Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 1, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
230901 4.3 警告 サン・マイクロシステムズ - Sun Java System Web Proxy Server の View URL Database 関数におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-6570 2012-12-20 18:34 2007-12-21 Show GitHub Exploit DB Packet Storm
230902 7.5 危険 xzeroscripts - XZero Community Classifieds の config.inc.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2007-6568 2012-12-20 18:34 2007-12-28 Show GitHub Exploit DB Packet Storm
230903 6.4 警告 xzeroscripts - XZero Community Classifieds の index.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2007-6567 2012-12-20 18:34 2007-12-28 Show GitHub Exploit DB Packet Storm
230904 7.5 危険 xzeroscripts - XZero Community Classifieds の post.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-6566 2012-12-20 18:34 2007-12-28 Show GitHub Exploit DB Packet Storm
230905 5 警告 tcpreen - TCPreen の FD_SET の使用におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2007-6562 2012-12-20 18:34 2007-12-27 Show GitHub Exploit DB Packet Storm
230906 4.3 警告 totalplayer - TotalPlayer におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2007-6558 2012-12-20 18:34 2007-12-27 Show GitHub Exploit DB Packet Storm
230907 7.5 危険 websihirbazi - websihirbazi における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-6556 2012-12-20 18:34 2007-12-27 Show GitHub Exploit DB Packet Storm
230908 7.5 危険 pmos helpdesk - PMOS Help Desk の form.php における任意の PHP コードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2007-6550 2012-12-20 18:34 2007-12-27 Show GitHub Exploit DB Packet Storm
230909 7.5 危険 runcms - RunCMS における脆弱性 CWE-DesignError
CVE-2007-6549 2012-12-20 18:34 2007-12-27 Show GitHub Exploit DB Packet Storm
230910 7.5 危険 runcms - RunCMS における任意の PHP コード挿入される脆弱性 CWE-94
コード・インジェクション
CVE-2007-6548 2012-12-20 18:34 2007-12-27 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 1, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
213601 9.6 CRITICAL
Network
radare
fedoraproject
radare2
fedora
In radare2 before version 4.5.0, malformed PDB file names in the PDB server path cause shell injection. To trigger the problem it's required to open the executable in radare2 and run idpd to trigger … CWE-78
OS Command 
CVE-2020-15121 2024-11-21 14:04 2020-07-21 Show GitHub Exploit DB Packet Storm
213602 6.1 MEDIUM
Network
articatech artica_proxy An issue was discovered in Artica Proxy CE before 4.28.030.418. Reflected XSS exists via these search fields: real time request, System Events, Proxy Events, Proxy Objects, and Firewall objects. CWE-79
Cross-site Scripting
CVE-2020-15053 2024-11-21 14:04 2020-07-21 Show GitHub Exploit DB Packet Storm
213603 7.5 HIGH
Network
articatech artica_proxy An issue was discovered in Artica Proxy CE before 4.28.030.418. SQL Injection exists via the Netmask, Hostname, and Alias fields. CWE-89
SQL Injection
CVE-2020-15052 2024-11-21 14:04 2020-07-21 Show GitHub Exploit DB Packet Storm
213604 9.3 CRITICAL
Network
codecov codecov In codecov (npm package) before version 3.7.1 the upload method has a command injection vulnerability. Clients of the codecov-node library are unlikely to be aware of this, so they might unwittingly … CWE-78
OS Command 
CVE-2020-15123 2024-11-21 14:04 2020-07-21 Show GitHub Exploit DB Packet Storm
213605 5.4 MEDIUM
Network
torchbox wagtail In Wagtail before versions 2.7.4 and 2.9.3, when a form page type is made available to Wagtail editors through the `wagtail.contrib.forms` app, and the page template is built using Django's standard … CWE-79
Cross-site Scripting
CVE-2020-15118 2024-11-21 14:04 2020-07-21 Show GitHub Exploit DB Packet Storm
213606 5.4 MEDIUM
Network
gofiber fiber In Fiber before version 1.12.6, the filename that is given in c.Attachment() (https://docs.gofiber.io/ctx#attachment) is not escaped, and therefore vulnerable for a CRLF injection attack. I.e. an att… CWE-74
Injection
CVE-2020-15111 2024-11-21 14:04 2020-07-21 Show GitHub Exploit DB Packet Storm
213607 7.8 HIGH
Local
asus screenpad2_upgrade_tool AsusScreenXpertServicec.exe and ScreenXpertUpgradeServiceManager.exe in ScreenPad2_Upgrade_Tool.msi V1.0.3 for ASUS PCs with ScreenPad 1.0 (UX450FDX, UX550GDX and UX550GEX) could lead to unsigned cod… CWE-426
 Untrusted Search Path
CVE-2020-15009 2024-11-21 14:04 2020-07-20 Show GitHub Exploit DB Packet Storm
213608 8.1 HIGH
Network
jupyterhub kubespawner In jupyterhub-kubespawner before 0.12, certain usernames will be able to craft particular server names which will grant them access to the default server of other users who have matching usernames. T… CWE-863
 Incorrect Authorization
CVE-2020-15110 2024-11-21 14:04 2020-07-18 Show GitHub Exploit DB Packet Storm
213609 7.1 HIGH
Network
glpi-project glpi In glpi before 9.5.1, there is a SQL injection for all usages of "Clone" feature. This has been fixed in 9.5.1. CWE-89
SQL Injection
CVE-2020-15108 2024-11-21 14:04 2020-07-18 Show GitHub Exploit DB Packet Storm
213610 5.9 MEDIUM
Network
gnome
debian
fedoraproject
canonical
evolution-data-server
debian_linux
fedora
ubuntu_linux
evolution-data-server (eds) through 3.36.3 has a STARTTLS buffering issue that affects SMTP and POP3. When a server sends a "begin TLS" response, eds reads additional data and evaluates it in a TLS c… CWE-74
Injection
CVE-2020-14928 2024-11-21 14:04 2020-07-18 Show GitHub Exploit DB Packet Storm