Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 18, 2026, 12:09 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
230121 7.6 危険 Yahoo! - Yahoo! Messenger におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2007-3928 2012-12-20 18:33 2007-07-20 Show GitHub Exploit DB Packet Storm
230122 7.8 危険 wesnoth - Wesnoth のマルチプレーヤーエンジンにおけるサービス運用妨害 (DoS) の脆弱性 CWE-134
書式文字列の問題
CVE-2007-3917 2012-12-20 18:33 2007-10-11 Show GitHub Exploit DB Packet Storm
230123 4.4 警告 skk openlab - SKK Tools の skkdic-expr.c における任意のファイルを上書きされる脆弱性 CWE-59
リンク解釈の問題
CVE-2007-3916 2012-12-20 18:33 2007-09-23 Show GitHub Exploit DB Packet Storm
230124 7.5 危険 Zoph - Zoph における SQL インジェクションの脆弱性 - CVE-2007-3905 2012-12-20 18:33 2007-07-19 Show GitHub Exploit DB Packet Storm
230125 7.5 危険 popscript.com - Expert Advisor の index.php における SQL インジェクションの脆弱性 - CVE-2007-3882 2012-12-20 18:33 2007-07-18 Show GitHub Exploit DB Packet Storm
230126 7.5 危険 pictures rating - Picture Rating の index.php における SQL インジェクションの脆弱性 - CVE-2007-3881 2012-12-20 18:33 2007-07-18 Show GitHub Exploit DB Packet Storm
230127 7.2 危険 サン・マイクロシステムズ - SUNWsrspx パッケージで同梱されている SRS Net Connect の srsexec におけるフォーマットストリングの脆弱性 CWE-134
書式文字列の問題
CVE-2007-3880 2012-12-20 18:33 2007-11-2 Show GitHub Exploit DB Packet Storm
230128 6.9 警告 トレンドマイクロ - Trend Micro AntiSpyware および PC-Cillin Internet Security 2007 の SSAPI Engine におけるスタックベースのバッファオーバーフローの脆弱性 - CVE-2007-3873 2012-12-20 18:33 2007-08-22 Show GitHub Exploit DB Packet Storm
230129 6 警告 TortoiseSVN
CollabNet, Inc.
- TortoiseSVN で使用されている Subversion におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2007-3846 2012-12-20 18:33 2007-08-27 Show GitHub Exploit DB Packet Storm
230130 9 危険 Pidgin - Linux 用の Pidgin における特定のコマンドを実行される脆弱性 - CVE-2007-3841 2012-12-20 18:33 2007-07-17 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 18, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
200391 9.8 CRITICAL
Network
nick_chan_bot_project nick_chan_bot In Nick Chan Bot before version 1.0.0-beta there is a vulnerability in the `npm` command which is part of this software package. This allows arbitrary shell execution,which can compromise the bot Thi… CWE-78
OS Command 
CVE-2020-5282 2024-11-21 14:33 2020-03-26 Show GitHub Exploit DB Packet Storm
200392 5.4 MEDIUM
Network
prestashop faceted_search_module PrestaShop module ps_facetedsearch versions before 3.5.0 has a reflected XSS with `url_name` parameter. The problem is fixed in 3.5.0 CWE-79
Cross-site Scripting
CVE-2020-5277 2024-11-21 14:33 2020-03-26 Show GitHub Exploit DB Packet Storm
200393 7.5 HIGH
Network
cesnet perun In Perun before version 3.9.1, VO or group manager can modify configuration of the LDAP extSource to retrieve all from Perun LDAP. Issue is fixed in version 3.9.1 by sanitisation of the input. CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2020-5281 2024-11-21 14:33 2020-03-26 Show GitHub Exploit DB Packet Storm
200394 7.5 HIGH
Network
typelevel http4s http4s before versions 0.18.26, 0.20.20, and 0.21.2 has a local file inclusion vulnerability. This vulnerability applies to all users of org.http4s.server.staticcontent.FileService, org.http4s.server… CWE-22
Path Traversal
CVE-2020-5280 2024-11-21 14:33 2020-03-26 Show GitHub Exploit DB Packet Storm
200395 6.8 MEDIUM
Network
sustainsys saml2 Saml2 Authentication services for ASP.NET (NuGet package Sustainsys.Saml2) greater than 2.0.0, and less than version 2.5.0 has a faulty implementation of Token Replay Detection. Token Replay Detectio… CWE-294
Authentication Bypass by Capture-replay 
CVE-2020-5261 2024-11-21 14:33 2020-03-25 Show GitHub Exploit DB Packet Storm
200396 4.1 MEDIUM
Local
pyup safety The command-line "safety" package for Python has a potential security issue. There are two Python characteristics that allow malicious code to “poison-pill” command-line Safety package detection rout… NVD-CWE-noinfo
CVE-2020-5252 2024-11-21 14:33 2020-03-24 Show GitHub Exploit DB Packet Storm
200397 4.8 MEDIUM
Network
rubyonrails
debian
fedoraproject
opensuse
actionview
debian_linux
fedora
leap
In ActionView before versions 6.0.2.2 and 5.2.4.2, there is a possible XSS vulnerability in ActionView's JavaScript literal escape helpers. Views that use the `j` or `escape_javascript` methods may b… - CVE-2020-5267 2024-11-21 14:33 2020-03-20 Show GitHub Exploit DB Packet Storm
200398 5.5 MEDIUM
Local
easybuild_project easybuild In EasyBuild before version 4.1.2, the GitHub Personal Access Token (PAT) used by EasyBuild for the GitHub integration features (like `--new-pr`, `--fro,-pr`, etc.) is shown in plain text in EasyBuil… CWE-922
 Insecure Storage of Sensitive Information
CVE-2020-5262 2024-11-21 14:33 2020-03-20 Show GitHub Exploit DB Packet Storm
200399 8.5 HIGH
Network
labdigital wagtail-2fa In wagtail-2fa before 1.4.1, any user with access to the CMS can view and delete other users 2FA devices by going to the correct path. The user does not require special permissions in order to do so.… CWE-863
 Incorrect Authorization
CVE-2020-5240 2024-11-21 14:33 2020-03-14 Show GitHub Exploit DB Packet Storm
200400 8.1 HIGH
Network
thoughtbot administrate In Administrate (rubygem) before version 0.13.0, when sorting by attributes on a dashboard, the direction parameter was not validated before being interpolated into the SQL query. This could present … CWE-89
SQL Injection
CVE-2020-5257 2024-11-21 14:33 2020-03-14 Show GitHub Exploit DB Packet Storm