Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 24, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
230791 5 警告 Thomson - Thomson ST 2030 SIP 電話機におけるサービス運用妨害 (DoS) の脆弱性 CWE-DesignError
CVE-2007-4753 2012-12-20 18:33 2007-09-7 Show GitHub Exploit DB Packet Storm
230792 6.8 警告 ppstream - PPStream の PowerPlayer.dll ActiveX コントロールにおけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2007-4748 2012-12-20 18:33 2007-09-6 Show GitHub Exploit DB Packet Storm
230793 9.3 危険 telecom italy - Telecom Italy Alice Messenger の Hp.Revolution.RegistryManager.dll 1 におけるレジストリキーを作成される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2007-4740 2012-12-20 18:33 2007-09-6 Show GitHub Exploit DB Packet Storm
230794 7.5 危険 speedtech - SpeedTech PHP Library における PHP リモートファイルインクルージョンの脆弱性 CWE-20
CWE-94
CVE-2007-4738 2012-12-20 18:33 2007-09-6 Show GitHub Exploit DB Packet Storm
230795 7.5 危険 speedtech - STPHPLibrary における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2007-4737 2012-12-20 18:33 2007-09-6 Show GitHub Exploit DB Packet Storm
230796 10 危険 トレンドマイクロ - Trend Micro ServerProtect の TMReg.dll におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2007-4731 2012-12-20 18:33 2007-09-11 Show GitHub Exploit DB Packet Storm
230797 5 警告 weboddity - Web Oddity におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2007-4726 2012-12-20 18:33 2007-09-5 Show GitHub Exploit DB Packet Storm
230798 7.5 危険 weblogicnet - Weblogicnet における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2007-4715 2012-12-20 18:33 2007-09-5 Show GitHub Exploit DB Packet Storm
230799 7.5 危険 yvora - Yvora の error_view.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-4714 2012-12-20 18:33 2007-09-5 Show GitHub Exploit DB Packet Storm
230800 4.3 警告 roi revolution - Urchin の urchin.cgi におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-4713 2012-12-20 18:33 2007-09-5 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 25, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
198141 7.5 HIGH
Network
argoproj argo_cd As of v1.5.0, the Argo web interface authentication system issued immutable tokens. Authentication tokens, once issued, were usable forever without expiration—there was no refresh or forced re-authen… CWE-384
 Session Fixation
CVE-2020-8826 2024-11-21 14:39 2020-04-9 Show GitHub Exploit DB Packet Storm
198142 5.5 MEDIUM
Local
canonical
netapp
ubuntu_linux
cloud_backup
steelstore_cloud_integrated_storage
solidfire_\&_hci_management_node
aff_8300_firmware
aff_8700_firmware
aff_a220_firmware
aff_a320_firmware
aff_…
The fix for the Linux kernel in Ubuntu 18.04 LTS for CVE-2019-14615 ("The Linux kernel did not properly clear data structures on context switches for certain Intel graphics processors.") was discover… CWE-200
Information Exposure
CVE-2020-8832 2024-11-21 14:39 2020-04-10 Show GitHub Exploit DB Packet Storm
198143 6.5 MEDIUM
Local
linux
canonical
opensuse
linux_kernel
ubuntu_linux
leap
KVM in the Linux kernel on Power8 processors has a conflicting use of HSTATE_HOST_R1 to store r1 state in kvmppc_hv_entry plus in kvmppc_{save,restore}_tm, leading to a stack corruption. Because of t… CWE-362
Race Condition
CVE-2020-8834 2024-11-21 14:39 2020-04-10 Show GitHub Exploit DB Packet Storm
198144 8.8 HIGH
Network
testlink testlink An unrestricted file upload vulnerability in keywordsImport.php in TestLink 1.9.20 allows remote attackers to execute arbitrary code by uploading a file with an executable extension. This allows an a… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2020-8639 2024-11-21 14:39 2020-04-4 Show GitHub Exploit DB Packet Storm
198145 9.8 CRITICAL
Network
testlink testlink A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in planUrgency.php via the urgency parameter. CWE-89
SQL Injection
CVE-2020-8638 2024-11-21 14:39 2020-04-4 Show GitHub Exploit DB Packet Storm
198146 9.8 CRITICAL
Network
testlink testlink A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in dragdroptreenodes.php via the node_id parameter. CWE-89
SQL Injection
CVE-2020-8637 2024-11-21 14:39 2020-04-4 Show GitHub Exploit DB Packet Storm
198147 8.0 HIGH
Adjacent
huawei smartax_ma5600t_firmware
smartax_ma5800_firmware
smartax_ea5800_firmware
There is a buffer overflow vulnerability in some Huawei products. The vulnerability can be exploited by an attacker to perform remote code execution on the affected products when the affected product… CWE-120
Classic Buffer Overflow
CVE-2020-9067 2024-11-21 14:39 2020-04-3 Show GitHub Exploit DB Packet Storm
198148 7.8 HIGH
Local
linux
fedoraproject
canonical
netapp
linux_kernel
fedora
ubuntu_linux
cloud_backup
steelstore_cloud_integrated_storage
solidfire
hci_management_node
a700s_firmware
8300_firmware
8700_firmware
a400_firmware<…
In the Linux kernel 5.5.0 and newer, the bpf verifier (kernel/bpf/verifier.c) did not properly restrict the register bounds for 32-bit operations, leading to out-of-bounds reads and writes in kernel … CWE-125
CWE-787
Out-of-bounds Read
 Out-of-bounds Write
CVE-2020-8835 2024-11-21 14:39 2020-04-3 Show GitHub Exploit DB Packet Storm
198149 6.1 MEDIUM
Network
tiki tikiwiki_cms\/groupware There is an Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in php webpages of Tiki-Wiki Groupware. Tiki-Wiki CMS all versions through 20.0 allows maliciou… CWE-79
Cross-site Scripting
CVE-2020-8966 2024-11-21 14:39 2020-04-2 Show GitHub Exploit DB Packet Storm
198150 5.4 MEDIUM
Network
versiant lynx_customer_service_portal Versiant LYNX Customer Service Portal (CSP), version 3.5.2, is vulnerable to stored cross-site scripting, which could allow a local, authenticated attacker to insert malicious JavaScript that is stor… CWE-79
Cross-site Scripting
CVE-2020-9055 2024-11-21 14:39 2020-03-31 Show GitHub Exploit DB Packet Storm