Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 4, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
229511 5 警告 webasyst llc - Shop-Script の premium/index.php における CRLF インジェクションの脆弱性 - CVE-2006-5566 2012-12-20 18:02 2006-10-27 Show GitHub Exploit DB Packet Storm
229512 5 警告 Yahoo! - Yahoo! Messenger におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2006-5563 2012-12-20 18:02 2006-10-27 Show GitHub Exploit DB Packet Storm
229513 7.5 危険 revilloc solutions - RevilloC MailServer におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2006-5552 2012-12-20 18:02 2006-10-26 Show GitHub Exploit DB Packet Storm
229514 7.5 危険 qksoft - QK SMTP におけるスタックベースのバッファオーバーフローの脆弱性 - CVE-2006-5551 2012-12-20 18:02 2006-10-26 Show GitHub Exploit DB Packet Storm
229515 5 警告 シマンテック - Domino Server 用の Symantec Mail Security におけるスパム送信用の踏み台として製品を使用される脆弱性 - CVE-2006-5545 2012-12-20 18:02 2006-10-19 Show GitHub Exploit DB Packet Storm
229516 7.5 危険 ueberproject management system - UeberProject Management System の login/secure.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-5539 2012-12-20 18:02 2006-10-26 Show GitHub Exploit DB Packet Storm
229517 4.3 警告 zwahlen informatik - Zwahlen Online Shop Freeware の index.htm におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2006-5534 2012-12-20 18:02 2006-10-26 Show GitHub Exploit DB Packet Storm
229518 6.8 警告 XOOPS - RMSOFT Gallery System の rmgs/images.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-5532 2012-12-20 18:02 2006-10-26 Show GitHub Exploit DB Packet Storm
229519 5.1 警告 schoolalumni portal - SchoolAlumni Portal の smumdadotcom_ascyb_alumni/mod.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-5529 2012-12-20 18:02 2006-10-26 Show GitHub Exploit DB Packet Storm
229520 5 警告 schoolalumni portal - SchoolAlumni Portal の mod.php におけるディレクトリトラバーサルの脆弱性 - CVE-2006-5528 2012-12-20 18:02 2006-10-26 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 4, 2026, 4:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
199521 9.8 CRITICAL
Network
qnap surveillance_station A stack-based buffer overflow vulnerability has been reported to affect QNAP NAS devices running Surveillance Station. If exploited, this vulnerability allows attackers to execute arbitrary code. QNA… CWE-787
 Out-of-bounds Write
CVE-2020-2501 2024-11-21 14:25 2021-02-17 Show GitHub Exploit DB Packet Storm
199522 9.8 CRITICAL
Network
qnap helpdesk The vulnerability have been reported to affect earlier versions of QTS. If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. This issue affects: … CWE-78
OS Command 
CVE-2020-2507 2024-11-21 14:25 2021-02-4 Show GitHub Exploit DB Packet Storm
199523 9.8 CRITICAL
Network
qnap helpdesk The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulnerability could allow attackers to compromise the security of the software by ga… NVD-CWE-Other
CVE-2020-2506 2024-11-21 14:25 2021-02-4 Show GitHub Exploit DB Packet Storm
199524 7.2 HIGH
Network
qnap qts
quts_hero
A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP hav… CWE-77
Command Injection
CVE-2020-2508 2024-11-21 14:25 2021-01-12 Show GitHub Exploit DB Packet Storm
199525 2.3 LOW
Local
qnap qes If exploited, this vulnerability could allow attackers to gain sensitive information via generation of error messages. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later. CWE-209
Information Exposure Through an Error Message
CVE-2020-2505 2024-11-21 14:25 2020-12-24 Show GitHub Exploit DB Packet Storm
199526 7.5 HIGH
Network
qnap qes If exploited, this absolute path traversal vulnerability could allow attackers to traverse files in File Station. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later. CWE-22
Path Traversal
CVE-2020-2504 2024-11-21 14:25 2020-12-24 Show GitHub Exploit DB Packet Storm
199527 5.4 MEDIUM
Network
qnap qes If exploited, this stored cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and… CWE-79
Cross-site Scripting
CVE-2020-2503 2024-11-21 14:25 2020-12-24 Show GitHub Exploit DB Packet Storm
199528 7.2 HIGH
Network
qnap qes A hard-coded password vulnerability has been reported to affect earlier versions of QES. If exploited, this vulnerability could allow attackers to log in with a hard-coded password. QNAP has already … CWE-798
 Use of Hard-coded Credentials
CVE-2020-2499 2024-11-21 14:25 2020-12-24 Show GitHub Exploit DB Packet Storm
199529 6.1 MEDIUM
Network
qnap quts_hero
qts
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in certificate configuration. QANP have already fixed these vulnerabilities in the followin… CWE-79
Cross-site Scripting
CVE-2020-2498 2024-11-21 14:25 2020-12-10 Show GitHub Exploit DB Packet Storm
199530 6.1 MEDIUM
Network
qnap music_station This cross-site scripting vulnerability in Music Station allows remote attackers to inject malicious code. QANP have already fixed this vulnerability in the following versions of Music Station. QuTS … CWE-79
Cross-site Scripting
CVE-2020-2494 2024-11-21 14:25 2020-12-10 Show GitHub Exploit DB Packet Storm