Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 9, 2026, 2 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
230421 7.5 危険 wahm e-commerce - WAHM E-Commerce Pie Cart Pro の enc/content.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-4970 2012-12-20 18:02 2006-09-24 Show GitHub Exploit DB Packet Storm
230422 7.5 危険 wahm e-commerce - WAHM E-Commerce Pie Cart Pro における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-4969 2012-12-20 18:02 2006-09-24 Show GitHub Exploit DB Packet Storm
230423 7.5 危険 postnuke software foundation - PNphpBB の includes/functions_admin.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-4968 2012-12-20 18:02 2006-09-24 Show GitHub Exploit DB Packet Storm
230424 5 警告 サン・マイクロシステムズ - SSGD におけるホスト名などを含む重要な情報を取得される脆弱性 - CVE-2006-4959 2012-12-20 18:02 2006-09-23 Show GitHub Exploit DB Packet Storm
230425 6.8 警告 サン・マイクロシステムズ - SSGD におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-4958 2012-12-20 18:02 2006-09-23 Show GitHub Exploit DB Packet Storm
230426 7.5 危険 the myreview system - MyReview の functions.php における SQL インジェクションの脆弱性 - CVE-2006-4957 2012-12-20 18:02 2006-09-23 Show GitHub Exploit DB Packet Storm
230427 7.5 危険 prosysinfo - ProSysInfo TFTP Server TFTPDWIN の tftpd.exe におけるスタックベースのバッファオーバーフローの脆弱性 - CVE-2006-4948 2012-12-20 18:02 2006-09-22 Show GitHub Exploit DB Packet Storm
230428 4.6 警告 シマンテック - Symantec AntiVirus などの製品で使用される NAVENG などのデバイスドライバにおける権限を取得される脆弱性 - CVE-2006-4927 2012-12-20 18:02 2006-10-4 Show GitHub Exploit DB Packet Storm
230429 5 警告 siteatschool - S@S の starnet/editors/htmlarea/popups/images.php における実行可能な拡張子を伴う任意のファイルをアップロードされる脆弱性 - CVE-2006-4922 2012-12-20 18:02 2006-09-20 Show GitHub Exploit DB Packet Storm
230430 7.5 危険 siteatschool - S@S における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-4921 2012-12-20 18:02 2006-09-20 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 9, 2026, 5:07 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
211381 9.8 CRITICAL
Network
draytek vigor300b_firmware
vigor3900_firmware
vigor2960_firmware
A stack-based buffer overflow in apmd on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve code execution via a remote HTTP request. CWE-787
 Out-of-bounds Write
CVE-2020-10827 2024-11-21 13:56 2020-03-27 Show GitHub Exploit DB Packet Storm
211382 9.8 CRITICAL
Network
draytek vigor300b_firmware
vigor3900_firmware
vigor2960_firmware
/cgi-bin/activate.cgi on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve command injection via a remote HTTP request in DEBUG mode. CWE-77
Command Injection
CVE-2020-10826 2024-11-21 13:56 2020-03-27 Show GitHub Exploit DB Packet Storm
211383 9.8 CRITICAL
Network
draytek vigor300b_firmware
vigor3900_firmware
vigor2960_firmware
A stack-based buffer overflow in /cgi-bin/activate.cgi while base64 decoding ticket parameter on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve co… CWE-787
 Out-of-bounds Write
CVE-2020-10825 2024-11-21 13:56 2020-03-27 Show GitHub Exploit DB Packet Storm
211384 9.8 CRITICAL
Network
draytek vigor300b_firmware
vigor3900_firmware
vigor2960_firmware
A stack-based buffer overflow in /cgi-bin/activate.cgi through ticket parameter on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve code execution v… CWE-787
 Out-of-bounds Write
CVE-2020-10824 2024-11-21 13:56 2020-03-27 Show GitHub Exploit DB Packet Storm
211385 9.8 CRITICAL
Network
draytek vigor300b_firmware
vigor3900_firmware
vigor2960_firmware
A stack-based buffer overflow in /cgi-bin/activate.cgi through var parameter on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve code execution via … CWE-787
 Out-of-bounds Write
CVE-2020-10823 2024-11-21 13:56 2020-03-27 Show GitHub Exploit DB Packet Storm
211386 8.8 HIGH
Network
fasterxml
debian
netapp
oracle
jackson-databind
debian_linux
steelstore_cloud_integrated_storage
retail_xstore_point_of_service
primavera_unifier
retail_service_backbone
weblogic_server
retail_merchandising_sy…
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane. CWE-502
 Deserialization of Untrusted Data
CVE-2020-10969 2024-11-21 13:56 2020-03-26 Show GitHub Exploit DB Packet Storm
211387 8.8 HIGH
Network
fasterxml
debian
netapp
oracle
jackson-databind
debian_linux
steelstore_cloud_integrated_storage
retail_xstore_point_of_service
primavera_unifier
retail_service_backbone
weblogic_server
retail_merchandising_sy…
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy). CWE-502
 Deserialization of Untrusted Data
CVE-2020-10968 2024-11-21 13:56 2020-03-26 Show GitHub Exploit DB Packet Storm
211388 6.5 MEDIUM
Network
hestiacp
vestacp
control_panel In the Password Reset Module in VESTA Control Panel through 0.9.8-25 and Hestia Control Panel before 1.1.1, Host header manipulation leads to account takeover because the victim receives a reset URL … NVD-CWE-Other
CVE-2020-10966 2024-11-21 13:56 2020-03-26 Show GitHub Exploit DB Packet Storm
211389 8.1 HIGH
Network
teradici pcoip_management_console Teradici PCoIP Management Console 20.01.0 and 19.11.1 is vulnerable to unauthenticated password resets via login/resetadminpassword of the default admin account. This vulnerability only exists when t… CWE-287
CWE-306
Improper Authentication
Missing Authentication for Critical Function
CVE-2020-10965 2024-11-21 13:56 2020-03-26 Show GitHub Exploit DB Packet Storm
211390 9.8 CRITICAL
Network
s9y serendipity Serendipity before 2.3.4 on Windows allows remote attackers to execute arbitrary code because the filename of a renamed file may end with a dot. This file may then be renamed to have a .php filename. CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2020-10964 2024-11-21 13:56 2020-03-26 Show GitHub Exploit DB Packet Storm