Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 10, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
230371 7.5 危険 videodb - VideoDB の core/pdf.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-5155 2012-12-20 18:02 2006-10-5 Show GitHub Exploit DB Packet Storm
230372 7.5 危険 vamp webmail - VAMP Webmail の wamp_dir/setup/yesno.phtml における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-5147 2012-12-20 18:02 2006-10-5 Show GitHub Exploit DB Packet Storm
230373 6.8 警告 y-blog - Yblog におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-5146 2012-12-20 18:02 2006-10-5 Show GitHub Exploit DB Packet Storm
230374 5 警告 UBB Systems - Groupee UBB.threads における重要な情報を取得される脆弱性 - CVE-2006-5138 2012-12-20 18:02 2006-10-3 Show GitHub Exploit DB Packet Storm
230375 5.1 警告 UBB Systems - Groupee UBB.threads における PHP コードを挿入される脆弱性 - CVE-2006-5137 2012-12-20 18:02 2006-10-3 Show GitHub Exploit DB Packet Storm
230376 7.5 危険 UBB Systems - Groupee UBB.threads の ubbt.inc.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-5136 2012-12-20 18:02 2006-10-3 Show GitHub Exploit DB Packet Storm
230377 7.5 危険 steve poulsen - GuildFTPd におけるバッファオーバーフローの脆弱性 - CVE-2006-5133 2012-12-20 18:02 2006-05-26 Show GitHub Exploit DB Packet Storm
230378 7.5 危険 phpmyagenda - phpMyAgenda における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-5132 2012-12-20 18:02 2006-10-3 Show GitHub Exploit DB Packet Storm
230379 7.5 危険 salims softhouse - ph03y3nk JAF CMS の module/shout/jafshout.php における "" で囲まれたセクション内の任意のコードを実行される脆弱性 - CVE-2006-5131 2012-12-20 18:02 2006-10-3 Show GitHub Exploit DB Packet Storm
230380 6.8 警告 salims softhouse - ph03y3nk JAF CMS におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-5130 2012-12-20 18:02 2006-10-3 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 11, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
198391 7.5 HIGH
Network
ibm curam_social_program_management A path traversal vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10, which could allow a remote attacker to traverse directories on the system. An attacker could send a spe… CWE-22
Path Traversal
CVE-2020-4776 2024-11-21 14:33 2020-10-12 Show GitHub Exploit DB Packet Storm
198392 5.4 MEDIUM
Network
ibm curam_social_program_management A cross-site scripting (XSS) vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10. This vulnerability allows attackers to inject malicious scripts into web applications for t… CWE-79
Cross-site Scripting
CVE-2020-4775 2024-11-21 14:33 2020-10-12 Show GitHub Exploit DB Packet Storm
198393 5.4 MEDIUM
Network
ibm curam_social_program_management An XPath vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10, caused by the improper handling of user-supplied input. By sending a specially-crafted input, a remote attacker… CWE-91
Blind XPath Injection
CVE-2020-4774 2024-11-21 14:33 2020-10-12 Show GitHub Exploit DB Packet Storm
198394 6.5 MEDIUM
Network
ibm curam_social_program_management A cross-site request forgery (CSRF) vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10, which is an attack that forces a user to execute unwanted actions on the web applica… CWE-352
 Origin Validation Error
CVE-2020-4773 2024-11-21 14:33 2020-10-12 Show GitHub Exploit DB Packet Storm
198395 8.1 HIGH
Network
ibm curam_social_program_management An XML External Entity Injection (XXE) vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10. A remote attacker could exploit this vulnerability to expose sensitive informatio… CWE-611
XXE
CVE-2020-4772 2024-11-21 14:33 2020-10-12 Show GitHub Exploit DB Packet Storm
198396 5.3 MEDIUM
Adjacent
ibm security_access_manager
security_verify_access
IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive using timing side channel attacks which could aid in further attacks against the sy… CWE-203
 Information Exposure Through Discrepancy
CVE-2020-4699 2024-11-21 14:33 2020-10-12 Show GitHub Exploit DB Packet Storm
198397 5.3 MEDIUM
Adjacent
ibm security_access_manager
security_verify_access
IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive using timing side channel attacks which could aid in further attacks against the sy… CWE-203
 Information Exposure Through Discrepancy
CVE-2020-4661 2024-11-21 14:33 2020-10-12 Show GitHub Exploit DB Packet Storm
198398 5.3 MEDIUM
Adjacent
ibm security_access_manager
security_verify_access
IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an attacker to obtain sensitive using timing side channel attacks which could aid in further attacks against the sy… CWE-203
 Information Exposure Through Discrepancy
CVE-2020-4660 2024-11-21 14:33 2020-10-12 Show GitHub Exploit DB Packet Storm
198399 5.3 MEDIUM
Network
sonicwall sonicos
sonicosv
SonicOS SSLVPN login page allows a remote unauthenticated attacker to perform firewall management administrator username enumeration based on the server responses. This vulnerability affected SonicOS… CWE-203
 Information Exposure Through Discrepancy
CVE-2020-5143 2024-11-21 14:33 2020-10-12 Show GitHub Exploit DB Packet Storm
198400 6.1 MEDIUM
Network
sonicwall sonicos
sonicosv
A stored cross-site scripting (XSS) vulnerability exists in the SonicOS SSLVPN web interface. A remote unauthenticated attacker is able to store and potentially execute arbitrary JavaScript code in t… CWE-79
Cross-site Scripting
CVE-2020-5142 2024-11-21 14:33 2020-10-12 Show GitHub Exploit DB Packet Storm