Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 7, 2026, 2 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
232161 6 警告 WordPress.org - WordPress のデフォルトテーマの functions.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-3238 2012-12-20 18:19 2007-06-14 Show GitHub Exploit DB Packet Storm
232162 6.8 警告 XOOPS - XOOPS 用の TinyContent モジュールにおける PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-3237 2012-12-20 18:19 2007-06-12 Show GitHub Exploit DB Packet Storm
232163 7.5 危険 XOOPS - XOOPS 用の Horoscope モジュールにおける PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-3236 2012-12-20 18:19 2007-06-14 Show GitHub Exploit DB Packet Storm
232164 5 警告 tec-it - TEC-IT TBarCode OCX ActiveX コントロール における任意のファイルを上書きされる脆弱性 - CVE-2007-3233 2012-12-20 18:19 2007-06-14 Show GitHub Exploit DB Packet Storm
232165 6.8 警告 simian systems inc - Idan Sofer PHP::HTML の phphtml.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-3230 2012-12-20 18:19 2007-06-14 Show GitHub Exploit DB Packet Storm
232166 6.8 警告 singapore - Singapore Gallery の index.php における重要な情報を取得される脆弱性 - CVE-2007-3229 2012-12-20 18:19 2007-06-14 Show GitHub Exploit DB Packet Storm
232167 6.8 警告 simian systems inc - Sitellite CMS における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-3228 2012-12-20 18:19 2007-06-14 Show GitHub Exploit DB Packet Storm
232168 4.3 警告 Ruby on Rails project - Ruby on Rails の to_json 関数におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-3227 2012-12-20 18:19 2007-06-14 Show GitHub Exploit DB Packet Storm
232169 6.4 警告 サン・マイクロシステムズ - slapd における特定のデータを変更される脆弱性 - CVE-2007-3225 2012-12-20 18:19 2007-06-13 Show GitHub Exploit DB Packet Storm
232170 5 警告 サン・マイクロシステムズ - slapd におけるエントリの属性の存在を特定される脆弱性 - CVE-2007-3224 2012-12-20 18:19 2007-06-13 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 7, 2026, 4:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
211731 8.8 HIGH
Network
wwbn avideo The import.json.php file before 8.9 for Avideo is vulnerable to a File Deletion vulnerability. This allows the deletion of configuration.php, which leads to certain privilege checks not being in plac… CWE-862
 Missing Authorization
CVE-2020-23489 2024-11-21 14:13 2020-11-17 Show GitHub Exploit DB Packet Storm
211732 8.1 HIGH
Network
microweber microweber Microweber 1.1.18 is affected by insufficient session expiration. When changing passwords, both sessions for when a user changes email and old sessions in any other browser or device, the session doe… CWE-613
 Insufficient Session Expiration
CVE-2020-23140 2024-11-21 14:13 2020-11-10 Show GitHub Exploit DB Packet Storm
211733 5.5 MEDIUM
Local
microweber microweber Microweber 1.1.18 is affected by broken authentication and session management. Local session hijacking may occur, which could result in unauthorized access to system data or functionality, or a compl… CWE-287
Improper Authentication
CVE-2020-23139 2024-11-21 14:13 2020-11-10 Show GitHub Exploit DB Packet Storm
211734 9.8 CRITICAL
Network
microweber microweber An unrestricted file upload vulnerability was discovered in the Microweber 1.1.18 admin account page. An attacker can upload PHP code or any extension (eg- .exe) to the web server by providing image … CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2020-23138 2024-11-21 14:13 2020-11-10 Show GitHub Exploit DB Packet Storm
211735 5.5 MEDIUM
Local
microweber microweber Microweber v1.1.18 is affected by no session expiry after log-out. CWE-613
 Insufficient Session Expiration
CVE-2020-23136 2024-11-21 14:13 2020-11-10 Show GitHub Exploit DB Packet Storm
211736 9.8 CRITICAL
Network
jomsocial jomsocial JomSocial (Joomla Social Network Extention) 4.7.6 allows CSV injection via a customer's profile. CWE-1236
 Improper Neutralization of Formula Elements in a CSV File
CVE-2020-22274 2024-11-21 14:13 2020-11-5 Show GitHub Exploit DB Packet Storm
211737 6.5 MEDIUM
Network
creativeitem neoflex_video_subscription_system Neoflex Video Subscription System Version 2.0 is affected by CSRF which allows the Website's Settings to be changed (such as Payment Settings) CWE-352
 Origin Validation Error
CVE-2020-22273 2024-11-21 14:13 2020-11-5 Show GitHub Exploit DB Packet Storm
211738 8.8 HIGH
Network
phpmyadmin phpmyadmin phpMyAdmin through 5.0.2 allows CSV injection via Export Section. NOTE: the vendor disputes this because "the CSV file is accurately generated based on the database contents. CWE-1236
 Improper Neutralization of Formula Elements in a CSV File
CVE-2020-22278 2024-11-21 14:13 2020-11-5 Show GitHub Exploit DB Packet Storm
211739 8.0 HIGH
Network
codection import_and_export_users_and_customers Import and export users and customers WordPress Plugin through 1.15.5.11 allows CSV injection via a customer's profile. CWE-1236
 Improper Neutralization of Formula Elements in a CSV File
CVE-2020-22277 2024-11-21 14:13 2020-11-5 Show GitHub Exploit DB Packet Storm
211740 9.8 CRITICAL
Network
weformspro weforms WeForms Wordpress Plugin 1.4.7 allows CSV injection via a form's entry. CWE-1236
 Improper Neutralization of Formula Elements in a CSV File
CVE-2020-22276 2024-11-21 14:13 2020-11-5 Show GitHub Exploit DB Packet Storm