Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 17, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
230761 4.3 警告 サン・マイクロシステムズ - Sun Java System Access Manager におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-0628 2012-12-20 18:19 2007-01-29 Show GitHub Exploit DB Packet Storm
230762 5 警告 vlad leont - FD Script の download.php における特定の拡張子を伴う Web 文書ルート配下のファイルのソースを読み取られる脆弱性 - CVE-2007-0620 2012-12-20 18:19 2007-01-31 Show GitHub Exploit DB Packet Storm
230763 7.8 危険 Zenphoto - zenphoto の zen/template-functions.php におけるディレクトリトラバーサルの脆弱性 - CVE-2007-0616 2012-12-20 18:19 2007-01-31 Show GitHub Exploit DB Packet Storm
230764 4.3 警告 W-Agora - Web-Agora におけるアプリケーションのパス情報を取得される脆弱性 - CVE-2007-0607 2012-12-20 18:19 2007-03-20 Show GitHub Exploit DB Packet Storm
230765 5 警告 W-Agora - w-agora における重要な情報を取得される脆弱性 - CVE-2007-0606 2012-12-20 18:19 2007-03-21 Show GitHub Exploit DB Packet Storm
230766 6.8 警告 シックス・アパート株式会社 - Movable Type におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-0604 2012-12-20 18:19 2007-01-30 Show GitHub Exploit DB Packet Storm
230767 6.9 警告 トレンドマイクロ - Linux 用の Trend Micro VirusWall におけるバッファオーバーフローの脆弱性 - CVE-2007-0602 2012-12-20 18:19 2007-01-30 Show GitHub Exploit DB Packet Storm
230768 5 警告 siteman - Siteman におけるパスワードハッシュを含むデータベースをダウンロードされる脆弱性 - CVE-2007-0594 2012-12-20 18:19 2007-01-30 Show GitHub Exploit DB Packet Storm
230769 5 警告 siteman - Siteman におけるパスワードハッシュを含むデータベースをダウンロードされる脆弱性 - CVE-2007-0593 2012-12-20 18:19 2007-01-30 Show GitHub Exploit DB Packet Storm
230770 7.5 危険 vu le an - VirtualPath の configure.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-0591 2012-12-20 18:19 2007-01-30 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 18, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
197801 8.8 HIGH
Network
ui airos We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilities found on AirMax AirOS v6.2.0 and prior TI, XW and XM boards, according to the… CWE-352
 Origin Validation Error
CVE-2020-8168 2024-11-21 14:38 2020-05-27 Show GitHub Exploit DB Packet Storm
197802 5.3 MEDIUM
Network
opensuse
debian
open_build_service
debian_linux
a Improper Access Control vulnerability in of Open Build Service allows remote attackers to read files of an OBS package where the sourceaccess/access is disabled This issue affects: Open Build Servi… - CVE-2020-8021 2024-11-21 14:38 2020-05-20 Show GitHub Exploit DB Packet Storm
197803 9.8 CRITICAL
Network
jenzabar internet_campus_solution Jenzabar JICS (aka Internet Campus Solution) before 9.0.1 Patch 3, 9.1 before 9.1.2 Patch 2, and 9.2 before 9.2.2 Patch 8 has session cookies that are a deterministic function of the username. There … CWE-384
 Session Fixation
CVE-2020-8434 2024-11-21 14:38 2020-05-19 Show GitHub Exploit DB Packet Storm
197804 6.1 MEDIUM
Network
horde groupware
gollem
Gollem before 3.0.13, as used in Horde Groupware Webmail Edition 5.2.22 and other products, is affected by a reflected Cross-Site Scripting (XSS) vulnerability via the HTTP GET dir parameter in the b… CWE-79
Cross-site Scripting
CVE-2020-8034 2024-11-21 14:38 2020-05-19 Show GitHub Exploit DB Packet Storm
197805 6.1 MEDIUM
Network
horde groupware The image view functionality in Horde Groupware Webmail Edition before 5.2.22 is affected by a stored Cross-Site Scripting (XSS) vulnerability via an SVG image upload containing a JavaScript payload.… CWE-79
Cross-site Scripting
CVE-2020-8035 2024-11-21 14:38 2020-05-19 Show GitHub Exploit DB Packet Storm
197806 9.8 CRITICAL
Network
logkitty_project logkitty Lack of output sanitization allowed an attack to execute arbitrary shell commands via the logkitty npm package before version 0.7.1. CWE-94
Code Injection
CVE-2020-8149 2024-11-21 14:38 2020-05-16 Show GitHub Exploit DB Packet Storm
197807 7.5 HIGH
Network
bitdefender engines Improper Input Validation vulnerability in the cevakrnl.rv0 module as used in the Bitdefender Engines allows an attacker to trigger a denial of service while scanning a specially-crafted sample. This… CWE-20
 Improper Input Validation 
CVE-2020-8100 2024-11-21 14:38 2020-05-15 Show GitHub Exploit DB Packet Storm
197808 6.1 MEDIUM
Network
opensuse
debian
open_build_service
debian_linux
A Improper Neutralization of Input During Web Page Generation vulnerability in open-build-service allows remote attackers to store arbitrary JS code to cause XSS. This issue affects: openSUSE open-bu… - CVE-2020-8020 2024-11-21 14:38 2020-05-14 Show GitHub Exploit DB Packet Storm
197809 9.8 CRITICAL
Network
rubyonrails
debian
actionpack_page-caching
debian_linux
There is a vulnerability in actionpack_page-caching gem < v1.2.1 that allows an attacker to write arbitrary files to a web server, potentially resulting in remote code execution if the attacker can w… CWE-22
Path Traversal
CVE-2020-8159 2024-11-21 14:38 2020-05-12 Show GitHub Exploit DB Packet Storm
197810 7.0 HIGH
Network
nextcloud
fedoraproject
mail
fedora
A missing verification of the TLS host in Nextcloud Mail 1.1.3 allowed a man in the middle attack. CWE-295
Improper Certificate Validation 
CVE-2020-8156 2024-11-21 14:38 2020-05-12 Show GitHub Exploit DB Packet Storm