Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 10, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
229951 7.5 危険 rediff - Rediff Bol Downloader OCX コントロールにおける重要な情報 (ユーザ名およびパス名) を取得される脆弱性 - CVE-2006-6838 2012-12-20 18:02 2006-12-31 Show GitHub Exploit DB Packet Storm
229952 6.8 警告 sergey oblomov - Total Commander 用の ISO プラグインの LoadTree などの関数におけるスタックベースのバッファオーバーフローの脆弱性 - CVE-2006-6837 2012-12-20 18:02 2006-12-31 Show GitHub Exploit DB Packet Storm
229953 7.5 危険 yrch - Yrch! の plugins/metasearch/plug.inc.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-6823 2012-12-20 18:02 2006-12-29 Show GitHub Exploit DB Packet Storm
229954 7.5 危険 vladimir menshakov - Vladimir Menshakov buratinable templator の process.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-6809 2012-12-20 18:02 2006-12-29 Show GitHub Exploit DB Packet Storm
229955 6.8 警告 WordPress.org - WordPress の wp-admin/templates.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-6808 2012-12-20 18:02 2006-12-28 Show GitHub Exploit DB Packet Storm
229956 7.5 危険 softwebsnepal - Softwebs Nepal Ananda Real Estate の list.asp における SQL インジェクションの脆弱性 - CVE-2006-6807 2012-12-20 18:02 2006-12-28 Show GitHub Exploit DB Packet Storm
229957 6.8 警告 sh-news - SH-News の misc.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-6801 2012-12-20 18:02 2006-12-28 Show GitHub Exploit DB Packet Storm
229958 7.5 危険 The Cacti Group - Cacti における SQL インジェクションの脆弱性 - CVE-2006-6799 2012-12-20 18:02 2006-12-28 Show GitHub Exploit DB Packet Storm
229959 7.5 危険 PHP Outburst - UPB の chat/login.php における任意の PHP コードを挿入される脆弱性 - CVE-2006-6790 2012-12-20 18:02 2006-12-27 Show GitHub Exploit DB Packet Storm
229960 7.5 危険 phpbbxtra - Phpbbxtra の includes/archive/archive_topic.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-6789 2012-12-20 18:02 2006-12-27 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 10, 2026, 4:58 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
210651 8.8 HIGH
Network
titanhq spamtitan An issue was discovered in Titan SpamTitan 7.07. Due to improper sanitization of the parameter quid, used in the page mailqueue.php, code injection can occur. The input for this parameter is provided… CWE-94
Code Injection
CVE-2020-11804 2024-11-21 13:58 2020-09-18 Show GitHub Exploit DB Packet Storm
210652 8.8 HIGH
Network
titanhq spamtitan An issue was discovered in Titan SpamTitan 7.07. Improper sanitization of the parameter jaction when interacting with the page mailqueue.php could lead to PHP code evaluation server-side, because the… CWE-94
Code Injection
CVE-2020-11803 2024-11-21 13:58 2020-09-18 Show GitHub Exploit DB Packet Storm
210653 6.5 MEDIUM
Network
titanhq spamtitan An issue was discovered in Titan SpamTitan 7.07. Improper sanitization of the parameter fname, used on the page certs-x.php, would allow an attacker to retrieve the contents of arbitrary files. The u… CWE-22
Path Traversal
CVE-2020-11700 2024-11-21 13:58 2020-09-18 Show GitHub Exploit DB Packet Storm
210654 8.8 HIGH
Network
titanhq spamtitan An issue was discovered in Titan SpamTitan 7.07. Improper validation of the parameter fname on the page certs-x.php would allow an attacker to execute remote code on the target server. The user has t… CWE-78
OS Command 
CVE-2020-11699 2024-11-21 13:58 2020-09-18 Show GitHub Exploit DB Packet Storm
210655 9.8 CRITICAL
Network
titanhq spamtitan An issue was discovered in Titan SpamTitan 7.07. Improper input sanitization of the parameter community on the page snmp-x.php would allow a remote attacker to inject commands into the file snmpd.con… CWE-77
Command Injection
CVE-2020-11698 2024-11-21 13:58 2020-09-18 Show GitHub Exploit DB Packet Storm
210656 7.5 HIGH
Network
mikrotik routeros An array index error in MikroTik RouterOS 6.41.3 through 6.46.5, and 7.x through 7.0 Beta5, allows an unauthenticated remote attacker to crash the SMB server via modified setup-request packets, aka S… CWE-129
 Improper Validation of Array Index
CVE-2020-11881 2024-11-21 13:58 2020-09-15 Show GitHub Exploit DB Packet Storm
210657 9.1 CRITICAL
Network
linux4sam at91bootstrap AT91bootstrap before 3.9.2 does not properly wipe encryption and authentication keys from memory before passing control to a less privileged software component. This can be exploited to disclose thes… CWE-212
 Improper Removal of Sensitive Information Before Storage or Transfer
CVE-2020-11684 2024-11-21 13:58 2020-09-14 Show GitHub Exploit DB Packet Storm
210658 6.8 MEDIUM
Physics
linux4sam at91bootstrap A timing side channel was discovered in AT91bootstrap before 3.9.2. It can be exploited by attackers with physical access to forge CMAC values and subsequently boot arbitrary code on an affected syst… CWE-203
 Information Exposure Through Discrepancy
CVE-2020-11683 2024-11-21 13:58 2020-09-14 Show GitHub Exploit DB Packet Storm
210659 8.1 HIGH
Network
foxitsoftware phantompdf
reader
In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can obtain sensitive information about an uninitialized object because of direct transformation from PDF Object to… CWE-345
 Insufficient Verification of Data Authenticity
CVE-2020-11493 2024-11-21 13:58 2020-09-4 Show GitHub Exploit DB Packet Storm
210660 7.5 HIGH
Network
chadhaajay phpkb An issue was discovered in Chadha PHPKB 9.0 Enterprise Edition. installer/test-connection.php (part of the installation process) allows a remote unauthenticated attacker to disclose local files on ho… CWE-306
Missing Authentication for Critical Function
CVE-2020-11579 2024-11-21 13:58 2020-09-4 Show GitHub Exploit DB Packet Storm