Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 2, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
230941 7.5 危険 xecms - xeCMS の view.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2007-6508 2012-12-20 18:34 2007-12-21 Show GitHub Exploit DB Packet Storm
230942 10 危険 トレンドマイクロ - Windows 用の Trend Micro ServerProtect における "ファイルシステムの全アクセス権限" を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2007-6507 2012-12-20 18:34 2007-07-27 Show GitHub Exploit DB Packet Storm
230943 4.9 警告 plain black - Plain Black WebGUI における管理アカウントを作成される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2007-6487 2012-12-20 18:34 2007-12-20 Show GitHub Exploit DB Packet Storm
230944 6.8 警告 phprpg - phpRPG の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-6484 2012-12-20 18:34 2007-12-20 Show GitHub Exploit DB Packet Storm
230945 7.8 危険 サン・マイクロシステムズ - Sun Ray Server Software の utdevmgrd におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2007-6482 2012-12-20 18:34 2007-12-18 Show GitHub Exploit DB Packet Storm
230946 6.4 警告 サン・マイクロシステムズ - Sun Ray Server Software の utdevmgrd における任意のディレクトリを削除される脆弱性 CWE-DesignError
CVE-2007-6481 2012-12-20 18:34 2007-12-18 Show GitHub Exploit DB Packet Storm
230947 9.4 危険 サン・マイクロシステムズ - Sun MC の Oracle データベースコンポーネントにおける任意のコードを実行される脆弱性 CWE-DesignError
CVE-2007-6480 2012-12-20 18:34 2007-12-18 Show GitHub Exploit DB Packet Storm
230948 6.8 警告 rosoftengineering - Rosoft Media Player におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2007-6478 2012-12-20 18:34 2007-12-20 Show GitHub Exploit DB Packet Storm
230949 5.8 警告 texas imperial software - Texas Imperial Software WFTPD Pro Explorer におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2007-6473 2012-12-20 18:34 2007-12-20 Show GitHub Exploit DB Packet Storm
230950 7.5 危険 phpmyrealty - PMR における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-6472 2012-12-20 18:34 2007-12-20 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 2, 2026, 4:18 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
209911 7.5 HIGH
Network
moog exvf5c-2_firmware
exvp7c2-3_firmware
Moog EXO Series EXVF5C-2 and EXVP7C2-3 units have a hardcoded credentials vulnerability. This could cause a confidentiality issue when using the FTP, Telnet, or SSH protocols. CWE-798
 Use of Hard-coded Credentials
CVE-2020-24053 2024-11-21 14:14 2020-08-22 Show GitHub Exploit DB Packet Storm
209912 9.1 CRITICAL
Network
moog exvf5c-2_firmware
exvp7c2-3_firmware
Several XML External Entity (XXE) vulnerabilities in the Moog EXO Series EXVF5C-2 and EXVP7C2-3 units allow remote unauthenticated users to read arbitrary files via a crafted Document Type Definition… CWE-611
XXE
CVE-2020-24052 2024-11-21 14:14 2020-08-22 Show GitHub Exploit DB Packet Storm
209913 9.8 CRITICAL
Network
moog exvf5c-2_firmware
exvp7c2-3_firmware
The Moog EXO Series EXVF5C-2 and EXVP7C2-3 units support the ONVIF interoperability IP-based physical security protocol, which requires authentication for some of its operations. It was found that th… CWE-306
Missing Authentication for Critical Function
CVE-2020-24051 2024-11-21 14:14 2020-08-22 Show GitHub Exploit DB Packet Storm
209914 7.5 HIGH
Network
hashicorp vault-ssh-helper HashiCorp vault-ssh-helper up to and including version 0.1.6 incorrectly accepted Vault-issued SSH OTPs for the subnet in which a host's network interface was located, rather than the specific IP add… CWE-20
 Improper Input Validation 
CVE-2020-24359 2024-11-21 14:14 2020-08-21 Show GitHub Exploit DB Packet Storm
209915 9.8 CRITICAL
Network
student_management_system_project student_management_system Kabir Alhasan Student Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Password: (Write Something)". CWE-89
SQL Injection
CVE-2020-23935 2024-11-21 14:14 2020-08-21 Show GitHub Exploit DB Packet Storm
209916 9.8 CRITICAL
Network
phpgurukul vehicle_parking_management_system PHPGurukul Vehicle Parking Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Password: (Write Something)". CWE-89
SQL Injection
CVE-2020-23936 2024-11-21 14:14 2020-08-20 Show GitHub Exploit DB Packet Storm
209917 7.5 HIGH
Network
icinga
debian
suse
icinga_web_2
debian_linux
package_hub
Icinga Icinga Web2 2.0.0 through 2.6.4, 2.7.4 and 2.8.2 has a Directory Traversal vulnerability which allows an attacker to access arbitrary files that are readable by the process running Icinga Web … CWE-22
Path Traversal
CVE-2020-24368 2024-11-21 14:14 2020-08-20 Show GitHub Exploit DB Packet Storm
209918 7.1 HIGH
Local
linux
canonical
opensuse
oracle
starwindsoftware
linux_kernel
ubuntu_linux
leap
sd-wan_edge
starwind_virtual_san
In the Linux kernel before 5.7.8, fs/nfsd/vfs.c (in the NFS server) can set incorrect permissions on new filesystem objects when the filesystem lacks ACL support, aka CID-22cf8419f131. This occurs be… CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2020-24394 2024-11-21 14:14 2020-08-19 Show GitHub Exploit DB Packet Storm
209919 7.5 HIGH
Network
gunet open_eclass_platform GUnet Open eClass Platform (aka openeclass) before 3.11 might allow remote attackers to read students' submitted assessments because it does not ensure that the web server blocks directory listings, … CWE-200
Information Exposure
CVE-2020-24381 2024-11-21 14:14 2020-08-19 Show GitHub Exploit DB Packet Storm
209920 9.8 CRITICAL
Network
xorux stor2rrd
lpar2rrd
tz.pl on XoruX LPAR2RRD and STOR2RRD 2.70 virtual appliances allows cmd=set&tz=OS command injection via shell metacharacters in a timezone. CWE-78
OS Command 
CVE-2020-24032 2024-11-21 14:14 2020-08-19 Show GitHub Exploit DB Packet Storm