Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 11, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
230741 4.3 警告 kailash nadh - Kailash Nadh boastMachine におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-3826 2012-12-20 18:02 2006-07-25 Show GitHub Exploit DB Packet Storm
230742 5.1 警告 Geodesic Solutions - GeodesicSolutions の index.php における SQL インジェクションの脆弱性 - CVE-2006-3823 2012-12-20 18:02 2006-07-25 Show GitHub Exploit DB Packet Storm
230743 5.1 警告 Geodesic Solutions - GeodesicSolutions GeoAuctions Enterprise の index.php における SQL インジェクションの脆弱性 - CVE-2006-3822 2012-12-20 18:02 2006-07-25 Show GitHub Exploit DB Packet Storm
230744 4.3 警告 ATRC - ATutor におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-3821 2012-12-20 18:02 2006-07-25 Show GitHub Exploit DB Packet Storm
230745 7.5 危険 TWiki - TWiki の設定スクリプトにおける任意の Perl コードを実行される脆弱性 - CVE-2006-3819 2012-12-20 18:02 2006-07-21 Show GitHub Exploit DB Packet Storm
230746 7.5 危険 krusader - Krusader におけるパスワードを盗まれる脆弱性 - CVE-2006-3816 2012-12-20 18:02 2006-07-25 Show GitHub Exploit DB Packet Storm
230747 5.1 警告 cheese tracker - Cheese Tracker の loader_xm.cpp におけるバッファオーバーフローの脆弱性 - CVE-2006-3814 2012-12-20 18:02 2006-07-25 Show GitHub Exploit DB Packet Storm
230748 4.3 警告 amazing flash commerce - Amazing Flash AFCommerce Shopping Cart におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-3800 2012-12-20 18:02 2006-07-24 Show GitHub Exploit DB Packet Storm
230749 7.5 危険 deluxebb - DeluxeBB における SQL インジェクション保護を回避される脆弱性 - CVE-2006-3799 2012-12-20 18:02 2006-07-24 Show GitHub Exploit DB Packet Storm
230750 5 警告 deluxebb - DeluxeBB における _GET 変数を上書きされる脆弱性 - CVE-2006-3798 2012-12-20 18:02 2006-07-24 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 11, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
211591 9.8 CRITICAL
Network
gitlab gitlab GitLab 8.10 and later through 12.9 is vulnerable to an SSRF in a project import note feature. CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2020-10956 2024-11-21 13:56 2020-03-28 Show GitHub Exploit DB Packet Storm
211592 6.5 MEDIUM
Network
gitlab
debian
gitlab
debian_linux
GitLab EE/CE 11.1 through 12.9 is vulnerable to parameter tampering on an upload feature that allows an unauthorized user to read content available under specific folders. CWE-862
 Missing Authorization
CVE-2020-10955 2024-11-21 13:56 2020-03-28 Show GitHub Exploit DB Packet Storm
211593 7.5 HIGH
Network
gitlab gitlab GitLab through 12.9 is affected by a potential DoS in repository archive download. CWE-400
 Uncontrolled Resource Consumption
CVE-2020-10954 2024-11-21 13:56 2020-03-28 Show GitHub Exploit DB Packet Storm
211594 7.5 HIGH
Network
gitlab gitlab In GitLab EE 11.7 through 12.9, the NPM feature is vulnerable to a path traversal issue. CWE-22
Path Traversal
CVE-2020-10953 2024-11-21 13:56 2020-03-28 Show GitHub Exploit DB Packet Storm
211595 6.5 MEDIUM
Network
gitlab gitlab GitLab EE/CE 8.11 through 12.9.1 allows blocked users to pull/push docker images. NVD-CWE-noinfo
CVE-2020-10952 2024-11-21 13:56 2020-03-28 Show GitHub Exploit DB Packet Storm
211596 8.8 HIGH
Network
custom_searchable_data_entry_system_project custom_searchable_data_entry_system The custom-searchable-data-entry-system (aka Custom Searchable Data Entry System) plugin through 1.7.1 for WordPress allows SQL Injection. NOTE: this product is discontinued. CWE-89
SQL Injection
CVE-2020-10817 2024-11-21 13:56 2020-03-28 Show GitHub Exploit DB Packet Storm
211597 9.1 CRITICAL
Network
osmand osmand Osmand through 2.0.0 allow XXE because of binary/BinaryMapIndexReader.java. CWE-611
XXE
CVE-2020-10993 2024-11-21 13:56 2020-03-27 Show GitHub Exploit DB Packet Storm
211598 9.8 CRITICAL
Network
azkaban_project azkaban Azkaban through 3.84.0 allows XXE, related to validator/XmlValidatorManager.java and user/XmlUserManager.java. CWE-611
XXE
CVE-2020-10992 2024-11-21 13:56 2020-03-27 Show GitHub Exploit DB Packet Storm
211599 9.8 CRITICAL
Network
mulesoft aplkit Mulesoft APIkit through 1.3.0 allows XXE because of validation/RestXmlSchemaValidator.java CWE-611
XXE
CVE-2020-10991 2024-11-21 13:56 2020-03-27 Show GitHub Exploit DB Packet Storm
211600 9.8 CRITICAL
Network
accenture mercury An XXE issue exists in Accenture Mercury before 1.12.28 because of the platformlambda/core/serializers/SimpleXmlParser.java component. CWE-611
XXE
CVE-2020-10990 2024-11-21 13:56 2020-03-27 Show GitHub Exploit DB Packet Storm