Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 3, 2026, 6:08 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
231361 6.8 警告 phphelpdesk - phphelpdesk の index.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2007-5915 2012-12-20 18:33 2007-11-9 Show GitHub Exploit DB Packet Storm
231362 6.8 警告 viewpoint - Viewpoint Media Player の AxMetaStream.dll におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2007-5911 2012-12-20 18:33 2007-11-9 Show GitHub Exploit DB Packet Storm
231363 4.7 警告 Xen プロジェクト - Xen におけるサービス運用妨害 (DoS) の脆弱性 CWE-DesignError
CVE-2007-5906 2012-12-20 18:33 2007-11-9 Show GitHub Exploit DB Packet Storm
231364 10 危険 ssreader - SSReader の pdg2.dll ActiveX コントロールにおけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2007-5892 2012-12-20 18:33 2007-11-7 Show GitHub Exploit DB Packet Storm
231365 6.8 警告 scwiki - scWiki の includes/common.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2007-5843 2012-12-20 18:33 2007-11-6 Show GitHub Exploit DB Packet Storm
231366 6.8 警告 vortex portal - Vortex Portal における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2007-5842 2012-12-20 18:33 2007-11-6 Show GitHub Exploit DB Packet Storm
231367 6.8 警告 SyndeoCMS - Fred Stuurman SyndeoCMS の starnet/themes/c-sky/main.inc.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2007-5840 2012-12-20 18:33 2007-11-5 Show GitHub Exploit DB Packet Storm
231368 7.2 危険 シマンテック - Symantec Altiris Deployment Solution の Aclient におけるローカルのシステム権限を取得される脆弱性 CWE-16
環境設定
CVE-2007-5838 2012-12-20 18:33 2007-10-30 Show GitHub Exploit DB Packet Storm
231369 6.8 警告 yarssr - yarssr の GUI.pm における任意のコマンドを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2007-5837 2012-12-20 18:33 2007-11-5 Show GitHub Exploit DB Packet Storm
231370 7.5 危険 ssl-explorer - SSL-Explorer の selectLanguage.do における HTTP トランザクション内にデータを挿入される脆弱性 CWE-20
不適切な入力確認
CVE-2007-5832 2012-12-20 18:33 2007-08-3 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 3, 2026, 4:18 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
210401 5.4 MEDIUM
Network
catalyst mahara Catalyst IT Ltd Mahara CMS v19.10.2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component groupfiles.php via the Number (Nombre) and Description (Descripción)… CWE-79
Cross-site Scripting
CVE-2020-23052 2024-11-21 14:13 2021-10-23 Show GitHub Exploit DB Packet Storm
210402 6.1 MEDIUM
Network
user_registration_\&_login_and_user_management_system_with_admin_panel_project user_registration_\&_login_and_user_management_system_with_admin_panel Phpgurukul User Registration & User Management System v2.0 was discovered to contain multiple stored cross-site scripting (XSS) vulnerabilities via the firstname and lastname parameters of the regist… CWE-79
Cross-site Scripting
CVE-2020-23051 2024-11-21 14:13 2021-10-23 Show GitHub Exploit DB Packet Storm
210403 8.0 HIGH
Network
taotesting tao_assessment_platform TAO Open Source Assessment Platform v3.3.0 RC02 was discovered to contain a HTML injection vulnerability in the userFirstName parameter of the user account input field. This vulnerability allows atta… CWE-74
Injection
CVE-2020-23050 2024-11-21 14:13 2021-10-23 Show GitHub Exploit DB Packet Storm
210404 5.4 MEDIUM
Network
fork-cms fork_cms Fork CMS Content Management System v5.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the `Displayname` field when using the `Add`, `Edit` or `Register' functions. This vu… CWE-79
Cross-site Scripting
CVE-2020-23049 2024-11-21 14:13 2021-10-23 Show GitHub Exploit DB Packet Storm
210405 6.1 MEDIUM
Network
seeddms seeddms SeedDMS Content Management System v6.0.7 contains a persistent cross-site scripting (XSS) vulnerability in the component AddEvent.php via the name and comment parameters. CWE-79
Cross-site Scripting
CVE-2020-23048 2024-11-21 14:13 2021-10-23 Show GitHub Exploit DB Packet Storm
210406 6.1 MEDIUM
Network
macs_cms_project macs_cms Macrob7 Macs Framework Content Management System - 1.14f was discovered to contain a cross-site scripting (XSS) vulnerability in the search input field of the search module. CWE-79
Cross-site Scripting
CVE-2020-23047 2024-11-21 14:13 2021-10-23 Show GitHub Exploit DB Packet Storm
210407 6.1 MEDIUM
Network
dedecms dedecms DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component tpl.php via the `filename`, `mid`, `userid`, and `templet' parameters. CWE-79
Cross-site Scripting
CVE-2020-23046 2024-11-21 14:13 2021-10-23 Show GitHub Exploit DB Packet Storm
210408 7.2 HIGH
Network
macs_cms_project macs_cms Macrob7 Macs Framework Content Management System - 1.14f was discovered to contain a SQL injection vulnerability via the 'roleId' parameter of the `editRole` and `deletUser` modules. CWE-89
SQL Injection
CVE-2020-23045 2024-11-21 14:13 2021-10-23 Show GitHub Exploit DB Packet Storm
210409 5.4 MEDIUM
Network
dedecms dedecms DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component file_pic_view.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor`… CWE-79
Cross-site Scripting
CVE-2020-23044 2024-11-21 14:13 2021-10-23 Show GitHub Exploit DB Packet Storm
210410 8.8 HIGH
Network
air_sender_project air_sender Tran Tu Air Sender v1.0.2 was discovered to contain an arbitrary file upload vulnerability in the upload module. This vulnerability allows attackers to execute arbitrary code via a crafted file. CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2020-23043 2024-11-21 14:13 2021-10-23 Show GitHub Exploit DB Packet Storm