Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 10, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
230391 7.5 危険 yuuki yoshizawa - Yuuki Yoshizawa Exporia の common.php におけるディレクトリトラバーサルの脆弱性 - CVE-2006-5113 2012-12-20 18:02 2006-10-3 Show GitHub Exploit DB Packet Storm
230392 6.8 警告 VirtueMart - VirtueMart Joomla! eCommerce Edition CMS の index.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-5096 2012-12-20 18:02 2006-09-29 Show GitHub Exploit DB Packet Storm
230393 5.1 警告 phpbb xs - phpBB XS の includes/functions_kb.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-5094 2012-12-20 18:02 2006-09-29 Show GitHub Exploit DB Packet Storm
230394 7.5 危険 php heaven - phpHeaven phpMyChat の connected_users.lib.php3 における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-5088 2012-12-20 18:02 2006-09-29 Show GitHub Exploit DB Packet Storm
230395 6.4 警告 pixel motion - Blog Pixel Motion における管理ユーザに対するユーザ名およびパスワードを変更される脆弱性 - CVE-2006-5086 2012-12-20 18:02 2006-09-28 Show GitHub Exploit DB Packet Storm
230396 7.5 危険 pixel motion - Blog Pixel Motion の config.php における任意の PHP コードを実行される脆弱性 - CVE-2006-5085 2012-12-20 18:02 2006-09-28 Show GitHub Exploit DB Packet Storm
230397 7.5 危険 Skype Technologies S.A. - Mac 用の eBay Skype におけるフォーマットストリングの脆弱性 CWE-20
不適切な入力確認
CVE-2006-5084 2012-12-20 18:02 2006-09-28 Show GitHub Exploit DB Packet Storm
230398 7.5 危険 phpbb security - IM Portal の includes/functions_portal.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-5083 2012-12-20 18:02 2006-09-28 Show GitHub Exploit DB Packet Storm
230399 7.5 危険 SugarCRM - SugarCRM における脆弱性 CWE-noinfo
情報不足
CVE-2006-5082 2012-12-20 18:02 2006-09-17 Show GitHub Exploit DB Packet Storm
230400 7.5 危険 polaring - Kristian Niemi Polaring の view/general.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-5078 2012-12-20 18:02 2006-09-28 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 10, 2026, 4:58 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
198491 8.8 HIGH
Network
ibm
netapp
cognos_analytics
oncommand_insight
IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to inject malicious HTML code that when viewed by the authenticated victim would execute the code. IBM X-Force ID: 182395. CWE-79
Cross-site Scripting
CVE-2020-4520 2024-11-21 14:32 2021-06-1 Show GitHub Exploit DB Packet Storm
198492 5.4 MEDIUM
Network
ibm
netapp
cognos_analytics
oncommand_insight
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality pot… CWE-79
Cross-site Scripting
CVE-2020-4354 2024-11-21 14:32 2021-06-1 Show GitHub Exploit DB Packet Storm
198493 8.2 HIGH
Network
ibm
netapp
cognos_analytics
oncommand_insight
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive info… CWE-611
XXE
CVE-2020-4300 2024-11-21 14:32 2021-06-1 Show GitHub Exploit DB Packet Storm
198494 4.3 MEDIUM
Network
ibm openpages_grc_platform IBM OpenPages GRC Platform 8.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in furt… CWE-209
Information Exposure Through an Error Message
CVE-2020-4536 2024-11-21 14:32 2021-05-12 Show GitHub Exploit DB Packet Storm
198495 5.4 MEDIUM
Network
ibm openpages_grc_platform IBM OpenPages GRC Platform 8.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potenti… CWE-79
Cross-site Scripting
CVE-2020-4535 2024-11-21 14:32 2021-05-12 Show GitHub Exploit DB Packet Storm
198496 9.1 CRITICAL
Network
fossasia susi.ai SUSI.AI is an intelligent Open Source personal assistant. SUSI.AI Server before version d27ed0f has a directory traversal vulnerability due to insufficient input validation. Any admin config and file… CWE-22
Path Traversal
CVE-2020-4039 2024-11-21 14:32 2021-05-1 Show GitHub Exploit DB Packet Storm
198497 5.3 MEDIUM
Network
ibm planning_analytics IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information by allowing cross-window communication with unrestricted target origin via documentation frames. NVD-CWE-Other
CVE-2020-4562 2024-11-21 14:32 2021-04-27 Show GitHub Exploit DB Packet Storm
198498 7.3 HIGH
Network
ibm security_guardium IBM Security Guardium 11.2 performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses. I… CWE-269
 Improper Privilege Management
CVE-2020-4184 2024-11-21 14:32 2021-03-16 Show GitHub Exploit DB Packet Storm
198499 6.1 MEDIUM
Network
hcltech digital_experience In Digital Experience 8.5, 9.0, and 9.5, WSRP consumer is vulnerable to cross-site scripting (XSS). CWE-79
Cross-site Scripting
CVE-2020-4081 2024-11-21 14:32 2021-02-3 Show GitHub Exploit DB Packet Storm
198500 5.4 MEDIUM
Network
ibm rational_quality_manager
rhapsody_design_manager
rational_engineering_lifecycle_manager
rhapsody_model_manager
engineering_workflow_management
collaborative_lifecycle_management
eng…
IBM Jazz Foundation products could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vuln… CWE-1021
 Improper Restriction of Rendered UI Layers or Frames
CVE-2020-4547 2024-11-21 14:32 2021-01-28 Show GitHub Exploit DB Packet Storm