Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 8, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
229901 7.5 危険 Plume CMS - Plume CMS の manager/tools/link/dbinstall.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2006-7021 2012-12-20 18:18 2007-02-14 Show GitHub Exploit DB Packet Storm
229902 7.5 危険 phpwcms - phpwcms における任意のコードを実行される脆弱性 - CVE-2006-7019 2012-12-20 18:18 2007-02-14 Show GitHub Exploit DB Packet Storm
229903 7.5 危険 phpjobboard - phpjobboard における認証を回避される脆弱性 - CVE-2006-7016 2012-12-20 18:18 2007-02-14 Show GitHub Exploit DB Packet Storm
229904 10 危険 scart - SCart の scart.cgi における任意のコマンドを実行される脆弱性 - CVE-2006-7012 2012-12-20 18:18 2007-02-14 Show GitHub Exploit DB Packet Storm
229905 4.3 警告 wheatblog - wB の add_comment.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-7002 2012-12-20 18:18 2007-02-12 Show GitHub Exploit DB Packet Storm
229906 7.1 危険 phpmychat plus - PhpMyChat Plus の avatar.php におけるディレクトリトラバーサルの脆弱性 - CVE-2006-7001 2012-12-20 18:18 2007-02-12 Show GitHub Exploit DB Packet Storm
229907 4.3 警告 the war forge - warforge.NEWS におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-6996 2012-12-20 18:18 2007-02-12 Show GitHub Exploit DB Packet Storm
229908 6 警告 v3chat - V3 Chat の mycontacts.php における他のユーザとして権限を取得される脆弱性 - CVE-2006-6995 2012-12-20 18:18 2007-02-12 Show GitHub Exploit DB Packet Storm
229909 7.8 危険 softinform - FineBrowser Freeware における他のドメインから制限された情報をアクセスされる脆弱性 - CVE-2006-6987 2012-12-20 18:18 2007-02-8 Show GitHub Exploit DB Packet Storm
229910 7.5 危険 phpgraphy - phpGraphy における任意の PHP コードを実行される脆弱性 - CVE-2006-6966 2012-12-20 18:18 2007-02-3 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 8, 2026, 4:54 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
199721 8.0 HIGH
Network
pickplugins team_showcase
post_grid
Stored Cross-Site Scripting (XSS) vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated attackers to import layouts including JavaScript supplied via a r… CWE-79
Cross-site Scripting
CVE-2020-35937 2024-11-21 14:28 2021-01-1 Show GitHub Exploit DB Packet Storm
199722 8.0 HIGH
Network
pickplugins team_showcase
post_grid
Stored Cross-Site Scripting (XSS) vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to import layouts including JavaScript supplied via a remote… CWE-79
Cross-site Scripting
CVE-2020-35936 2024-11-21 14:28 2021-01-1 Show GitHub Exploit DB Packet Storm
199723 8.8 HIGH
Network
vasyltech advanced_access_manager The Advanced Access Manager plugin before 6.6.2 for WordPress allows privilege escalation on profile updates via the aam_user_roles POST parameter if Multiple Role support is enabled. (The mechanism … NVD-CWE-noinfo
CVE-2020-35935 2024-11-21 14:28 2021-01-1 Show GitHub Exploit DB Packet Storm
199724 4.3 MEDIUM
Network
vasyltech advanced_access_manager The Advanced Access Manager plugin before 6.6.2 for WordPress displays the unfiltered user object (including all metadata) upon login via the REST API (aam/v1/authenticate or aam/v2/authenticate). Th… CWE-200
Information Exposure
CVE-2020-35934 2024-11-21 14:28 2021-01-1 Show GitHub Exploit DB Packet Storm
199725 6.5 MEDIUM
Network
thenewsletterplugin newsletter A Reflected Authenticated Cross-Site Scripting (XSS) vulnerability in the Newsletter plugin before 6.8.2 for WordPress allows remote attackers to trick a victim into submitting a tnpc_render AJAX req… CWE-79
Cross-site Scripting
CVE-2020-35933 2024-11-21 14:28 2021-01-1 Show GitHub Exploit DB Packet Storm
199726 8.8 HIGH
Network
tribulant newsletter Insecure Deserialization in the Newsletter plugin before 6.8.2 for WordPress allows authenticated remote attackers with minimal privileges (such as subscribers) to use the tpnc_render AJAX action to … CWE-502
 Deserialization of Untrusted Data
CVE-2020-35932 2024-11-21 14:28 2021-01-1 Show GitHub Exploit DB Packet Storm
199727 7.8 HIGH
Local
foxitsoftware foxit_reader
phantompdf
An issue was discovered in Foxit Reader before 10.1.1 (and before 4.1.1 on macOS) and PhantomPDF before 9.7.5 and 10.x before 10.1.1 (and before 4.1.1 on macOS). An attacker can spoof a certified PDF… CWE-754
 Improper Check for Unusual or Exceptional Conditions
CVE-2020-35931 2024-11-21 14:28 2021-01-1 Show GitHub Exploit DB Packet Storm
199728 5.4 MEDIUM
Network
seopanel seo_panel Seo Panel 4.8.0 allows stored XSS by an Authenticated User via the url parameter, as demonstrated by the seo/seopanel/websites.php URI. CWE-79
Cross-site Scripting
CVE-2020-35930 2024-11-21 14:28 2021-01-1 Show GitHub Exploit DB Packet Storm
199729 4.7 MEDIUM
Local
atom_project atom An issue was discovered in the atom crate before 0.3.6 for Rust. An unsafe Send implementation allows a cross-thread data race. CWE-362
Race Condition
CVE-2020-35897 2024-11-21 14:28 2020-12-31 Show GitHub Exploit DB Packet Storm
199730 7.5 HIGH
Network
ws-rs_project ws-rs An issue was discovered in the ws crate through 2020-09-25 for Rust. The outgoing buffer is not properly limited, leading to a remote memory-consumption attack. CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2020-35896 2024-11-21 14:28 2020-12-31 Show GitHub Exploit DB Packet Storm