Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 5, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
229901 5.1 警告 tsep - Olaf Noehring TSEP の copyright.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-3993 2012-12-20 18:02 2006-08-4 Show GitHub Exploit DB Packet Storm
229902 7.5 危険 voc-project - Cisco Unified Wireless IP Phone 7921 における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-3991 2012-12-20 18:02 2006-08-4 Show GitHub Exploit DB Packet Storm
229903 7.5 危険 phpsavant - Paul M. Jones Savant2 における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-3990 2012-12-20 18:02 2006-08-4 Show GitHub Exploit DB Packet Storm
229904 5 警告 scott weedon - Scott Weedon Ajax Chat の visitor/livesupport/chat.php におけるディレクトリトラバーサルの脆弱性 - CVE-2006-3972 2012-12-20 18:02 2006-08-2 Show GitHub Exploit DB Packet Storm
229905 6.8 警告 scott weedon - Scott Weedon Ajax Chat の visitor/livesupport/chat.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-3971 2012-12-20 18:02 2006-08-2 Show GitHub Exploit DB Packet Storm
229906 5 警告 サン・マイクロシステムズ - Sun Solaris 10 3/05 HW2 の暗号化プロバイダにおけるアプリケーションがデータ変更を検出しない脆弱性 - CVE-2006-3968 2012-12-20 18:02 2006-08-1 Show GitHub Exploit DB Packet Storm
229907 7.5 危険 x-scripts - X-Scripts X-Poll の top.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2006-3960 2012-12-20 18:02 2006-08-1 Show GitHub Exploit DB Packet Storm
229908 7.5 危険 x-scripts - X-Scripts X-Protection の protect.php における SQL インジェクションの脆弱性 - CVE-2006-3959 2012-12-20 18:02 2006-08-1 Show GitHub Exploit DB Packet Storm
229909 4.3 警告 pkr internet - Taskjitsu におけるクロスサイトスクリプティングの脆弱性 CWE-noinfo
情報不足
CVE-2006-3958 2012-12-20 18:02 2006-07-6 Show GitHub Exploit DB Packet Storm
229910 4.3 警告 total online solutions - AWBS の contact.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-3956 2012-12-20 18:02 2006-08-1 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 5, 2026, 4:51 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
199251 6.1 MEDIUM
Network
pi-hole pi-hole The DNS query log in Pi-hole before 5.2.2 is vulnerable to stored XSS. An attacker with the ability to directly or indirectly query DNS with a malicious hostname can cause arbitrary JavaScript to exe… CWE-79
Cross-site Scripting
CVE-2020-35659 2024-11-21 14:27 2020-12-25 Show GitHub Exploit DB Packet Storm
199252 6.1 MEDIUM
Network
dart http An issue was discovered in the http package through 0.12.2 for Dart. If the attacker controls the HTTP method and the app is using Request directly, it's possible to achieve CRLF injection in an HTTP… CWE-74
Injection
CVE-2020-35669 2024-11-21 14:27 2020-12-24 Show GitHub Exploit DB Packet Storm
199253 4.8 MEDIUM
Network
bigprof online_invoicing_system BigProf Online Invoicing System before 4.0 fails to adequately sanitize fields for HTML characters upon an administrator using admin/pageEditGroup.php to create a new group, resulting in Stored XSS. … CWE-352
CWE-79
 Origin Validation Error
Cross-site Scripting
CVE-2020-35677 2024-11-21 14:27 2020-12-24 Show GitHub Exploit DB Packet Storm
199254 6.1 MEDIUM
Network
bigprof online_invoicing_system BigProf Online Invoicing System before 3.1 fails to correctly sanitize an XSS payload when a user registers using the self-registration functionality. As such, an attacker can input a crafted payload… CWE-79
Cross-site Scripting
CVE-2020-35676 2024-11-21 14:27 2020-12-24 Show GitHub Exploit DB Packet Storm
199255 7.5 HIGH
Network
redislabs redisgraph RedisGraph 2.x through 2.2.11 has a NULL Pointer Dereference that leads to a server crash because it mishandles an unquoted string, such as an alias that has not yet been introduced. CWE-476
 NULL Pointer Dereference
CVE-2020-35668 2024-11-21 14:27 2020-12-24 Show GitHub Exploit DB Packet Storm
199256 8.8 HIGH
Network
steedos steedos Steedos Platform through 1.21.24 allows NoSQL injection because the /api/collection/findone implementation in server/packages/steedos_base.js mishandles req.body validation, as demonstrated by MongoD… CWE-89
SQL Injection
CVE-2020-35666 2024-11-21 14:27 2020-12-24 Show GitHub Exploit DB Packet Storm
199257 9.8 CRITICAL
Network
terra-master terramaster_operating_system An unauthenticated command-execution vulnerability exists in TerraMaster TOS through 4.2.06 via shell metacharacters in the Event parameter in include/makecvs.php during CSV creation. CWE-78
OS Command 
CVE-2020-35665 2024-11-21 14:27 2020-12-24 Show GitHub Exploit DB Packet Storm
199258 7.5 HIGH
Network
advanced_comment_system_project advanced_comment_system ACS Advanced Comment System 1.0 is affected by Directory Traversal via an advanced_component_system/index.php?ACS_path=..%2f URI. NOTE: this might be the same as CVE-2009-4623 CWE-22
Path Traversal
CVE-2020-35598 2024-11-21 14:27 2020-12-24 Show GitHub Exploit DB Packet Storm
199259 8.8 HIGH
Network
raysync raysync A RCE vulnerability exists in Raysync below 3.3.3.8. An unauthenticated unauthorized attacker sending a specifically crafted request to override the specific file in server with malicious content can… CWE-22
Path Traversal
CVE-2020-35370 2024-11-21 14:27 2020-12-24 Show GitHub Exploit DB Packet Storm
199260 8.8 HIGH
Network
nagios nagios_core Nagios Core application version 4.2.4 is vulnerable to Site-Wide Cross-Site Request Forgery (CSRF) in many functions, like adding – deleting for hosts or servers. CWE-352
 Origin Validation Error
CVE-2020-35269 2024-11-21 14:27 2020-12-24 Show GitHub Exploit DB Packet Storm