Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 12, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
230431 6.8 警告 textsend - Carsen Klock TextSend の sender.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-6686 2012-12-20 18:02 2006-12-21 Show GitHub Exploit DB Packet Storm
230432 5 警告 winftp server - WinFtp Server におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2006-6673 2012-12-20 18:02 2006-12-20 Show GitHub Exploit DB Packet Storm
230433 6.8 警告 webcalendar - WebCalendar の export_handler.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-6669 2012-12-20 18:02 2006-12-20 Show GitHub Exploit DB Packet Storm
230434 6.8 警告 verliadmin - VerliAdmin におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-6668 2012-12-20 18:02 2006-12-20 Show GitHub Exploit DB Packet Storm
230435 7.5 危険 verliadmin - VerliAdmin における SQL インジェクションの脆弱性 - CVE-2006-6667 2012-12-20 18:02 2006-12-20 Show GitHub Exploit DB Packet Storm
230436 7.5 危険 verliadmin - VerliAdmin の index.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-6666 2012-12-20 18:02 2006-12-20 Show GitHub Exploit DB Packet Storm
230437 4.1 警告 SUSE - SUSE Linux 上で稼動する Linux novell-lum におけるパスワードなしでコンソールへログインされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2006-6662 2012-12-20 18:02 2006-12-19 Show GitHub Exploit DB Packet Storm
230438 7.5 危険 php-update - PHP-Update の blog.php における任意の PHP コードを実行される脆弱性 - CVE-2006-6661 2012-12-20 18:02 2006-12-20 Show GitHub Exploit DB Packet Storm
230439 7.5 危険 planetluc.com - planetluc.com RateMe の main.inc.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-6648 2012-12-20 18:02 2006-12-19 Show GitHub Exploit DB Packet Storm
230440 7.5 危険 yapbb - YapBB の include/yapbb_session.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-6633 2012-12-20 18:02 2006-12-18 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 13, 2026, 5:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
198381 8.8 HIGH
Network
marvell qconvergeconslole_gui In Marvell QConvergeConsole GUI <= 5.5.0.74, credentials are stored in cleartext in tomcat-users.xml. OS-level users on the QCC host who are not authorized to use QCC may use the plaintext credential… CWE-312
 Cleartext Storage of Sensitive Information
CVE-2020-5805 2024-11-21 14:34 2021-01-9 Show GitHub Exploit DB Packet Storm
198382 8.1 HIGH
Network
marvell qconvergeconslole_gui Marvell QConvergeConsole GUI <= 5.5.0.74 is affected by a path traversal vulnerability. The deleteEventLogFile method of the GWTTestServiceImpl class lacks proper validation of a user-supplied path p… CWE-22
Path Traversal
CVE-2020-5804 2024-11-21 14:34 2021-01-9 Show GitHub Exploit DB Packet Storm
198383 6.5 MEDIUM
Network
umbraco umbraco_cms An authenticated path traversal vulnerability exists during package installation in Umbraco CMS <= 8.9.1 or current, which could result in arbitrary files being written outside of the site home and e… CWE-22
Path Traversal
CVE-2020-5811 2024-11-21 14:34 2020-12-31 Show GitHub Exploit DB Packet Storm
198384 5.4 MEDIUM
Network
umbraco umbraco_cms A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user authorized to upload media can upload a malicious .svg file which act as a stored XSS payload. CWE-79
Cross-site Scripting
CVE-2020-5810 2024-11-21 14:34 2020-12-31 Show GitHub Exploit DB Packet Storm
198385 5.4 MEDIUM
Network
umbraco umbraco_cms A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user can inject arbitrary JavaScript code into iframes when editing content using the TinyMCE rich-text editor, … CWE-79
Cross-site Scripting
CVE-2020-5809 2024-11-21 14:34 2020-12-31 Show GitHub Exploit DB Packet Storm
198386 7.5 HIGH
Network
rockwellautomation factorytalk_diagnostics An unauthenticated remote attacker can send data to RsvcHost.exe listening on TCP port 5241 to add entries in the FactoryTalk Diagnostics event log. The attacker can specify long fields in the log en… CWE-755
 Improper Handling of Exceptional Conditions
CVE-2020-5807 2024-11-21 14:34 2020-12-30 Show GitHub Exploit DB Packet Storm
198387 5.5 MEDIUM
Local
rockwellautomation factorytalk_linx An attacker-controlled memory allocation size can be passed to the C++ new operator in the CServerManager::HandleBrowseLoadIconStreamRequest in messaging.dll. This can be done by sending a specially … CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2020-5806 2024-11-21 14:34 2020-12-30 Show GitHub Exploit DB Packet Storm
198388 7.5 HIGH
Network
rockwellautomation factorytalk_linx An attacker-controlled memory allocation size can be passed to the C++ new operator in RnaDaSvr.dll by sending a specially crafted ConfigureItems message to TCP port 4241. This will cause an unhandle… CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2020-5802 2024-11-21 14:34 2020-12-30 Show GitHub Exploit DB Packet Storm
198389 7.5 HIGH
Network
rockwellautomation factorytalk_linx An attacker can craft and send an OpenNamespace message to port 4241 with valid session-id that triggers an unhandled exception in CFTLDManager::HandleRequest function in RnaDaSvr.dll, resulting in p… CWE-755
 Improper Handling of Exceptional Conditions
CVE-2020-5801 2024-11-21 14:34 2020-12-30 Show GitHub Exploit DB Packet Storm
198390 4.8 MEDIUM
Network
nec ism_server iSM client versions from V5.1 prior to V12.1 running on NEC Storage Manager or NEC Storage Manager Express does not verify a server certificate properly, which allows a man-in-the-middle attacker to … CWE-295
Improper Certificate Validation 
CVE-2020-5684 2024-11-21 14:34 2020-12-24 Show GitHub Exploit DB Packet Storm