Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 18, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
230791 5 警告 tuan do - Tuan Do Uploader における管理者パスワードハッシュを取得される脆弱性 - CVE-2007-0532 2012-12-20 18:19 2007-01-25 Show GitHub Exploit DB Packet Storm
230792 6.8 警告 WebsiteBaker Org - Website Baker の class.login.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-0527 2012-12-20 18:19 2007-01-25 Show GitHub Exploit DB Packet Storm
230793 3.3 注意 sony ericsson - Sony Ericsson K700i および W810i 電話機におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2007-0521 2012-12-20 18:19 2007-01-25 Show GitHub Exploit DB Packet Storm
230794 7.5 危険 unique ads - UDS の banner.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-0520 2012-12-20 18:19 2007-01-25 Show GitHub Exploit DB Packet Storm
230795 3.5 注意 xmb software - XMB U2U Instant Messenger の memcp.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-0519 2012-12-20 18:19 2007-01-25 Show GitHub Exploit DB Packet Storm
230796 7.5 危険 Scriptsez.net - Scriptsez Smart PHP Subscriber におけるエンコードされたパスワードを取得される脆弱性 - CVE-2007-0518 2012-12-20 18:19 2007-01-25 Show GitHub Exploit DB Packet Storm
230797 7.5 危険 Scriptsez.net - Scriptsez Random PHP Quote におけるパスワード情報を取得される脆弱性 - CVE-2007-0517 2012-12-20 18:19 2007-01-25 Show GitHub Exploit DB Packet Storm
230798 4.9 警告 yana framework - Yana Framework における任意のゲストブックプロファイルを変更される脆弱性 CWE-noinfo
情報不足
CVE-2007-0516 2012-12-20 18:19 2007-01-25 Show GitHub Exploit DB Packet Storm
230799 6.8 警告 phpxmldom - phpXD における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-0511 2012-12-20 18:19 2007-01-25 Show GitHub Exploit DB Packet Storm
230800 10 危険 vote pro - Vote! Pro の poll_frame.php における任意の PHP コードを実行される脆弱性 - CVE-2007-0504 2012-12-20 18:19 2007-01-25 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 18, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
197811 5.4 MEDIUM
Network
nextcloud nextcloud_server An outdated 3rd party library in the Files PDF viewer for Nextcloud Server 18.0.2 caused a Cross-site scripting vulnerability when opening a malicious PDF. CWE-79
Cross-site Scripting
CVE-2020-8155 2024-11-21 14:38 2020-05-12 Show GitHub Exploit DB Packet Storm
197812 7.7 HIGH
Network
nextcloud nextcloud_server An Insecure direct object reference vulnerability in Nextcloud Server 18.0.2 allowed an attacker to remote wipe devices of other users when sending a malicious request directly to the endpoint. CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2020-8154 2024-11-21 14:38 2020-05-12 Show GitHub Exploit DB Packet Storm
197813 8.1 HIGH
Network
nextcloud
fedoraproject
group_folders
fedora
Improper access control in Groupfolders app 4.0.3 allowed to delete hidden directories when when renaming an accessible item to the same name. CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2020-8153 2024-11-21 14:38 2020-05-12 Show GitHub Exploit DB Packet Storm
197814 7.5 HIGH
Network
rubyonrails
fedoraproject
active_resource
fedora
There is a possible information disclosure issue in Active Resource <v5.1.1 that could allow an attacker to create specially crafted requests to access data in an unexpected way and possibly leak inf… CWE-863
 Incorrect Authorization
CVE-2020-8151 2024-11-21 14:38 2020-05-12 Show GitHub Exploit DB Packet Storm
197815 5.3 MEDIUM
Network
mongodb mongodb Improper serialization of internal state in the authorization subsystem in MongoDB Server's authorization subsystem permits a user with valid credentials to bypass IP whitelisting protection mechani… CWE-863
 Incorrect Authorization
CVE-2020-7921 2024-11-21 14:38 2020-05-7 Show GitHub Exploit DB Packet Storm
197816 6.1 MEDIUM
Network
commscope ruckus_zoneflex_r500_firmware Ruckus R500 3.4.2.0.384 devices allow XSS via the index.asp Device Name field. CWE-79
Cross-site Scripting
CVE-2020-8033 2024-11-21 14:38 2020-05-6 Show GitHub Exploit DB Packet Storm
197817 8.1 HIGH
Network
commscope ruckus_zoneflex_r500_firmware A CSRF issue in login.asp on Ruckus R500 3.4.2.0.384 devices allows remote attackers to access the panel or conduct SSRF attacks. CWE-352
 Origin Validation Error
CVE-2020-7983 2024-11-21 14:38 2020-05-6 Show GitHub Exploit DB Packet Storm
197818 7.8 HIGH
Local
suse linux_enterprise_desktop A Incorrect Default Permissions vulnerability in the SLES15-SP1-CHOST-BYOS and SLES15-SP1-CAP-Deployment-BYOS images of SUSE Linux Enterprise Server 15 SP1 allows local attackers with the UID 1000 to… CWE-276
Incorrect Default Permissions 
CVE-2020-8018 2024-11-21 14:38 2020-05-4 Show GitHub Exploit DB Packet Storm
197819 6.8 MEDIUM
Physics
ui unifi_cloud_key_gen2_firmware
unifi_cloud_key_gen2_plus_firmware
UniFi Cloud Key firmware <= v1.1.10 for Cloud Key gen2 and Cloud Key gen2 Plus contains a vulnerability that allows unrestricted root access through the serial interface (UART). NVD-CWE-noinfo
CVE-2020-8157 2024-11-21 14:38 2020-05-3 Show GitHub Exploit DB Packet Storm
197820 7.8 HIGH
Local
abb 800xa_information_management Insufficient protection of the inter-process communication functions in ABB System 800xA Information Management (all published versions) enables an attacker authenticated on the local system to injec… NVD-CWE-Other
CVE-2020-8489 2024-11-21 14:38 2020-04-29 Show GitHub Exploit DB Packet Storm