Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 15, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
230401 6.8 警告 tumusika evolution - TuMusika Evolution の index.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-2090 2012-12-20 18:19 2007-04-18 Show GitHub Exploit DB Packet Storm
230402 7.5 危険 pl-php - pL-PHP の admin.php における認証を回避される脆弱性 - CVE-2007-2007 2012-12-20 18:19 2007-04-12 Show GitHub Exploit DB Packet Storm
230403 7.5 危険 pl-php - pL-PHP の login.php における SQL インジェクションの脆弱性 - CVE-2007-2006 2012-12-20 18:19 2007-04-12 Show GitHub Exploit DB Packet Storm
230404 7.5 危険 raphael limbach - Crea-Book の admin/admin.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-2000 2012-12-20 18:19 2007-04-12 Show GitHub Exploit DB Packet Storm
230405 4.3 警告 Youngzsoft - CmailServer WebMail の mail/signup.asp におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-1991 2012-12-20 18:19 2007-04-12 Show GitHub Exploit DB Packet Storm
230406 7.5 危険 sam crew - Sam Crew MyBlog の games.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-1990 2012-12-20 18:19 2007-04-12 Show GitHub Exploit DB Packet Storm
230407 4.3 警告 phpecho cms - PHPEcho CMS の kernel/filters.inc.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-1988 2012-12-20 18:19 2007-04-11 Show GitHub Exploit DB Packet Storm
230408 7.5 危険 phpexplorator - phpexplorator の phpexplorator.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-1985 2012-12-20 18:19 2007-04-11 Show GitHub Exploit DB Packet Storm
230409 7.5 危険 really simple php and ajax - RSPA における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-1982 2012-12-20 18:19 2007-04-11 Show GitHub Exploit DB Packet Storm
230410 7.5 危険 有限会社ブルームーン - XOOPS 用の PopnupBlog モジュールにおける SQL インジェクションの脆弱性 - CVE-2007-1979 2012-12-20 18:19 2007-04-11 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 15, 2026, 4:28 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
199871 6.5 MEDIUM
Network
dell powerprotect_data_manager
powerprotect_x400_firmware
Dell PowerProtect Data Manager (PPDM) versions prior to 19.4 and Dell PowerProtect X400 versions prior to 3.2 contain an improper authorization vulnerability. A remote authenticated malicious user ma… CWE-552
 Files or Directories Accessible to External Parties
CVE-2020-5356 2024-11-21 14:33 2020-07-7 Show GitHub Exploit DB Packet Storm
199872 8.8 HIGH
Network
dell emc_data_protection_advisor Dell EMC Data Protection Advisor 6.4, 6.5 and 18.1 contain an OS command injection vulnerability. A remote authenticated malicious user may exploit this vulnerability to execute arbitrary commands on… CWE-78
OS Command 
CVE-2020-5352 2024-11-21 14:33 2020-07-7 Show GitHub Exploit DB Packet Storm
199873 6.5 MEDIUM
Network
github_flavored_markdown_project
fedoraproject
github_flavored_markdown
fedora
The table extension in GitHub Flavored Markdown before version 0.29.0.gfm.1 takes O(n * n) time to parse certain inputs. An attacker could craft a markdown table which would take an unreasonably long… - CVE-2020-5238 2024-11-21 14:33 2020-07-2 Show GitHub Exploit DB Packet Storm
199874 5.4 MEDIUM
Network
dell powermax_os
emc_unisphere_for_powermax_virtual_appliance
emc_unisphere_for_powermax
Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Appliance versions prior to 9.1.0.17, and PowerMax OS Release 5978 contain an authorization bypass … CWE-862
 Missing Authorization
CVE-2020-5345 2024-11-21 14:33 2020-06-24 Show GitHub Exploit DB Packet Storm
199875 7.8 HIGH
Local
dell endpoint_security_suite_enterprise
encryption
Dell Encryption versions prior to 10.7 and Dell Endpoint Security Suite versions prior to 2.7 contain a privilege escalation vulnerability due to incorrect permissions. A local malicious user with lo… CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2020-5358 2024-11-21 14:33 2020-06-16 Show GitHub Exploit DB Packet Storm
199876 4.4 MEDIUM
Local
dell chengming_3967_firmware
chengming_3977_firmware
chengming_3980_firmware
chengming_3988_firmware
chengming_3990_firmware
chengming_3991_firmware
g3_15_3500_firmware
g3_15_3590_fir…
Dell Client Consumer and Commercial platforms include an improper authorization vulnerability in the Dell Manageability interface for which an unauthorized actor, with local system access with OS adm… CWE-862
 Missing Authorization
CVE-2020-5362 2024-11-21 14:33 2020-06-11 Show GitHub Exploit DB Packet Storm
199877 7.5 HIGH
Network
whitesourcesoftware whitesource The dashboard in WhiteSource Application Vulnerability Management (AVM) before version 20.4.1 allows Log Injection via a %0A%0D substring in the idp parameter to the /saml/login URI. This closes the … CWE-116
 Improper Encoding or Escaping of Output
CVE-2020-5304 2024-11-21 14:33 2020-06-9 Show GitHub Exploit DB Packet Storm
199878 4.8 MEDIUM
Network
octobercms october In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, a user with the ability to use the import functionality of the `ImportExportController` behavior can be soci… CWE-79
Cross-site Scripting
CVE-2020-5298 2024-11-21 14:33 2020-06-4 Show GitHub Exploit DB Packet Storm
199879 5.1 MEDIUM
Network
octobercms october In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, any users with the ability to modify any data that could eventually be exported as a CSV file from the `Impo… CWE-77
Command Injection
CVE-2020-5299 2024-11-21 14:33 2020-06-4 Show GitHub Exploit DB Packet Storm
199880 2.7 LOW
Network
octobercms october In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, an attacker can exploit this vulnerability to upload jpg, jpeg, bmp, png, webp, gif, ico, css, js, woff, wof… CWE-610
Externally Controlled Reference to a Resource in Another Sphere
CVE-2020-5297 2024-11-21 14:33 2020-06-4 Show GitHub Exploit DB Packet Storm