Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 8, 2026, 2:21 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
230181 5 警告 php heaven - PhpMyChat の localization/languages.lib.php3 におけるディレクトリトラバーサルの脆弱性 - CVE-2006-5898 2012-12-20 18:02 2006-11-15 Show GitHub Exploit DB Packet Storm
230182 5 警告 php heaven - PhpMyChat Plus におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2006-5897 2012-12-20 18:02 2006-11-15 Show GitHub Exploit DB Packet Storm
230183 5 警告 remlab - REMLAB Web Mech Designer におけるスクリプトのフルパスを取得される脆弱性 - CVE-2006-5896 2012-12-20 18:02 2006-11-27 Show GitHub Exploit DB Packet Storm
230184 6.8 警告 rama cms - Rama CMS の lang.php におけるディレクトリトラバーサルの脆弱性 - CVE-2006-5894 2012-12-20 18:02 2006-11-14 Show GitHub Exploit DB Packet Storm
230185 7.5 危険 the net guys - The Net Guys ASPired2Poll の MoreInfo.asp における SQL インジェクションの脆弱性 - CVE-2006-5892 2012-12-20 18:02 2006-11-14 Show GitHub Exploit DB Packet Storm
230186 7.5 危険 superfreaker studios - Superfreaker Studios Ustore の detail.asp における SQL インジェクションの脆弱性 - CVE-2006-5891 2012-12-20 18:02 2006-11-14 Show GitHub Exploit DB Packet Storm
230187 7.5 危険 superfreaker studios - Superfreaker Studios Usupport の detail.asp における SQL インジェクションの脆弱性 - CVE-2006-5890 2012-12-20 18:02 2006-11-14 Show GitHub Exploit DB Packet Storm
230188 7.5 危険 superfreaker studios - Superfreaker Studios UPublisher の viewarticle.asp における SQL インジェクションの脆弱性 - CVE-2006-5888 2012-12-20 18:02 2006-11-14 Show GitHub Exploit DB Packet Storm
230189 5.1 警告 pstotext - pstotext における任意のコマンドを実行される脆弱性 - CVE-2006-5869 2012-12-20 18:02 2006-11-26 Show GitHub Exploit DB Packet Storm
230190 6.4 警告 phpmanta - phpManta の Mdoc/view-sourcecode.php におけるディレクトリトラバーサルの脆弱性 - CVE-2006-5866 2012-12-20 18:02 2006-11-10 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 8, 2026, 4:54 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
199361 7.5 HIGH
Network
arm
debian
mbed_tls
debian_linux
An issue was discovered in Mbed TLS before 2.24.0 (and before 2.16.8 LTS and before 2.7.17 LTS). There is missing zeroization of plaintext buffers in mbedtls_ssl_read to erase unused application data… CWE-212
 Improper Removal of Sensitive Information Before Storage or Transfer
CVE-2020-36476 2024-11-21 14:29 2021-08-23 Show GitHub Exploit DB Packet Storm
199362 7.5 HIGH
Network
arm
siemens
debian
mbed_tls
logo\!_cmr2020_firmware
logo\!_cmr2040_firmware
simatic_rtu3031c_firmware
simatic_rtu3041c_firmware
simatic_rtu3030c_firmware
simatic_rtu3000c_firmware
debian_linux
An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). The calculations performed by mbedtls_mpi_exp_mod are not limited; thus, supplying overly large parame… CWE-131
Incorrect Calculation of Buffer Size
CVE-2020-36475 2024-11-21 14:29 2021-08-23 Show GitHub Exploit DB Packet Storm
199363 7.5 HIGH
Network
arm
siemens
debian
mbed_tls
logo\!_cmr2020_firmware
logo\!_cmr2040_firmware
simatic_rtu3031c_firmware
simatic_rtu3041c_firmware
simatic_rtu3030c_firmware
simatic_rtu3000c_firmware
debian_linux
An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). A NULL algorithm parameters entry looks identical to an array of REAL (size zero) and thus the certifi… CWE-295
Improper Certificate Validation 
CVE-2020-36478 2024-11-21 14:29 2021-08-23 Show GitHub Exploit DB Packet Storm
199364 5.9 MEDIUM
Network
arm mbed_tls An issue was discovered in Mbed TLS before 2.24.0. The verification of X.509 certificates when matching the expected common name (the cn argument of mbedtls_x509_crt_verify) with the actual certifica… CWE-295
Improper Certificate Validation 
CVE-2020-36477 2024-11-21 14:29 2021-08-23 Show GitHub Exploit DB Packet Storm
199365 9.8 CRITICAL
Network
safecurl_project safecurl SafeCurl before 0.9.2 has a DNS rebinding vulnerability. NVD-CWE-Other
CVE-2020-36474 2024-11-21 14:29 2021-08-21 Show GitHub Exploit DB Packet Storm
199366 3.7 LOW
Network
ucweb ucweb_uc UCWeb UC 12.12.3.1219 through 12.12.3.1226 uses cleartext HTTP, and thus man-in-the-middle attackers can discover visited URLs. CWE-312
 Cleartext Storage of Sensitive Information
CVE-2020-36473 2024-11-21 14:29 2021-08-15 Show GitHub Exploit DB Packet Storm
199367 9.8 CRITICAL
Network
amazon amazon_cloudfront Amazon AWS CloudFront TLSv1.2_2019 allows TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 and TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384, which some entities consider to be weak ciphers. CWE-327
 Use of a Broken or Risky Cryptographic Algorithm
CVE-2020-36363 2024-11-21 14:29 2021-08-13 Show GitHub Exploit DB Packet Storm
199368 5.9 MEDIUM
Network
max7301_project max7301 An issue was discovered in the max7301 crate before 0.2.0 for Rust. The ImmediateIO and TransactionalIO types implement Sync for all Expander<EI> types that they contain. NVD-CWE-noinfo
CVE-2020-36472 2024-11-21 14:29 2021-08-8 Show GitHub Exploit DB Packet Storm
199369 5.9 MEDIUM
Network
generator_project generator An issue was discovered in the generator crate before 0.7.0 for Rust. It does not ensure that a function (for yielding values) has Send bounds. NVD-CWE-noinfo
CVE-2020-36471 2024-11-21 14:29 2021-08-8 Show GitHub Exploit DB Packet Storm
199370 5.9 MEDIUM
Network
disrustor_project disrustor An issue was discovered in the disrustor crate through 2020-12-17 for Rust. RingBuffer doe not properly limit the number of mutable references. NVD-CWE-noinfo
CVE-2020-36470 2024-11-21 14:29 2021-08-8 Show GitHub Exploit DB Packet Storm