Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 20, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
230521 6.4 警告 universal ircd - ircu における特定のチャンネルモードを設定される脆弱性 - CVE-2007-4407 2012-12-20 18:33 2007-08-18 Show GitHub Exploit DB Packet Storm
230522 7.5 危険 universal ircd - ircu における分割時にチャンネルをコントロールされる脆弱性 - CVE-2007-4406 2012-12-20 18:33 2007-08-18 Show GitHub Exploit DB Packet Storm
230523 7.8 危険 universal ircd - ircu におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-4405 2012-12-20 18:33 2007-08-18 Show GitHub Exploit DB Packet Storm
230524 7.8 危険 universal ircd - ircu におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-4404 2012-12-20 18:33 2007-08-18 Show GitHub Exploit DB Packet Storm
230525 2.1 注意 SUSE - SUSE Linux 上で稼動する findutils-locate パッケージが作成した "コアクリーン" cron ジョブにおける任意のファイルを削除される脆弱性 - CVE-2007-4394 2012-12-20 18:33 2007-08-10 Show GitHub Exploit DB Packet Storm
230526 4.6 警告 SUSE - SUSE Linux 上で稼動する orarun 用のインストールスクリプトにおける未加工のディスクパーティションを読み書きされる脆弱性 - CVE-2007-4393 2012-12-20 18:33 2007-08-10 Show GitHub Exploit DB Packet Storm
230527 6.8 警告 stephane pineau - Stephane Pineau VOTE の depouilg.php3 における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-4384 2012-12-20 18:33 2007-08-17 Show GitHub Exploit DB Packet Storm
230528 7.2 危険 シマンテック - Symantec Altiris Deployment Solution の Aclient におけるローカルのシステム権限を取得される脆弱性 - CVE-2007-4380 2012-12-20 18:33 2007-08-13 Show GitHub Exploit DB Packet Storm
230529 4.3 警告 rndlabs - Babo Violent におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-4379 2012-12-20 18:33 2007-08-16 Show GitHub Exploit DB Packet Storm
230530 6.8 警告 rndlabs - Babo Violent におけるフォーマットストリングの脆弱性 - CVE-2007-4378 2012-12-20 18:33 2007-08-16 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 20, 2026, 4:14 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
197321 9.8 CRITICAL
Network
whmcssmarters web_tv_player IPTV Smarters WEB TV PLAYER through 2020-02-22 allows attackers to execute OS commands by uploading a script. CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2020-9380 2024-11-21 14:40 2020-03-5 Show GitHub Exploit DB Packet Storm
197322 9.1 CRITICAL
Network
humaxdigital hga12r-02_firmware HUMAX HGA12R-02 BRGCAA 1.1.53 devices allow Session Hijacking. CWE-384
 Session Fixation
CVE-2020-9370 2024-11-21 14:40 2020-03-5 Show GitHub Exploit DB Packet Storm
197323 9.8 CRITICAL
Network
rubetek smarthome_firmware Rubetek SmartHome 2020 devices use unencrypted 433 MHz communication between controllers and beacons, allowing an attacker to sniff and spoof beacon requests remotely. CWE-319
Cleartext Transmission of Sensitive Information
CVE-2020-9550 2024-11-21 14:40 2020-03-5 Show GitHub Exploit DB Packet Storm
197324 9.8 CRITICAL
Network
humaxdigital hga12r-02_firmware An issue was discovered on HUMAX HGA12R-02 BRGCAA 1.1.53 devices. A vulnerability in the authentication functionality in the web-based interface could allow an unauthenticated remote attacker to capt… CWE-319
Cleartext Transmission of Sensitive Information
CVE-2020-9477 2024-11-21 14:40 2020-03-5 Show GitHub Exploit DB Packet Storm
197325 7.5 HIGH
Network
commscope arris_tg1692a_firmware ARRIS TG1692A devices allow remote attackers to discover the administrator login name and password by reading the /login page and performing base64 decoding. CWE-326
Inadequate Encryption Strength
CVE-2020-9476 2024-11-21 14:40 2020-03-5 Show GitHub Exploit DB Packet Storm
197326 7.8 HIGH
Local
codepeople appointment_booking_calendar The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking form to be any formula, which then could be exported via t… CWE-1236
 Improper Neutralization of Formula Elements in a CSV File
CVE-2020-9372 2024-11-21 14:40 2020-03-5 Show GitHub Exploit DB Packet Storm
197327 4.8 MEDIUM
Network
codepeople appointment_booking_calendar Stored XSS exists in the Appointment Booking Calendar plugin before 1.3.35 for WordPress. In the cpabc_appointments.php file, the Calendar Name input could allow attackers to inject arbitrary JavaScr… CWE-79
Cross-site Scripting
CVE-2020-9371 2024-11-21 14:40 2020-03-5 Show GitHub Exploit DB Packet Storm
197328 5.3 MEDIUM
Network
creative-solutions creative_contact_form An issue was discovered in helpers/mailer.php in the Creative Contact Form extension 4.6.2 before 2019-12-03 for Joomla!. A directory traversal vulnerability resides in the filename field for uploade… CWE-22
Path Traversal
CVE-2020-9364 2024-11-21 14:40 2020-03-5 Show GitHub Exploit DB Packet Storm
197329 7.8 HIGH
Local
pdfresurrect_project
debian
pdfresurrect
debian_linux
In PDFResurrect 0.12 through 0.19, get_type in pdf.c has an out-of-bounds write via a crafted PDF document. CWE-787
 Out-of-bounds Write
CVE-2020-9549 2024-11-21 14:40 2020-03-2 Show GitHub Exploit DB Packet Storm
197330 7.5 HIGH
Network
palemoon pale_moon Pale Moon 28.x before 28.8.4 has a segmentation fault related to module scripting, as demonstrated by a Lacoste web site. CWE-476
 NULL Pointer Dereference
CVE-2020-9545 2024-11-21 14:40 2020-03-2 Show GitHub Exploit DB Packet Storm