Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 14, 2026, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
230661 10 危険 phpBB - phpBB の Dimension モジュールにおける PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-7174 2012-12-20 18:19 2007-03-21 Show GitHub Exploit DB Packet Storm
230662 10 危険 php-stats - PHP-Stats の admin.php における任意の PHP コードを実行される脆弱性 - CVE-2006-7173 2012-12-20 18:19 2007-03-20 Show GitHub Exploit DB Packet Storm
230663 7.5 危険 php-stats - PHP-Stats の php-stats.recphp.php における SQL インジェクションの脆弱性 - CVE-2006-7172 2012-12-20 18:19 2007-03-20 Show GitHub Exploit DB Packet Storm
230664 6.8 警告 PHP Outburst - UPB の includes/header_simple.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-7169 2012-12-20 18:19 2007-03-20 Show GitHub Exploit DB Packet Storm
230665 7.5 危険 prorat - ProRat Server におけるリモートログインに対する認証メカニズムを回避される脆弱性 - CVE-2006-7167 2012-12-20 18:19 2007-03-20 Show GitHub Exploit DB Packet Storm
230666 1.9 注意 レッドハット - RHEL のカーネルにおける虚偽の成功ステータスを取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2007-0004 2012-12-20 18:19 2006-07-21 Show GitHub Exploit DB Packet Storm
230667 6.5 警告 XWiki - XWiki の PreviewAction における任意のコードを実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2006-7223 2012-12-20 18:19 2006-10-11 Show GitHub Exploit DB Packet Storm
230668 7.5 危険 Sendmail Consortium - Red Hat Enterprise Linux 上で稼動する Sendmail における想定より少ないセキュアチャネルが使用される脆弱性 - CVE-2006-7175 2012-12-20 18:19 2005-11-3 Show GitHub Exploit DB Packet Storm
230669 1.9 注意 Simon Tatham - PuTTY における重要な情報を取得される脆弱性 - CVE-2006-7162 2012-12-20 18:18 2007-03-7 Show GitHub Exploit DB Packet Storm
230670 10 危険 phpBB - Brazilian PHPBB の maluinfo における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-7148 2012-12-20 18:18 2007-03-7 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 15, 2026, 4:28 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
199291 5.5 MEDIUM
Local
f5 big-ip_access_policy_manager In versions bundled with BIG-IP APM 12.1.0-12.1.5 and 11.6.1-11.6.5.2, Edge Client for Linux exposes full session ID in the local log files. CWE-532
 Inclusion of Sensitive Information in Log Files
CVE-2020-5908 2024-11-21 14:34 2020-07-2 Show GitHub Exploit DB Packet Storm
199292 7.2 HIGH
Network
f5 big-ip_local_traffic_manager
big-ip_advanced_firewall_manager
big-ip_application_acceleration_manager
big-ip_analytics
big-ip_access_policy_manager
big-ip_application_security_manager<…
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, an authorized user provided with access only to the TMOS Shell (tmsh) may be able to conduc… NVD-CWE-noinfo
CVE-2020-5907 2024-11-21 14:34 2020-07-2 Show GitHub Exploit DB Packet Storm
199293 8.1 HIGH
Network
f5 big-ip_local_traffic_manager
big-ip_advanced_firewall_manager
big-ip_application_acceleration_manager
big-ip_analytics
big-ip_access_policy_manager
big-ip_application_security_manager<…
In versions 13.1.0-13.1.3.3, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, the BIG-IP system does not properly enforce the access controls for the scp.blacklist files. This allows Admin and Resource Admin us… CWE-276
Incorrect Default Permissions 
CVE-2020-5906 2024-11-21 14:34 2020-07-2 Show GitHub Exploit DB Packet Storm
199294 9.6 CRITICAL
Network
f5 nginx_controller In NGINX Controller 3.3.0-3.4.0, undisclosed API endpoints may allow for a reflected Cross Site Scripting (XSS) attack. If the victim user is logged in as admin this could result in a complete compro… CWE-79
Cross-site Scripting
CVE-2020-5901 2024-11-21 14:34 2020-07-2 Show GitHub Exploit DB Packet Storm
199295 7.8 HIGH
Local
f5 nginx_controller In NGINX Controller 3.0.0-3.4.0, recovery code required to change a user's password is transmitted and stored in the database in plain text, which allows an attacker who can intercept the database co… CWE-312
CWE-319
CWE-522
 Cleartext Storage of Sensitive Information
Cleartext Transmission of Sensitive Information
 Insufficiently Protected Credentials
CVE-2020-5899 2024-11-21 14:34 2020-07-2 Show GitHub Exploit DB Packet Storm
199296 4.3 MEDIUM
Network
f5 big-ip_access_policy_manager
big-ip_advanced_firewall_manager
big-ip_analytics
big-ip_application_acceleration_manager
big-ip_application_security_manager
big-ip_domain_name_system
In version 11.6.1-11.6.5.2 of the BIG-IP system Configuration utility Network > WCCP page, the system does not sanitize all user-provided data before display. CWE-79
Cross-site Scripting
CVE-2020-5905 2024-11-21 14:34 2020-07-2 Show GitHub Exploit DB Packet Storm
199297 8.8 HIGH
Network
f5 big-ip_access_policy_manager
big-ip_advanced_firewall_manager
big-ip_analytics
big-ip_application_acceleration_manager
big-ip_application_security_manager
big-ip_domain_name_system
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, a cross-site request forgery (CSRF) vulnerability in the Traffic Management User Interface (TMUI), also referred… CWE-352
 Origin Validation Error
CVE-2020-5904 2024-11-21 14:34 2020-07-2 Show GitHub Exploit DB Packet Storm
199298 6.1 MEDIUM
Network
f5 big-ip_local_traffic_manager
big-ip_advanced_firewall_manager
big-ip_application_acceleration_manager
big-ip_analytics
big-ip_access_policy_manager
big-ip_application_security_manager<…
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, a Cross-Site Scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility. CWE-79
Cross-site Scripting
CVE-2020-5903 2024-11-21 14:34 2020-07-2 Show GitHub Exploit DB Packet Storm
199299 9.8 CRITICAL
Network
f5 big-ip_access_policy_manager
big-ip_advanced_firewall_manager
big-ip_advanced_web_application_firewall
big-ip_analytics
big-ip_application_acceleration_manager
big-ip_application_secur…
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility… CWE-22
Path Traversal
CVE-2020-5902 2024-11-21 14:34 2020-07-2 Show GitHub Exploit DB Packet Storm
199300 8.8 HIGH
Network
f5 nginx_controller In versions 3.0.0-3.4.0, 2.0.0-2.9.0, and 1.0.1, there is insufficient cross-site request forgery (CSRF) protections for the NGINX Controller user interface. CWE-352
 Origin Validation Error
CVE-2020-5900 2024-11-21 14:34 2020-07-1 Show GitHub Exploit DB Packet Storm