Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 16, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
230101 6.5 警告 xythos - XEDM におけるクロスサイトリクエストフォージェリの脆弱性 - CVE-2007-3255 2012-12-20 18:19 2007-06-27 Show GitHub Exploit DB Packet Storm
230102 3.5 注意 xythos - XEDM におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-3254 2012-12-20 18:19 2007-06-27 Show GitHub Exploit DB Packet Storm
230103 7.8 危険 portalapp - PortalApp におけるデータベースをダウンロードされる脆弱性 - CVE-2007-3252 2012-12-20 18:19 2007-06-18 Show GitHub Exploit DB Packet Storm
230104 6.8 警告 VirtueMart - VirtueMart における SQL インジェクションの脆弱性 - CVE-2007-3247 2012-12-20 18:19 2007-06-18 Show GitHub Exploit DB Packet Storm
230105 7.5 危険 web-app.org
web-app.net
- web-app.net WebAPP などの Menu Manager Mod における任意のコマンドを実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2007-3242 2012-12-20 18:19 2007-06-14 Show GitHub Exploit DB Packet Storm
230106 4.3 警告 WordPress.org - WordPress 用の cordobo-green-park テーマの blogroll.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-3241 2012-12-20 18:19 2007-06-14 Show GitHub Exploit DB Packet Storm
230107 4.3 警告 WordPress.org - WordPress 用の Vistered-Little テーマの 404.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-3240 2012-12-20 18:19 2007-06-14 Show GitHub Exploit DB Packet Storm
230108 4.3 警告 WordPress.org - WordPress 用の AndyBlue テーマの searchform.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-3239 2012-12-20 18:19 2007-06-14 Show GitHub Exploit DB Packet Storm
230109 6 警告 WordPress.org - WordPress のデフォルトテーマの functions.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-3238 2012-12-20 18:19 2007-06-14 Show GitHub Exploit DB Packet Storm
230110 6.8 警告 XOOPS - XOOPS 用の TinyContent モジュールにおける PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-3237 2012-12-20 18:19 2007-06-12 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 17, 2026, 4:15 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
197011 9.8 CRITICAL
Network
eyesofnetwork eyesofnetwork An issue was discovered in EyesOfNetwork eonweb 5.1 through 5.3 before 5.3-3. The eonweb web interface is prone to a SQL injection, allowing an unauthenticated attacker to perform various tasks such … CWE-89
SQL Injection
CVE-2020-9465 2024-11-21 14:40 2020-02-29 Show GitHub Exploit DB Packet Storm
197012 8.8 HIGH
Network
centreon centreon Centreon 19.10 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the server_ip field in JSON data in an api/internal.php?object=centreon_configuration_rem… CWE-78
OS Command 
CVE-2020-9463 2024-11-21 14:40 2020-02-29 Show GitHub Exploit DB Packet Storm
197013 6.1 MEDIUM
Network
gwtupload_project gwtupload There is an XSS (cross-site scripting) vulnerability in GwtUpload 1.0.3 in the file upload functionality. Someone can upload a file with a malicious filename, which contains JavaScript code, which wo… CWE-79
Cross-site Scripting
CVE-2020-9447 2024-11-21 14:40 2020-02-29 Show GitHub Exploit DB Packet Storm
197014 7.8 HIGH
Local
openvpn connect OpenVPN Connect 3.1.0.361 on Windows has Insecure Permissions for %PROGRAMDATA%\OpenVPN Connect\drivers\tap\amd64\win10, which allows local users to gain privileges by copying a malicious drvstore.dl… CWE-281
 Improper Preservation of Permissions
CVE-2020-9442 2024-11-21 14:40 2020-02-28 Show GitHub Exploit DB Packet Storm
197015 5.5 MEDIUM
Local
avast antivirus_for_linux
antivirus_pro_plus
antivirus_pro
The Avast AV parsing engine allows virus-detection bypass via a crafted ZIP archive. This affects versions before 12 definitions 200114-0 of Antivirus Pro, Antivirus Pro Plus, and Antivirus for Linux. CWE-436
 Interpretation Conflict
CVE-2020-9399 2024-11-21 14:40 2020-02-28 Show GitHub Exploit DB Packet Storm
197016 9.1 CRITICAL
Network
lua-openssl_project lua-openssl openssl_x509_check_ip_asc in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean for certain non-boolean return values. CWE-295
Improper Certificate Validation 
CVE-2020-9434 2024-11-21 14:40 2020-02-28 Show GitHub Exploit DB Packet Storm
197017 9.1 CRITICAL
Network
lua-openssl_project lua-openssl openssl_x509_check_email in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean for certain non-boolean return values. CWE-295
Improper Certificate Validation 
CVE-2020-9433 2024-11-21 14:40 2020-02-28 Show GitHub Exploit DB Packet Storm
197018 9.1 CRITICAL
Network
lua-openssl_project lua-openssl openssl_x509_check_host in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean for certain non-boolean return values. CWE-295
Improper Certificate Validation 
CVE-2020-9432 2024-11-21 14:40 2020-02-28 Show GitHub Exploit DB Packet Storm
197019 7.5 HIGH
Network
wireshark
opensuse
fedoraproject
debian
wireshark
leap
fedora
debian_linux
In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the LTE RRC dissector could leak memory. This was addressed in epan/dissectors/packet-lte-rrc.c by adjusting certain append operation… CWE-401
 Missing Release of Memory after Effective Lifetime
CVE-2020-9431 2024-11-21 14:40 2020-02-28 Show GitHub Exploit DB Packet Storm
197020 7.5 HIGH
Network
wireshark
fedoraproject
opensuse
debian
wireshark
fedora
leap
debian_linux
In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the WiMax DLMAP dissector could crash. This was addressed in plugins/epan/wimax/msg_dlmap.c by validating a length field. CWE-20
 Improper Input Validation 
CVE-2020-9430 2024-11-21 14:40 2020-02-28 Show GitHub Exploit DB Packet Storm