Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 27, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
231801 7.5 危険 xigla - Absolute Image Gallery の gallery.asp における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-1469 2012-12-20 18:19 2007-03-16 Show GitHub Exploit DB Packet Storm
231802 6.8 警告 webcreator - WebCreator における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-1459 2012-12-20 18:19 2007-03-14 Show GitHub Exploit DB Packet Storm
231803 7.5 危険 PHPNUKE - PHP-Nuke の mainfile.php における SQL インジェクションの脆弱性 - CVE-2007-1450 2012-12-20 18:19 2007-03-14 Show GitHub Exploit DB Packet Storm
231804 4.3 警告 PHPNUKE - PHP-Nuke の mainfile.php におけるディレクトリトラバーサルの脆弱性 - CVE-2007-1449 2012-12-20 18:19 2007-03-14 Show GitHub Exploit DB Packet Storm
231805 4.3 警告 woltlab - wBB および Burning Board Lite の register.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-1443 2012-12-20 18:19 2007-03-13 Show GitHub Exploit DB Packet Storm
231806 4.3 警告 BlackBerry - RIM BlackBerry 8100 上で稼動している 4thPass ブラウザにおけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2007-1441 2012-12-20 18:19 2007-03-13 Show GitHub Exploit DB Packet Storm
231807 7.5 危険 x-ice - X-Ice News System の devami.asp における SQL インジェクションの脆弱性 - CVE-2007-1438 2012-12-20 18:19 2007-03-13 Show GitHub Exploit DB Packet Storm
231808 7.5 危険 triexa - Triexa SonicMailer Pro の index.php における SQL インジェクションの脆弱性 - CVE-2007-1425 2012-12-20 18:19 2007-03-12 Show GitHub Exploit DB Packet Storm
231809 7.5 危険 softnews media group - Softnews Media Group DataLife Engine における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-1424 2012-12-20 18:19 2007-03-12 Show GitHub Exploit DB Packet Storm
231810 9.3 危険 work system e-commerce - WORK system e-commerce における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-1423 2012-12-20 18:19 2007-03-12 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 28, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
211771 2.3 LOW
Local
hms-networks ewon_flexy_firmware
ewon_cosy_firmware
All version of Ewon Flexy and Cosy prior to 14.1 use wildcards such as (*) under which domains can request resources. An attacker with local access and high privileges could inject scripts into the C… NVD-CWE-Other
CVE-2020-16230 2024-11-21 14:06 2020-09-19 Show GitHub Exploit DB Packet Storm
211772 6.5 MEDIUM
Adjacent
philips clinical_collaboration_platform Philips Clinical Collaboration Platform, Versions 12.2.1 and prior. The software does not properly control the allocation and maintenance of a limited resource, thereby enabling an attacker to influe… - CVE-2020-16200 2024-11-21 14:06 2020-09-19 Show GitHub Exploit DB Packet Storm
211773 6.3 MEDIUM
Adjacent
philips clinical_collaboration_platform Philips Clinical Collaboration Platform, Versions 12.2.1 and prior. When an attacker claims to have a given identity, the software does not prove or insufficiently proves the claim is correct. - CVE-2020-16198 2024-11-21 14:06 2020-09-19 Show GitHub Exploit DB Packet Storm
211774 8.6 HIGH
Network
1crm 1crm An issue was discovered in 1CRM System through 8.6.7. An insecure direct object reference to internally stored files allows a remote attacker to access various sensitive information via an unauthenti… CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2020-15958 2024-11-21 14:06 2020-09-19 Show GitHub Exploit DB Packet Storm
211775 6.5 MEDIUM
Network
gradle enterprise An issue was discovered in Gradle Enterprise before 2020.2.4. Because of unrestricted cross-origin requests to read-only data in the Export API, an attacker can access data as a user (for the duratio… CWE-346
 Origin Validation Error
CVE-2020-15773 2024-11-21 14:06 2020-09-19 Show GitHub Exploit DB Packet Storm
211776 8.8 HIGH
Network
gradle enterprise An issue was discovered in Gradle Enterprise 2018.2 - 2020.2.4. The CSRF prevention token is stored in a request cookie that is not annotated as HttpOnly. An attacker with the ability to execute arbi… CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2020-15776 2024-11-21 14:06 2020-09-18 Show GitHub Exploit DB Packet Storm
211777 7.5 HIGH
Network
gradle enterprise An issue was discovered in Gradle Enterprise 2017.1 - 2020.2.4. The /usage page of Gradle Enterprise conveys high level build information such as project names and build counts over time. This page i… CWE-922
 Insecure Storage of Sensitive Information
CVE-2020-15775 2024-11-21 14:06 2020-09-18 Show GitHub Exploit DB Packet Storm
211778 6.8 MEDIUM
Physics
gradle enterprise An issue was discovered in Gradle Enterprise 2018.5 - 2020.2.4. An attacker with physical access to the browser of a user who has recently logged in to Gradle Enterprise and since closed their browse… CWE-613
 Insufficient Session Expiration
CVE-2020-15774 2024-11-21 14:06 2020-09-18 Show GitHub Exploit DB Packet Storm
211779 4.9 MEDIUM
Network
gradle enterprise An issue was discovered in Gradle Enterprise 2018.5 - 2020.2.4. When configuring Gradle Enterprise to integrate with a SAML identity provider, an XML metadata file can be uploaded by an administrator… CWE-611
CWE-918
XXE
Server-Side Request Forgery (SSRF) 
CVE-2020-15772 2024-11-21 14:06 2020-09-18 Show GitHub Exploit DB Packet Storm
211780 7.5 HIGH
Network
gradle enterprise_cache_node
enterprise
An issue was discovered in Gradle Enterprise 2018.2 and Gradle Enterprise Build Cache Node 4.1. Cross-site transmission of cookie containing CSRF token allows remote attacker to bypass CSRF mitigatio… CWE-311
Missing Encryption of Sensitive Data
CVE-2020-15771 2024-11-21 14:06 2020-09-18 Show GitHub Exploit DB Packet Storm