Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 2, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
231081 5 警告 ssl-explorer - SSL-Explorer の fileSystem.do におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2007-5831 2012-12-20 18:33 2007-11-5 Show GitHub Exploit DB Packet Storm
231082 6 警告 シマンテック - Macintosh 用の Symantec AntiVirus などの製品の Disk Mount スキャナにおける root 権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2007-5829 2012-12-20 18:33 2007-11-1 Show GitHub Exploit DB Packet Storm
231083 7.5 危険 scribe - Ben Ng Scribe の forum.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2007-5823 2012-12-20 18:33 2007-11-5 Show GitHub Exploit DB Packet Storm
231084 7.5 危険 scribe - Ben Ng Scribe の forum.php における regged/ 配下の特定のファイルへ任意の PHP コードを挿入される脆弱性 CWE-94
コード・インジェクション
CVE-2007-5822 2012-12-20 18:33 2007-11-5 Show GitHub Exploit DB Packet Storm
231085 7.6 危険 sblog - sBlog の blocks_edit_do.php におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2007-5818 2012-12-20 18:33 2007-11-5 Show GitHub Exploit DB Packet Storm
231086 10 危険 SonicWALL - SonicWall SSL-VPN 200 および SSL-VPN 2000/4000 の WebCacheCleaner ActiveX コントロールにおける絶対パストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2007-5815 2012-12-20 18:33 2007-11-5 Show GitHub Exploit DB Packet Storm
231087 9.3 危険 SonicWALL - SonicWall SSL-VPN NetExtender NELaunchCtrl ActiveX コントロールにおけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2007-5814 2012-12-20 18:33 2007-11-5 Show GitHub Exploit DB Packet Storm
231088 6.8 警告 ssreader - SSReader の Ultra Star Reader ActiveX コントロールにおけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2007-5807 2012-12-20 18:33 2007-11-5 Show GitHub Exploit DB Packet Storm
231089 7.5 危険 work system e-commerce - WORK system e-commerce における脆弱性 CWE-noinfo
情報不足
CVE-2007-5801 2012-12-20 18:33 2007-11-2 Show GitHub Exploit DB Packet Storm
231090 6.8 警告 tom willmot - WordPress 用の BackUpWordPress プラグインにおける PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2007-5800 2012-12-20 18:33 2007-11-2 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 2, 2026, 4:18 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
200281 7.3 HIGH
Adjacent
mi miui_firmware An issue was discovered on Xiaomi MIUI V11.0.5.0.QFAEUXM devices. In the Web resources of GetApps(com.xiaomi.mipicks), the parameters passed in are read and executed. After reading the resource files… NVD-CWE-noinfo
CVE-2020-9531 2024-11-21 14:40 2020-03-7 Show GitHub Exploit DB Packet Storm
200282 7.8 HIGH
Local
redsoftware pdfescape An untrusted search path vulnerability in the installer of PDFescape Desktop version 4.0.22 and earlier allows an attacker to gain privileges and execute code via DLL hijacking. CWE-426
 Untrusted Search Path
CVE-2020-9418 2024-11-21 14:40 2020-03-6 Show GitHub Exploit DB Packet Storm
200283 7.5 HIGH
Network
d-link dsl-2640b_firmware An issue was discovered on D-Link DSL-2640B E1 EU_1.01 devices. The administrative interface doesn't perform authentication checks for a firmware-update POST request. Any attacker that can access the… CWE-306
Missing Authentication for Critical Function
CVE-2020-9544 2024-11-21 14:40 2020-03-6 Show GitHub Exploit DB Packet Storm
200284 8.8 HIGH
Network
djangoproject
debian
fedoraproject
netapp
canonical
django
debian_linux
fedora
steelstore_cloud_integrated_storage
ubuntu_linux
Django 1.11 before 1.11.29, 2.2 before 2.2.11, and 3.0 before 3.0.4 allows SQL Injection if untrusted data is used as a tolerance parameter in GIS functions and aggregates on Oracle. By passing a sui… CWE-89
SQL Injection
CVE-2020-9402 2024-11-21 14:40 2020-03-6 Show GitHub Exploit DB Packet Storm
200285 9.8 CRITICAL
Network
whmcssmarters web_tv_player IPTV Smarters WEB TV PLAYER through 2020-02-22 allows attackers to execute OS commands by uploading a script. CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2020-9380 2024-11-21 14:40 2020-03-5 Show GitHub Exploit DB Packet Storm
200286 9.1 CRITICAL
Network
humaxdigital hga12r-02_firmware HUMAX HGA12R-02 BRGCAA 1.1.53 devices allow Session Hijacking. CWE-384
 Session Fixation
CVE-2020-9370 2024-11-21 14:40 2020-03-5 Show GitHub Exploit DB Packet Storm
200287 9.8 CRITICAL
Network
rubetek smarthome_firmware Rubetek SmartHome 2020 devices use unencrypted 433 MHz communication between controllers and beacons, allowing an attacker to sniff and spoof beacon requests remotely. CWE-319
Cleartext Transmission of Sensitive Information
CVE-2020-9550 2024-11-21 14:40 2020-03-5 Show GitHub Exploit DB Packet Storm
200288 9.8 CRITICAL
Network
humaxdigital hga12r-02_firmware An issue was discovered on HUMAX HGA12R-02 BRGCAA 1.1.53 devices. A vulnerability in the authentication functionality in the web-based interface could allow an unauthenticated remote attacker to capt… CWE-319
Cleartext Transmission of Sensitive Information
CVE-2020-9477 2024-11-21 14:40 2020-03-5 Show GitHub Exploit DB Packet Storm
200289 7.5 HIGH
Network
commscope arris_tg1692a_firmware ARRIS TG1692A devices allow remote attackers to discover the administrator login name and password by reading the /login page and performing base64 decoding. CWE-326
Inadequate Encryption Strength
CVE-2020-9476 2024-11-21 14:40 2020-03-5 Show GitHub Exploit DB Packet Storm
200290 7.8 HIGH
Local
codepeople appointment_booking_calendar The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking form to be any formula, which then could be exported via t… CWE-1236
 Improper Neutralization of Formula Elements in a CSV File
CVE-2020-9372 2024-11-21 14:40 2020-03-5 Show GitHub Exploit DB Packet Storm