Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 11, 2026, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
230461 5 警告 Xerox - Xerox WorkCentre などにおける特定の設定内容を変更される脆弱性 - CVE-2006-6429 2012-12-20 18:02 2006-12-10 Show GitHub Exploit DB Packet Storm
230462 7.5 危険 Xerox - Xerox WorkCentre などにおけるアクセス権を取得される脆弱性 - CVE-2006-6428 2012-12-20 18:02 2006-12-10 Show GitHub Exploit DB Packet Storm
230463 7.5 危険 Xerox - Xerox WorkCentre および WorkCentre Pro の Web User Interface における任意のコマンドを実行される脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2006-6427 2012-12-20 18:02 2006-12-10 Show GitHub Exploit DB Packet Storm
230464 6.8 警告 thinkedit - ThinkEdit の design/thinkedit/render.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-6426 2012-12-20 18:02 2006-12-10 Show GitHub Exploit DB Packet Storm
230465 6 警告 phpBB - phpBB のプライベートメッセージボックス実装 (privmsg.php) におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-6421 2012-12-20 18:02 2006-12-10 Show GitHub Exploit DB Packet Storm
230466 6.8 警告 Widget Factory Limited - Joomla! 用の Ryan Demmer JCE におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-6420 2012-12-20 18:02 2006-12-10 Show GitHub Exploit DB Packet Storm
230467 7.5 危険 Widget Factory Limited - Joomla! 用の Ryan Demmer JCE における任意のローカルファイルをインクルードされる脆弱性 - CVE-2006-6419 2012-12-20 18:02 2006-12-10 Show GitHub Exploit DB Packet Storm
230468 7.5 危険 phpleague - univert - PhpLeague - Univert PhpLeague における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-6416 2012-12-20 18:02 2006-12-10 Show GitHub Exploit DB Packet Storm
230469 4.6 警告 VMware - VMWare の ActiveX コントロールにおけるバッファオーバーフローの脆弱性 - CVE-2006-6410 2012-12-20 18:02 2006-12-9 Show GitHub Exploit DB Packet Storm
230470 5 警告 softwin - SMB の BitDefender Mail Protection におけるウィルス検出を回避される脆弱性 - CVE-2006-6405 2012-12-20 18:02 2006-12-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 12, 2026, 5:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
198471 5.3 MEDIUM
Local
sonicwall netextender SonicWall NetExtender Windows client vulnerable to unquoted service path vulnerability, this allows a local attacker to gain elevated privileges in the host operating system. This vulnerability impac… CWE-428
 Unquoted Search Path or Element
CVE-2020-5147 2024-11-21 14:33 2021-01-9 Show GitHub Exploit DB Packet Storm
198472 7.2 HIGH
Network
sonicwall sma_100_firmware A vulnerability in SonicWall SMA100 appliance allow an authenticated management-user to perform OS command injection using HTTP POST parameters. This vulnerability affected SMA100 Appliance version 1… CWE-78
OS Command 
CVE-2020-5146 2024-11-21 14:33 2021-01-9 Show GitHub Exploit DB Packet Storm
198473 5.4 MEDIUM
Network
ibm rational_quality_manager
rational_team_concert
rational_doors_next_generation
rational_rhapsody_design_manager
rhapsody_model_manager
doors_next
engineering_workflow_management
c…
IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentia… CWE-79
Cross-site Scripting
CVE-2020-4733 2024-11-21 14:33 2021-01-9 Show GitHub Exploit DB Packet Storm
198474 5.4 MEDIUM
Network
ibm rational_quality_manager
rational_team_concert
rational_doors_next_generation
rational_rhapsody_design_manager
rhapsody_model_manager
doors_next
engineering_workflow_management
c…
IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentia… CWE-79
Cross-site Scripting
CVE-2020-4697 2024-11-21 14:33 2021-01-9 Show GitHub Exploit DB Packet Storm
198475 5.4 MEDIUM
Network
ibm rational_quality_manager
rational_team_concert
rational_doors_next_generation
rational_rhapsody_design_manager
rhapsody_model_manager
doors_next
engineering_workflow_management
c…
IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentia… CWE-79
Cross-site Scripting
CVE-2020-4691 2024-11-21 14:33 2021-01-9 Show GitHub Exploit DB Packet Storm
198476 5.3 MEDIUM
Network
ibm spectrum_protect_plus IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may allow unauthenticated and unauthorized access to VDAP proxy which can result in an attacker obtaining information they are not authorized to access… CWE-306
CWE-862
Missing Authentication for Critical Function
 Missing Authorization
CVE-2020-5022 2024-11-21 14:33 2021-01-9 Show GitHub Exploit DB Packet Storm
198477 4.4 MEDIUM
Local
ibm spectrum_protect_plus IBM Spectrum Protect Plus 10.1.0 through 10.1.6 does not invalidate session after a password reset which could allow a local user to impersonate another user on the system. IBM X-Force ID: 193657. CWE-384
 Session Fixation
CVE-2020-5021 2024-11-21 14:33 2021-01-9 Show GitHub Exploit DB Packet Storm
198478 6.1 MEDIUM
Network
ibm spectrum_protect_plus IBM Spectrum Protect Plus 10.1.0 through 10.1.6 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker coul… CWE-1021
 Improper Restriction of Rendered UI Layers or Frames
CVE-2020-5020 2024-11-21 14:33 2021-01-9 Show GitHub Exploit DB Packet Storm
198479 6.5 MEDIUM
Network
ibm spectrum_protect_plus IBM Spectrum Protect Plus 10.1.0 through 10.1.6 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. By sending a specially crafted HTTP request, a remo… CWE-74
Injection
CVE-2020-5019 2024-11-21 14:33 2021-01-9 Show GitHub Exploit DB Packet Storm
198480 7.5 HIGH
Network
ibm spectrum_protect_plus IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may include sensitive information in its URLs increasing the risk of such information being caputured by an attacker. IBM X-Force ID: 193654. CWE-312
 Cleartext Storage of Sensitive Information
CVE-2020-5018 2024-11-21 14:33 2021-01-9 Show GitHub Exploit DB Packet Storm