Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 3, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
229701 7.5 危険 reamday enterprises - Reamday Enterprises Magic News Pro の scripts/news_page.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-4823 2012-12-20 18:02 2006-09-15 Show GitHub Exploit DB Packet Storm
229702 4.6 警告 シマンテック - Symantec AntiVirus Corporate Edition などの Real Time Virus Scan サービスにおけるフォーマットストリングの脆弱性 - CVE-2006-4802 2012-12-20 18:02 2006-09-13 Show GitHub Exploit DB Packet Storm
229703 6.2 警告 ROXIO - Roxio Toast Titanium で使用されている Deja Vu における任意のコードを実行される脆弱性 CWE-362
競合状態
CVE-2006-4801 2012-12-20 18:02 2006-09-14 Show GitHub Exploit DB Packet Storm
229704 7.5 危険 Xine - xine-lib 用の ffmpeg におけるバッファオーバーフローの脆弱性 - CVE-2006-4799 2012-12-20 18:02 2006-09-13 Show GitHub Exploit DB Packet Storm
229705 4.3 警告 Snitz - Snitz Forums 2000 の forum.asp におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-4796 2012-12-20 18:02 2006-09-14 Show GitHub Exploit DB Packet Storm
229706 7.5 危険 tualblog - TualBLOG の icerik.asp における SQL インジェクションの脆弱性 - CVE-2006-4793 2012-12-20 18:02 2006-09-14 Show GitHub Exploit DB Packet Storm
229707 5.1 警告 telekorn - Telekorn SL の includes/log.inc.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-4788 2012-12-20 18:02 2006-09-14 Show GitHub Exploit DB Packet Storm
229708 5.1 警告 webSPELL - WebSPELL の squads.php における SQL インジェクションの脆弱性 - CVE-2006-4783 2012-12-20 18:02 2006-09-14 Show GitHub Exploit DB Packet Storm
229709 5.4 警告 webSPELL - WebSPELL の src/index.php における認証を回避される脆弱性 - CVE-2006-4782 2012-12-20 18:02 2006-09-14 Show GitHub Exploit DB Packet Storm
229710 7.5 危険 phpbb xs - phpBB XS の includes/functions.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-4780 2012-12-20 18:02 2006-09-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 3, 2026, 4:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
199051 7.5 HIGH
Network
opensmtpd
fedoraproject
opensmtpd
fedora
smtpd/lka_filter.c in OpenSMTPD before 6.8.0p1, in certain configurations, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted pattern of cl… CWE-476
 NULL Pointer Dereference
CVE-2020-35680 2024-11-21 14:27 2020-12-25 Show GitHub Exploit DB Packet Storm
199052 7.5 HIGH
Network
opensmtpd
fedoraproject
opensmtpd
fedora
smtpd/table.c in OpenSMTPD before 6.8.0p1 lacks a certain regfree, which might allow attackers to trigger a "very significant" memory leak via messages to an instance that performs many regex lookups. CWE-401
 Missing Release of Memory after Effective Lifetime
CVE-2020-35679 2024-11-21 14:27 2020-12-25 Show GitHub Exploit DB Packet Storm
199053 6.1 MEDIUM
Network
pi-hole pi-hole The DNS query log in Pi-hole before 5.2.2 is vulnerable to stored XSS. An attacker with the ability to directly or indirectly query DNS with a malicious hostname can cause arbitrary JavaScript to exe… CWE-79
Cross-site Scripting
CVE-2020-35659 2024-11-21 14:27 2020-12-25 Show GitHub Exploit DB Packet Storm
199054 6.1 MEDIUM
Network
dart http An issue was discovered in the http package through 0.12.2 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF injection in an HTTP… CWE-74
Injection
CVE-2020-35669 2024-11-21 14:27 2020-12-24 Show GitHub Exploit DB Packet Storm
199055 4.8 MEDIUM
Network
bigprof online_invoicing_system BigProf Online Invoicing System before 4.0 fails to adequately sanitize fields for HTML characters upon an administrator using admin/pageEditGroup.php to create a new group, resulting in Stored XSS. … CWE-352
CWE-79
 Origin Validation Error
Cross-site Scripting
CVE-2020-35677 2024-11-21 14:27 2020-12-24 Show GitHub Exploit DB Packet Storm
199056 6.1 MEDIUM
Network
bigprof online_invoicing_system BigProf Online Invoicing System before 3.1 fails to correctly sanitize an XSS payload when a user registers using the self-registration functionality. As such, an attacker can input a crafted payload… CWE-79
Cross-site Scripting
CVE-2020-35676 2024-11-21 14:27 2020-12-24 Show GitHub Exploit DB Packet Storm
199057 7.5 HIGH
Network
redislabs redisgraph RedisGraph 2.x through 2.2.11 has a NULL Pointer Dereference that leads to a server crash because it mishandles an unquoted string, such as an alias that has not yet been introduced. CWE-476
 NULL Pointer Dereference
CVE-2020-35668 2024-11-21 14:27 2020-12-24 Show GitHub Exploit DB Packet Storm
199058 8.8 HIGH
Network
steedos steedos Steedos Platform through 1.21.24 allows NoSQL injection because the /api/collection/findone implementation in server/packages/steedos_base.js mishandles req.body validation, as demonstrated by MongoD… CWE-89
SQL Injection
CVE-2020-35666 2024-11-21 14:27 2020-12-24 Show GitHub Exploit DB Packet Storm
199059 9.8 CRITICAL
Network
terra-master terramaster_operating_system An unauthenticated command-execution vulnerability exists in TerraMaster TOS through 4.2.06 via shell metacharacters in the Event parameter in include/makecvs.php during CSV creation. CWE-78
OS Command 
CVE-2020-35665 2024-11-21 14:27 2020-12-24 Show GitHub Exploit DB Packet Storm
199060 7.5 HIGH
Network
advanced_comment_system_project advanced_comment_system ACS Advanced Comment System 1.0 is affected by Directory Traversal via an advanced_component_system/index.php?ACS_path=..%2f URI. NOTE: this might be the same as CVE-2009-4623 CWE-22
Path Traversal
CVE-2020-35598 2024-11-21 14:27 2020-12-24 Show GitHub Exploit DB Packet Storm