Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":April 30, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
229361 7.5 危険 videodb - VideoDB の core/pdf.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-5155 2012-12-20 18:02 2006-10-5 Show GitHub Exploit DB Packet Storm
229362 7.5 危険 vamp webmail - VAMP Webmail の wamp_dir/setup/yesno.phtml における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-5147 2012-12-20 18:02 2006-10-5 Show GitHub Exploit DB Packet Storm
229363 6.8 警告 y-blog - Yblog におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-5146 2012-12-20 18:02 2006-10-5 Show GitHub Exploit DB Packet Storm
229364 5 警告 UBB Systems - Groupee UBB.threads における重要な情報を取得される脆弱性 - CVE-2006-5138 2012-12-20 18:02 2006-10-3 Show GitHub Exploit DB Packet Storm
229365 5.1 警告 UBB Systems - Groupee UBB.threads における PHP コードを挿入される脆弱性 - CVE-2006-5137 2012-12-20 18:02 2006-10-3 Show GitHub Exploit DB Packet Storm
229366 7.5 危険 UBB Systems - Groupee UBB.threads の ubbt.inc.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-5136 2012-12-20 18:02 2006-10-3 Show GitHub Exploit DB Packet Storm
229367 7.5 危険 steve poulsen - GuildFTPd におけるバッファオーバーフローの脆弱性 - CVE-2006-5133 2012-12-20 18:02 2006-05-26 Show GitHub Exploit DB Packet Storm
229368 7.5 危険 phpmyagenda - phpMyAgenda における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-5132 2012-12-20 18:02 2006-10-3 Show GitHub Exploit DB Packet Storm
229369 7.5 危険 salims softhouse - ph03y3nk JAF CMS の module/shout/jafshout.php における "" で囲まれたセクション内の任意のコードを実行される脆弱性 - CVE-2006-5131 2012-12-20 18:02 2006-10-3 Show GitHub Exploit DB Packet Storm
229370 6.8 警告 salims softhouse - ph03y3nk JAF CMS におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-5130 2012-12-20 18:02 2006-10-3 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 30, 2026, 4:58 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
198921 9.8 CRITICAL
Network
qnap surveillance_station A stack-based buffer overflow vulnerability has been reported to affect QNAP NAS devices running Surveillance Station. If exploited, this vulnerability allows attackers to execute arbitrary code. QNA… CWE-787
 Out-of-bounds Write
CVE-2020-2501 2024-11-21 14:25 2021-02-17 Show GitHub Exploit DB Packet Storm
198922 9.8 CRITICAL
Network
qnap helpdesk The vulnerability have been reported to affect earlier versions of QTS. If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. This issue affects: … CWE-78
OS Command 
CVE-2020-2507 2024-11-21 14:25 2021-02-4 Show GitHub Exploit DB Packet Storm
198923 9.8 CRITICAL
Network
qnap helpdesk The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulnerability could allow attackers to compromise the security of the software by ga… NVD-CWE-Other
CVE-2020-2506 2024-11-21 14:25 2021-02-4 Show GitHub Exploit DB Packet Storm
198924 7.2 HIGH
Network
qnap qts
quts_hero
A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP hav… CWE-77
Command Injection
CVE-2020-2508 2024-11-21 14:25 2021-01-12 Show GitHub Exploit DB Packet Storm
198925 2.3 LOW
Local
qnap qes If exploited, this vulnerability could allow attackers to gain sensitive information via generation of error messages. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later. CWE-209
Information Exposure Through an Error Message
CVE-2020-2505 2024-11-21 14:25 2020-12-24 Show GitHub Exploit DB Packet Storm
198926 7.5 HIGH
Network
qnap qes If exploited, this absolute path traversal vulnerability could allow attackers to traverse files in File Station. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later. CWE-22
Path Traversal
CVE-2020-2504 2024-11-21 14:25 2020-12-24 Show GitHub Exploit DB Packet Storm
198927 5.4 MEDIUM
Network
qnap qes If exploited, this stored cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and… CWE-79
Cross-site Scripting
CVE-2020-2503 2024-11-21 14:25 2020-12-24 Show GitHub Exploit DB Packet Storm
198928 7.2 HIGH
Network
qnap qes A hard-coded password vulnerability has been reported to affect earlier versions of QES. If exploited, this vulnerability could allow attackers to log in with a hard-coded password. QNAP has already … CWE-798
 Use of Hard-coded Credentials
CVE-2020-2499 2024-11-21 14:25 2020-12-24 Show GitHub Exploit DB Packet Storm
198929 6.1 MEDIUM
Network
qnap quts_hero
qts
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in certificate configuration. QANP have already fixed these vulnerabilities in the followin… CWE-79
Cross-site Scripting
CVE-2020-2498 2024-11-21 14:25 2020-12-10 Show GitHub Exploit DB Packet Storm
198930 6.1 MEDIUM
Network
qnap music_station This cross-site scripting vulnerability in Music Station allows remote attackers to inject malicious code. QANP have already fixed this vulnerability in the following versions of Music Station. QuTS … CWE-79
Cross-site Scripting
CVE-2020-2494 2024-11-21 14:25 2020-12-10 Show GitHub Exploit DB Packet Storm