Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 27, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
230611 7.5 危険 Trivantis Corporation Inc. - Trivantis CourseMill Enterprise Learning Management System の userlogin.jsp における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-6338 2012-12-20 18:34 2007-12-14 Show GitHub Exploit DB Packet Storm
230612 5 警告 sergey lyubka - Windows 上で稼動する Sergey Lyubka Simple HTTPD におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2007-6326 2012-12-20 18:34 2007-12-13 Show GitHub Exploit DB Packet Storm
230613 5 警告 xml2owl - xml2owl の filedownload.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2007-6322 2012-12-20 18:34 2007-12-13 Show GitHub Exploit DB Packet Storm
230614 4.3 警告 Roundcube.net - RoundCube webmail におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-6321 2012-12-20 18:34 2007-12-11 Show GitHub Exploit DB Packet Storm
230615 6.8 警告 WordPress.org - WordPress の wp-includes/query.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-6318 2012-12-20 18:34 2007-12-11 Show GitHub Exploit DB Packet Storm
230616 5.5 警告 Real Time Logic - BarracudaDrive Web Server におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2007-6317 2012-12-20 18:34 2007-12-11 Show GitHub Exploit DB Packet Storm
230617 4.3 警告 Real Time Logic - BarracudaDrive Web Server におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-6316 2012-12-20 18:34 2007-12-11 Show GitHub Exploit DB Packet Storm
230618 4 警告 Real Time Logic - Group Chat の BarracudaDrive Web Server におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2007-6315 2012-12-20 18:34 2007-12-11 Show GitHub Exploit DB Packet Storm
230619 5 警告 Real Time Logic - BarracudaDrive Web Server における Web スクリプトに対するソースコードを読まれる脆弱性 CWE-20
不適切な入力確認
CVE-2007-6314 2012-12-20 18:34 2007-12-11 Show GitHub Exploit DB Packet Storm
230620 4.3 警告 ウェブセンス - Websense Enterprise および Web Security Suite の Web Reporting Tools portal におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-6312 2012-12-20 18:34 2007-12-11 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 27, 2026, 4:52 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
214011 7.8 HIGH
Local
microfocus operations_agent Unauthorized escalation of local privileges vulnerability on Micro Focus Operation Agent, affecting all versions prior to versions 12.11. The vulnerability could be exploited to escalate the local pr… NVD-CWE-noinfo
CVE-2020-11861 2024-11-21 13:58 2020-09-19 Show GitHub Exploit DB Packet Storm
214012 8.8 HIGH
Network
titanhq spamtitan An issue was discovered in Titan SpamTitan 7.07. Due to improper sanitization of the parameter quid, used in the page mailqueue.php, code injection can occur. The input for this parameter is provided… CWE-94
Code Injection
CVE-2020-11804 2024-11-21 13:58 2020-09-18 Show GitHub Exploit DB Packet Storm
214013 8.8 HIGH
Network
titanhq spamtitan An issue was discovered in Titan SpamTitan 7.07. Improper sanitization of the parameter jaction when interacting with the page mailqueue.php could lead to PHP code evaluation server-side, because the… CWE-94
Code Injection
CVE-2020-11803 2024-11-21 13:58 2020-09-18 Show GitHub Exploit DB Packet Storm
214014 6.5 MEDIUM
Network
titanhq spamtitan An issue was discovered in Titan SpamTitan 7.07. Improper sanitization of the parameter fname, used on the page certs-x.php, would allow an attacker to retrieve the contents of arbitrary files. The u… CWE-22
Path Traversal
CVE-2020-11700 2024-11-21 13:58 2020-09-18 Show GitHub Exploit DB Packet Storm
214015 8.8 HIGH
Network
titanhq spamtitan An issue was discovered in Titan SpamTitan 7.07. Improper validation of the parameter fname on the page certs-x.php would allow an attacker to execute remote code on the target server. The user has t… CWE-78
OS Command 
CVE-2020-11699 2024-11-21 13:58 2020-09-18 Show GitHub Exploit DB Packet Storm
214016 9.8 CRITICAL
Network
titanhq spamtitan An issue was discovered in Titan SpamTitan 7.07. Improper input sanitization of the parameter community on the page snmp-x.php would allow a remote attacker to inject commands into the file snmpd.con… CWE-77
Command Injection
CVE-2020-11698 2024-11-21 13:58 2020-09-18 Show GitHub Exploit DB Packet Storm
214017 7.5 HIGH
Network
mikrotik routeros An array index error in MikroTik RouterOS 6.41.3 through 6.46.5, and 7.x through 7.0 Beta5, allows an unauthenticated remote attacker to crash the SMB server via modified setup-request packets, aka S… CWE-129
 Improper Validation of Array Index
CVE-2020-11881 2024-11-21 13:58 2020-09-15 Show GitHub Exploit DB Packet Storm
214018 9.1 CRITICAL
Network
linux4sam at91bootstrap AT91bootstrap before 3.9.2 does not properly wipe encryption and authentication keys from memory before passing control to a less privileged software component. This can be exploited to disclose thes… CWE-212
 Improper Removal of Sensitive Information Before Storage or Transfer
CVE-2020-11684 2024-11-21 13:58 2020-09-14 Show GitHub Exploit DB Packet Storm
214019 6.8 MEDIUM
Physics
linux4sam at91bootstrap A timing side channel was discovered in AT91bootstrap before 3.9.2. It can be exploited by attackers with physical access to forge CMAC values and subsequently boot arbitrary code on an affected syst… CWE-203
 Information Exposure Through Discrepancy
CVE-2020-11683 2024-11-21 13:58 2020-09-14 Show GitHub Exploit DB Packet Storm
214020 8.1 HIGH
Network
foxitsoftware phantompdf
reader
In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can obtain sensitive information about an uninitialized object because of direct transformation from PDF Object to… CWE-345
 Insufficient Verification of Data Authenticity
CVE-2020-11493 2024-11-21 13:58 2020-09-4 Show GitHub Exploit DB Packet Storm