.5 危険 vt-forum - Vt-Forum Lite における SQL インジェクションの脆弱性 - CVE-2006-6448 2012-12-20 18:02 2006-12-10 Show GitHub Exploit DB Packet Storm
229287 6.8 警告 vt-forum - Vt-Forum Lite におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-6447 2012-12-20 18:02 2006-12-10 Show GitHub Exploit DB Packet Storm
229288 4.6 警告 Xerox - Xerox WorkCentre および WorkCentre Pro におけるセキュリティ制御を回避される脆弱性 - CVE-2006-6441 2012-12-20 18:02 2006-11-30 Show GitHub Exploit DB Packet Storm
229289 7.5 危険 Xerox - Xerox WorkCentre および WorkCentre Pro などにおける脆弱性 - CVE-2006-6440 2012-12-20 18:02 2006-11-30 Show GitHub Exploit DB Packet Storm
229290 7.8 危険 Xerox - Xerox WorkCentre および WorkCentre Pro における監査ログをダウンロードされる脆弱性 - CVE-2006-6439 2012-12-20 18:02 2006-11-30 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 6, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
197191 9.8 CRITICAL
Network
dell security_management_server Dell Security Management Server versions prior to 10.2.10 contain a Java RMI Deserialization of Untrusted Data vulnerability. When the server is exposed to the internet and Windows Firewall is disabl… CWE-502
 Deserialization of Untrusted Data
CVE-2020-5327 2024-11-21 14:33 2020-03-7 Show GitHub Exploit DB Packet Storm
197192 6.3 MEDIUM
Network
prestashop prestashop In PrestaShop before version 1.7.6.4, when a customer edits their address, they can freely change the id_address in the form, and thus steal someone else's address. It is the same with CustomerForm, … CWE-552
 Files or Directories Accessible to External Parties
CVE-2020-5250 2024-11-21 14:33 2020-03-6 Show GitHub Exploit DB Packet Storm
197193 5.3 MEDIUM
Network
parseplatform parse-server In parser-server before version 4.1.0, you can fetch all the users objects, by using regex in the NoSQL query. Using the NoSQL, you can use a regex on sessionToken and find valid accounts this way. CWE-863
 Incorrect Authorization
CVE-2020-5251 2024-11-21 14:33 2020-03-5 Show GitHub Exploit DB Packet Storm
197194 6.5 MEDIUM
Network
puma puma In Puma (RubyGem) before 4.3.3 and 3.12.4, if an application using Puma allows untrusted input in an early-hints header, an attacker can use a carriage return character to end the header and inject m… CWE-74
Injection
CVE-2020-5249 2024-11-21 14:33 2020-03-3 Show GitHub Exploit DB Packet Storm
197195 7.5 HIGH
Network
ruby-lang
puma
debian
fedoraproject
ruby
puma
debian_linux
fedora
In Puma (RubyGem) before 4.3.2 and before 3.12.3, if an application using Puma allows untrusted input in a response header, an attacker can use newline characters (i.e. `CR`, `LF` or`/r`, `/n`) to en… - CVE-2020-5247 2024-11-21 14:33 2020-02-29 Show GitHub Exploit DB Packet Storm
197196 8.8 HIGH
Network
dropwizard
oracle
dropwizard_validation
blockchain_platform
Dropwizard-Validation before 1.3.19, and 2.0.2 may allow arbitrary code execution on the host system, with the privileges of the Dropwizard service account, by injecting arbitrary Java Expression Lan… CWE-74
Injection
CVE-2020-5245 2024-11-21 14:33 2020-02-25 Show GitHub Exploit DB Packet Storm
197197 7.5 HIGH
Network
buddypress buddypress In BuddyPress before 5.1.2, requests to a certain REST API endpoint can result in private user data getting exposed. Authentication is not needed. This has been patched in version 5.1.2. CWE-200
Information Exposure
CVE-2020-5244 2024-11-21 14:33 2020-02-25 Show GitHub Exploit DB Packet Storm
197198 6.5 MEDIUM
Network
dnnsoftware dotnetnuke DNN (formerly DotNetNuke) through 9.4.4 has Insecure Permissions. CWE-669
CWE-434
 Incorrect Resource Transfer Between Spheres
 Unrestricted Upload of File with Dangerous Type 
CVE-2020-5188 2024-11-21 14:33 2020-02-25 Show GitHub Exploit DB Packet Storm
197199 8.8 HIGH
Network
dnnsoftware dotnetnuke DNN (formerly DotNetNuke) through 9.4.4 allows Path Traversal (issue 2 of 2). CWE-22
Path Traversal
CVE-2020-5187 2024-11-21 14:33 2020-02-25 Show GitHub Exploit DB Packet Storm
197200 5.4 MEDIUM
Network
dnnsoftware dotnetnuke DNN (formerly DotNetNuke) through 9.4.4 allows XSS (issue 1 of 2). CWE-79
Cross-site Scripting
CVE-2020-5186 2024-11-21 14:33 2020-02-25 Show GitHub Exploit DB Packet Storm