Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 12, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
229381 4.3 警告 softlink europe - Oliver Library Management System におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-3569 2012-12-20 18:19 2007-07-5 Show GitHub Exploit DB Packet Storm
229382 4.3 警告 webixir - Efendy Blog の ara.asp におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-3561 2012-12-20 18:19 2007-07-4 Show GitHub Exploit DB Packet Storm
229383 3.5 注意 PHP-Fusion - PHP-Fusion の infusions/shoutbox_panel/shoutbox_panel.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-3559 2012-12-20 18:19 2007-07-4 Show GitHub Exploit DB Packet Storm
229384 6.8 警告 wheatblog - wB の admin/login.php における SQL インジェクションの脆弱性 - CVE-2007-3557 2012-12-20 18:19 2007-07-4 Show GitHub Exploit DB Packet Storm
229385 7.5 危険 Vastal I-Tech & Co. - Buddy Zone の view_sub_cat.php における SQL インジェクションの脆弱性 - CVE-2007-3549 2012-12-20 18:19 2007-07-3 Show GitHub Exploit DB Packet Storm
229386 7.1 危険 w3filer - W3Filer におけるスタックベースのバッファオーバーフローの脆弱性 - CVE-2007-3548 2012-12-20 18:19 2007-07-3 Show GitHub Exploit DB Packet Storm
229387 7.8 危険 qt-cute - QuickTicket の qti_checkname.php におけるディレクトリトラバーサルの脆弱性 - CVE-2007-3547 2012-12-20 18:19 2007-07-3 Show GitHub Exploit DB Packet Storm
229388 7.1 危険 warzone - Warzone 2100 Resurrection におけるバッファオーバーフローの脆弱性 - CVE-2007-3545 2012-12-20 18:19 2007-06-22 Show GitHub Exploit DB Packet Storm
229389 6.5 警告 WordPress.org - WordPress および WordPress MU の wp-app.php などにおける任意の PHP コードを実行される脆弱性 - CVE-2007-3544 2012-12-20 18:19 2007-07-3 Show GitHub Exploit DB Packet Storm
229390 6 警告 WordPress.org - WordPress および WordPress MU における任意の PHP コードを実行される脆弱性 - CVE-2007-3543 2012-12-20 18:19 2007-07-3 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 12, 2026, 5:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
196761 6.1 MEDIUM
Network
siemens climatix_pol908_firmware
climatix_pol909_firmware
A vulnerability has been identified in Climatix POL908 (BACnet/IP module) (All versions), Climatix POL909 (AWM module) (All versions < V11.32). A persistent cross-site scripting (XSS) vulnerability e… CWE-79
Cross-site Scripting
CVE-2020-7574 2024-11-21 14:37 2020-04-15 Show GitHub Exploit DB Packet Storm
196762 5.3 MEDIUM
Network
sds_project sds sds through 3.2.0 is vulnerable to Prototype Pollution.The library could be tricked into adding or modifying properties of the 'Object.prototype' by abusing the 'set' function located in 'js/set.js'. CWE-1321
 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVE-2020-7618 2024-11-21 14:37 2020-04-7 Show GitHub Exploit DB Packet Storm
196763 5.3 MEDIUM
Network
express-mock-middleware_project express-mock-middleware express-mock-middleware through 0.0.6 is vulnerable to Prototype Pollution. Exported functions by the package can be tricked into adding or modifying properties of the `Object.prototype`. Exploitatio… CWE-1321
 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVE-2020-7616 2024-11-21 14:37 2020-04-7 Show GitHub Exploit DB Packet Storm
196764 7.8 HIGH
Local
fsa_project fsa fsa through 0.5.1 is vulnerable to Command Injection. The first argument of 'execGitCommand()', located within 'lib/rep.js#63' can be controlled by users without any sanitization to inject arbitrary … CWE-78
OS Command 
CVE-2020-7615 2024-11-21 14:37 2020-04-7 Show GitHub Exploit DB Packet Storm
196765 9.8 CRITICAL
Network
npm-programmatic_project npm-programmatic npm-programmatic through 0.0.12 is vulnerable to Command Injection.The packages and option properties are concatenated together without any validation and are used by the 'exec' function directly. CWE-20
CWE-78
 Improper Input Validation 
OS Command 
CVE-2020-7614 2024-11-21 14:37 2020-04-7 Show GitHub Exploit DB Packet Storm
196766 8.1 HIGH
Network
clamscan_project clamscan clamscan through 1.2.0 is vulnerable to Command Injection. It is possible to inject arbitrary commands as part of the `_is_clamav_binary` function located within `Index.js`. It should be noted that t… CWE-78
OS Command 
CVE-2020-7613 2024-11-21 14:37 2020-04-7 Show GitHub Exploit DB Packet Storm
196767 9.8 CRITICAL
Network
jooby jooby This affects the package io.jooby:jooby-netty before 1.6.9, from 2.0.0 and before 2.2.1. The DefaultHttpHeaders is set to false which means it does not validates that the header isn't being abused fo… NVD-CWE-Other
CVE-2020-7622 2024-11-21 14:37 2020-04-7 Show GitHub Exploit DB Packet Storm
196768 5.3 MEDIUM
Network
dot_project dot eivindfjeldstad-dot below 1.0.3 is vulnerable to Prototype Pollution.The function 'set' could be tricked into adding or modifying properties of 'Object.prototype' using a '__proto__' payload. CWE-1321
 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVE-2020-7639 2024-11-21 14:37 2020-04-6 Show GitHub Exploit DB Packet Storm
196769 5.3 MEDIUM
Network
confinit_project confinit confinit through 0.3.0 is vulnerable to Prototype Pollution.The 'setDeepProperty' function could be tricked into adding or modifying properties of 'Object.prototype' using a '__proto__' payload. CWE-1321
 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVE-2020-7638 2024-11-21 14:37 2020-04-6 Show GitHub Exploit DB Packet Storm
196770 5.3 MEDIUM
Network
class-transformer_project class-transformer class-transformer before 0.3.1 allow attackers to perform Prototype Pollution. The classToPlainFromExist function could be tricked into adding or modifying properties of Object.prototype using a __pr… CWE-1321
 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVE-2020-7637 2024-11-21 14:37 2020-04-6 Show GitHub Exploit DB Packet Storm