Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 6, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
230031 7.5 危険 mybulletinboard - MyBB の Archive Model の inc/init.php における任意の変数を上書きされる脆弱性 - CVE-2006-3758 2012-12-20 18:02 2006-06-27 Show GitHub Exploit DB Packet Storm
230032 5 警告 Zen Cart - Zen Cart の index.php における重要な情報を取得される脆弱性 - CVE-2006-3757 2012-12-20 18:02 2006-07-21 Show GitHub Exploit DB Packet Storm
230033 7.5 危険 flushcms - FlushCMS の Include/editor/class.rich.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-3755 2012-12-20 18:02 2006-07-21 Show GitHub Exploit DB Packet Storm
230034 7.5 危険 flushcms - FlushCMS の Include/editor/rich_files/class.rich.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-3754 2012-12-20 18:02 2006-07-21 Show GitHub Exploit DB Packet Storm
230035 6.4 警告 professional home page tools - Professional Home Page Tools Guestbook の管理ログインにおけるパスワードを推測する総当り攻撃を実行される脆弱性 - CVE-2006-3753 2012-12-20 18:02 2006-07-21 Show GitHub Exploit DB Packet Storm
230036 7.5 危険 professional home page tools - Professional Home Page Tools Guestbook の class.php における SQL インジェクションの脆弱性 - CVE-2006-3752 2012-12-20 18:02 2006-07-21 Show GitHub Exploit DB Packet Storm
230037 6.8 警告 htmlarea3 - ImageManager 用の HTMLArea3 Addon Component における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2006-3751 2012-12-20 18:02 2006-07-21 Show GitHub Exploit DB Packet Storm
230038 6.8 警告 hashcash - Joomla! 用の com_hashcash の server.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2006-3750 2012-12-20 18:02 2006-07-21 Show GitHub Exploit DB Packet Storm
230039 6.8 警告 Mambo Foundation - Mambo 用の Sitemap コンポーネントにおける PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2006-3749 2012-12-20 18:02 2006-07-10 Show GitHub Exploit DB Packet Storm
230040 6.8 警告 mamboxchange - Mambo 用の LoudMouth コンポーネントにおける PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2006-3748 2012-12-20 18:02 2006-07-21 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 6, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
198971 6.5 MEDIUM
Network
symonics
fedoraproject
libmysofa
fedora
Incorrect handling of input data in changeAttribute function in the libmysofa library 0.5 - 1.1 will lead to NULL pointer dereference and segmentation fault error in case of restrictive memory protec… CWE-476
 NULL Pointer Dereference
CVE-2020-36149 2024-11-21 14:28 2021-02-9 Show GitHub Exploit DB Packet Storm
198972 6.5 MEDIUM
Network
symonics
fedoraproject
libmysofa
fedora
Incorrect handling of input data in verifyAttribute function in the libmysofa library 0.5 - 1.1 will lead to NULL pointer dereference and segmentation fault error in case of restrictive memory protec… CWE-476
 NULL Pointer Dereference
CVE-2020-36148 2024-11-21 14:28 2021-02-9 Show GitHub Exploit DB Packet Storm
198973 8.8 HIGH
Network
zohocorp manageengine_applications_manager doFilter in com.adventnet.appmanager.filter.UriCollector in Zoho ManageEngine Applications Manager through 14930 allows an authenticated SQL Injection via the resourceid parameter to showresource.do. CWE-89
SQL Injection
CVE-2020-35765 2024-11-21 14:28 2021-02-5 Show GitHub Exploit DB Packet Storm
198974 9.8 CRITICAL
Network
asus rt-ax86u_firmware ASUS RT-AX86U router firmware below version under 9.0.0.4_386 has a buffer overflow in the blocking_request.cgi function of the httpd module that can cause code execution when an attacker constructs … CWE-120
Classic Buffer Overflow
CVE-2020-36109 2024-11-21 14:28 2021-02-1 Show GitHub Exploit DB Packet Storm
198975 5.4 MEDIUM
Network
egavilanmedia phpcrud Stored Cross Site Scripting (XSS) vulnerability in EGavilan Media CRUD Operation with PHP, MySQL, Bootstrap, and Dompdf via First Name or Last Name parameter in the 'Add New Record Feature'. CWE-79
Cross-site Scripting
CVE-2020-36115 2024-11-21 14:28 2021-01-29 Show GitHub Exploit DB Packet Storm
198976 7.2 HIGH
Network
opensolution quick.cms
quick.cart
OpenSolution Quick.CMS < 6.7 and Quick.Cart < 6.7 allow an authenticated user to perform code injection (and consequently Remote Code Execution) via the input fields of the Language tab. CWE-94
Code Injection
CVE-2020-35754 2024-11-21 14:28 2021-01-29 Show GitHub Exploit DB Packet Storm
198977 4.8 MEDIUM
Network
bdtask multi-store Stored XSS vulnerability in BDTASK Multi-Store Inventory Management System 1.0 allows a local admin to inject arbitrary code via the Customer Name Field. CWE-79
Cross-site Scripting
CVE-2020-36012 2024-11-21 14:28 2021-01-27 Show GitHub Exploit DB Packet Storm
198978 4.8 MEDIUM
Network
qdocs smart_hospital A cross-site scripting (XSS) issue in Add Patient Form in QDOCS Smart Hospital Management System 3.1 allows a remote attacker to inject arbitrary code via the Name, Guardian Name, Email, Address, Rem… CWE-79
Cross-site Scripting
CVE-2020-36011 2024-11-21 14:28 2021-01-27 Show GitHub Exploit DB Packet Storm
198979 4.8 MEDIUM
Network
textpattern textpattern Textpattern 4.8.4 is affected by cross-site scripting (XSS) in the Body parameter. CWE-79
Cross-site Scripting
CVE-2020-35854 2024-11-21 14:28 2021-01-27 Show GitHub Exploit DB Packet Storm
198980 4.8 MEDIUM
Network
4homepages 4images 4images Image Gallery Management System 1.7.11 is affected by cross-site scripting (XSS) in the Image URL. This vulnerability can result in an attacker to inject the XSS payload into the IMAGE URL. E… CWE-79
Cross-site Scripting
CVE-2020-35853 2024-11-21 14:28 2021-01-27 Show GitHub Exploit DB Packet Storm