Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 15, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
230381 5 警告 web-app.org - WebAPP の Search フォームなどにおける脆弱性 - CVE-2007-1185 2012-12-20 18:19 2007-03-2 Show GitHub Exploit DB Packet Storm
230382 5 警告 web-app.org - WebAPP の初期設定における不正なデータを送信される脆弱性 CWE-16
環境設定
CVE-2007-1184 2012-12-20 18:19 2007-03-2 Show GitHub Exploit DB Packet Storm
230383 7.5 危険 web-app.org - WebAPP におけるユーザの本名を偽装される脆弱性 - CVE-2007-1183 2012-12-20 18:19 2007-03-2 Show GitHub Exploit DB Packet Storm
230384 6.4 警告 web-app.org - WebAPP における Guest プロフィールを編集される脆弱性 - CVE-2007-1182 2012-12-20 18:19 2007-03-2 Show GitHub Exploit DB Packet Storm
230385 5 警告 web-app.org - WebAPP における脆弱性 - CVE-2007-1181 2012-12-20 18:19 2007-03-2 Show GitHub Exploit DB Packet Storm
230386 4.3 警告 web-app.org - WebAPP におけるクロスサイトリクエストフォージェリ攻撃を仕掛けられる脆弱性 - CVE-2007-1180 2012-12-20 18:19 2007-03-2 Show GitHub Exploit DB Packet Storm
230387 5 警告 web-app.org - WebAPP における脆弱性 - CVE-2007-1179 2012-12-20 18:19 2007-03-2 Show GitHub Exploit DB Packet Storm
230388 7.5 危険 web-app.org - WebAPP における脆弱性 - CVE-2007-1178 2012-12-20 18:19 2007-03-2 Show GitHub Exploit DB Packet Storm
230389 5.8 警告 web-app.org - WebAPP における脆弱性 - CVE-2007-1177 2012-12-20 18:19 2007-03-2 Show GitHub Exploit DB Packet Storm
230390 4.3 警告 web-app.org - WebAPP におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-1176 2012-12-20 18:19 2007-03-2 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 15, 2026, 4:28 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
213321 6.1 MEDIUM
Network
sun ehrd Sunnet eHRD, a human training and development management system, contains vulnerability of Cross-Site Scripting (XSS), attackers can inject arbitrary command into the system and launch XSS attack. CWE-79
Cross-site Scripting
CVE-2020-10509 2024-11-21 13:55 2020-03-27 Show GitHub Exploit DB Packet Storm
213322 7.5 HIGH
Network
sun ehrd Sunnet eHRD, a human training and development management system, improperly stores system files. Attackers can use a specific URL and capture confidential information. NVD-CWE-noinfo
CVE-2020-10508 2024-11-21 13:55 2020-03-27 Show GitHub Exploit DB Packet Storm
213323 9.8 CRITICAL
Network
codesys control_for_plcnext
control_for_beaglebone
control_for_empc-a\/imx6
control_for_iot2000
control_for_linux
control_for_pfc100
control_for_pfc200
control_for_raspberry_pi
contro…
CODESYS V3 web server before 3.5.15.40, as used in CODESYS Control runtime systems, has a buffer overflow. CWE-787
 Out-of-bounds Write
CVE-2020-10245 2024-11-21 13:55 2020-03-26 Show GitHub Exploit DB Packet Storm
213324 7.8 HIGH
Local
asus device_activation DevActSvc.exe in ASUS Device Activation before 1.0.7.0 for Windows 10 notebooks and PCs could lead to unsigned code execution with no additional restrictions when a user puts an application at a part… CWE-427
 Uncontrolled Search Path Element
CVE-2020-10649 2024-11-21 13:55 2020-03-26 Show GitHub Exploit DB Packet Storm
213325 5.4 MEDIUM
Network
wpforms contact_form A stored cross-site scripting (XSS) vulnerability exists in the WPForms Contact Form (aka wpforms-lite) plugin before 1.5.9 for WordPress. CWE-79
Cross-site Scripting
CVE-2020-10385 2024-11-21 13:55 2020-03-25 Show GitHub Exploit DB Packet Storm
213326 7.1 HIGH
Local
redhat
debian
fedoraproject
openstack
ansible_tower
ansible
debian_linux
fedora
A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a subkey of itself and promoting it to a variable wh… CWE-862
 Missing Authorization
CVE-2020-10684 2024-11-21 13:55 2020-03-24 Show GitHub Exploit DB Packet Storm
213327 6.1 MEDIUM
Physics
telegram telegram The Telegram application through 5.12 for Android, when Show Popup is enabled, might allow physically proximate attackers to bypass intended restrictions on message reading and message replying. This… NVD-CWE-noinfo
CVE-2020-10570 2024-11-21 13:55 2020-03-24 Show GitHub Exploit DB Packet Storm
213328 7.5 HIGH
Network
mikrotik routeros The SSH daemon on MikroTik routers through v6.44.3 could allow remote attackers to generate CPU activity, trigger refusal of new authorized connections, and cause a reboot via connect and write syste… CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2020-10364 2024-11-21 13:55 2020-03-24 Show GitHub Exploit DB Packet Storm
213329 9.1 CRITICAL
Network
hashicorp vault HashiCorp Vault and Vault Enterprise versions 0.11.0 through 1.3.3 may, under certain circumstances, have existing nested-path policies grant access to Namespaces created after-the-fact. Fixed in 1.3… NVD-CWE-noinfo
CVE-2020-10661 2024-11-21 13:55 2020-03-23 Show GitHub Exploit DB Packet Storm
213330 5.3 MEDIUM
Network
hashicorp vault HashiCorp Vault and Vault Enterprise versions 0.9.0 through 1.3.3 may, under certain circumstances, have an Entity's Group membership inadvertently include Groups the Entity no longer has permissions… CWE-276
Incorrect Default Permissions 
CVE-2020-10660 2024-11-21 13:55 2020-03-23 Show GitHub Exploit DB Packet Storm