Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 4, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
229411 7.5 危険 website designs for less - Website Designs for Less Inventory Manager の inventory/display/imager.asp における SQL インジェクションの脆弱性 - CVE-2006-5943 2012-12-20 18:02 2006-11-16 Show GitHub Exploit DB Packet Storm
229412 6.8 警告 website designs for less - Website Designs For Less Inventory Manager の inventory/display/display_results.asp におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-5942 2012-12-20 18:02 2006-11-16 Show GitHub Exploit DB Packet Storm
229413 7.5 危険 sitexpress - SiteXpress E-Commerce System の dept.asp における SQL インジェクションの脆弱性 - CVE-2006-5936 2012-12-20 18:02 2006-11-15 Show GitHub Exploit DB Packet Storm
229414 7.5 危険 shopsystems - ShopSystems の index.php における SQL インジェクションの脆弱性 - CVE-2006-5935 2012-12-20 18:02 2006-11-15 Show GitHub Exploit DB Packet Storm
229415 7.5 危険 ultrasite - UltraSite の update.asp における SQL インジェクションの脆弱性 - CVE-2006-5933 2012-12-20 18:02 2006-11-15 Show GitHub Exploit DB Packet Storm
229416 7.5 危険 phpjobscheduler - Phpjobscheduler の firepjs.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-5929 2012-12-20 18:02 2006-11-15 Show GitHub Exploit DB Packet Storm
229417 7.5 危険 phpjobscheduler - Phpjobscheduler における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-5928 2012-12-20 18:02 2006-11-15 Show GitHub Exploit DB Packet Storm
229418 7.5 危険 vallheru - Vallheru の mail.php における SQL インジェクションの脆弱性 - CVE-2006-5926 2012-12-20 18:02 2006-11-15 Show GitHub Exploit DB Packet Storm
229419 5 警告 wheatblog - wB の index.php における重要な情報を取得される脆弱性 - CVE-2006-5922 2012-12-20 18:02 2006-11-15 Show GitHub Exploit DB Packet Storm
229420 5.8 警告 wheatblog - wB の add_comment.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-5921 2012-12-20 18:02 2006-11-15 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 5, 2026, 4:51 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
210791 5.3 MEDIUM
Network
cpanel cpanel cPanel before 84.0.20 allows attackers to bypass intended restrictions on features and demo accounts via WebDisk UAPI calls (SEC-541). CWE-862
 Missing Authorization
CVE-2020-10116 2024-11-21 13:54 2020-03-18 Show GitHub Exploit DB Packet Storm
210792 7.2 HIGH
Network
cpanel cpanel cPanel before 84.0.20, when PowerDNS is used, allows arbitrary code execution as root via dnsadmin. (SEC-537). NVD-CWE-noinfo
CVE-2020-10115 2024-11-21 13:54 2020-03-18 Show GitHub Exploit DB Packet Storm
210793 6.1 MEDIUM
Network
cpanel cpanel cPanel before 84.0.20 allows stored self-XSS via the HTML file editor (SEC-535). CWE-79
Cross-site Scripting
CVE-2020-10114 2024-11-21 13:54 2020-03-18 Show GitHub Exploit DB Packet Storm
210794 6.1 MEDIUM
Network
cpanel cpanel cPanel before 84.0.20 allows self XSS via a temporary character-set specification (SEC-515). CWE-79
Cross-site Scripting
CVE-2020-10113 2024-11-21 13:54 2020-03-18 Show GitHub Exploit DB Packet Storm
210795 9.8 CRITICAL
Network
gitlab gitlab GitLab EE 3.0 through 12.8.1 allows SSRF. An internal investigation revealed that a particular deprecated service was creating a server side request forgery risk. CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2020-10077 2024-11-21 13:54 2020-03-14 Show GitHub Exploit DB Packet Storm
210796 6.1 MEDIUM
Network
gitlab gitlab GitLab 12.1 through 12.8.1 allows XSS. A stored cross-site scripting vulnerability was discovered when displaying merge requests. CWE-79
Cross-site Scripting
CVE-2020-10076 2024-11-21 13:54 2020-03-14 Show GitHub Exploit DB Packet Storm
210797 6.1 MEDIUM
Network
gitlab gitlab GitLab 12.5 through 12.8.1 allows HTML Injection. A particular error header was potentially susceptible to injection or potentially other vulnerabilities via unescaped input. CWE-79
Cross-site Scripting
CVE-2020-10075 2024-11-21 13:54 2020-03-14 Show GitHub Exploit DB Packet Storm
210798 9.8 CRITICAL
Network
gitlab gitlab GitLab 10.1 through 12.8.1 has Incorrect Access Control. A scenario was discovered in which a GitLab account could be taken over through an expired link. NVD-CWE-noinfo
CVE-2020-10074 2024-11-21 13:54 2020-03-14 Show GitHub Exploit DB Packet Storm
210799 7.5 HIGH
Network
gitlab gitlab GitLab EE 12.4.2 through 12.8.1 allows Denial of Service. It was internally discovered that a potential denial of service involving permissions checks could impact a project home page. NVD-CWE-noinfo
CVE-2020-10073 2024-11-21 13:54 2020-03-14 Show GitHub Exploit DB Packet Storm
210800 6.5 MEDIUM
Network
sapplica sentrifugo A Blind SQL Injection issue was discovered in Sapplica Sentrifugo 3.2 via the index.php/holidaygroups/add id parameter because of the HolidaydatesController.php addAction function. CWE-89
SQL Injection
CVE-2020-10218 2024-11-21 13:54 2020-03-14 Show GitHub Exploit DB Packet Storm