Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 7, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
248541 4.3 警告 dotnetindex - ActiveNews Manager におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-6096 2012-06-26 15:37 2006-11-24 Show GitHub Exploit DB Packet Storm
248542 7.5 危険 dotnetindex - ActiveNews Manager における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2006-6095 2012-06-26 15:37 2006-11-24 Show GitHub Exploit DB Packet Storm
248543 7.5 危険 dotnetindex - ActiveNews Manager における SQL インジェクションの脆弱性 - CVE-2006-6094 2012-06-26 15:37 2006-11-24 Show GitHub Exploit DB Packet Storm
248544 7.5 危険 20 20 applications - 20/20 Auto Gallery の vehiclelistings.asp における SQL インジェクションの脆弱性 - CVE-2006-6092 2012-06-26 15:37 2006-11-24 Show GitHub Exploit DB Packet Storm
248545 4.3 警告 grimbb - Grim Pirate GrimBB におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-6091 2012-06-26 15:37 2006-11-24 Show GitHub Exploit DB Packet Storm
248546 7.5 危険 baalasp - BaalAsp フォーラムにおける SQL インジェクションの脆弱性 - CVE-2006-6090 2012-06-26 15:37 2006-11-24 Show GitHub Exploit DB Packet Storm
248547 4.3 警告 baalasp - BaalAsp フォーラムの addpost1.asp におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-6089 2012-06-26 15:37 2006-11-24 Show GitHub Exploit DB Packet Storm
248548 4.3 警告 blue-collar productions - BlueCollar i-Gallery におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-6088 2012-06-26 15:37 2006-11-24 Show GitHub Exploit DB Packet Storm
248549 5.1 警告 e-ark - e-Ark の src/ark_inc.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2006-6086 2012-06-26 15:37 2006-11-24 Show GitHub Exploit DB Packet Storm
248550 4.3 警告 creascripts - CreaScripts Creadirectory におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-6082 2012-06-26 15:37 2006-11-24 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 7, 2026, 4:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
210471 7.5 HIGH
Network
online_shopping_alphaware_project online_shopping_alphaware The id paramater in Online Shopping Alphaware 1.0 has been discovered to be vulnerable to an Error-Based blind SQL injection in the /alphaware/details.php path. This allows an attacker to retrieve al… CWE-89
SQL Injection
CVE-2020-25362 2024-11-21 14:17 2021-06-3 Show GitHub Exploit DB Packet Storm
210472 6.5 MEDIUM
Network
online_examination_system_project online_examination_system Projectworlds Online Examination System 1.0 is vulnerable to CSRF, which allows a remote attacker to delete the existing user. CWE-352
 Origin Validation Error
CVE-2020-25411 2024-11-21 14:17 2021-05-24 Show GitHub Exploit DB Packet Storm
210473 9.8 CRITICAL
Network
college_management_system_project college_management_system Projectsworlds College Management System Php 1.0 is vulnerable to SQL injection issues over multiple parameters. CWE-89
SQL Injection
CVE-2020-25409 2024-11-21 14:17 2021-05-24 Show GitHub Exploit DB Packet Storm
210474 6.5 MEDIUM
Network
college_management_system_project college_management_system A Cross-Site Request Forgery (CSRF) vulnerability exists in ProjectWorlds College Management System Php 1.0 that allows a remote attacker to modify, delete, or make a new entry of the student, facult… CWE-352
 Origin Validation Error
CVE-2020-25408 2024-11-21 14:17 2021-05-24 Show GitHub Exploit DB Packet Storm
210475 7.5 HIGH
Network
siemens simatic_net_cp_343-1_advanced_firmware
simatic_net_cp_343-1_lean_firmware
simatic_net_cp_343-1_standard_firmware
A vulnerability has been identified in SIMATIC NET CP 343-1 Advanced (incl. SIPLUS variants) (All versions), SIMATIC NET CP 343-1 Lean (incl. SIPLUS variants) (All versions), SIMATIC NET CP 343-1 Sta… - CVE-2020-25242 2024-11-21 14:17 2021-05-12 Show GitHub Exploit DB Packet Storm
210476 8.4 HIGH
Local
siemens logo\!_soft_comfort A vulnerability has been identified in LOGO! Soft Comfort (All versions < V8.4). The software insecurely loads libraries which makes it vulnerable to DLL hijacking. Successful exploitation by a local… CWE-427
 Uncontrolled Search Path Element
CVE-2020-25244 2024-11-21 14:17 2021-04-23 Show GitHub Exploit DB Packet Storm
210477 5.1 MEDIUM
Local
siemens logo\!_soft_comfort A vulnerability has been identified in LOGO! Soft Comfort (All versions < V8.4). A zip slip vulnerability could be triggered while importing a compromised project file to the affected software. Chain… - CVE-2020-25243 2024-11-21 14:17 2021-04-23 Show GitHub Exploit DB Packet Storm
210478 9.8 CRITICAL
Network
grandstream grp2612_firmware
grp2612p_firmware
grp2612w_firmware
grp2613_firmware
grp2614_firmware
grp2615_firmware
grp2616_firmware
Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allow Authentication Bypass in its administrative web interface. CWE-306
Missing Authentication for Critical Function
CVE-2020-25218 2024-11-21 14:17 2021-03-30 Show GitHub Exploit DB Packet Storm
210479 7.2 HIGH
Network
grandstream grp2612_firmware
grp2612p_firmware
grp2612w_firmware
grp2613_firmware
grp2614_firmware
grp2615_firmware
grp2616_firmware
Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allows Command Injection as root in its administrative web interface. CWE-77
Command Injection
CVE-2020-25217 2024-11-21 14:17 2021-03-30 Show GitHub Exploit DB Packet Storm
210480 8.6 HIGH
Network
squid-cache
debian
fedoraproject
netapp
squid
debian_linux
fedora
cloud_manager
An issue was discovered in Squid through 4.13 and 5.x through 5.0.4. Due to improper input validation, it allows a trusted client to perform HTTP Request Smuggling and access services otherwise forbi… CWE-20
CWE-444
 Improper Input Validation 
HTTP Request Smuggling
CVE-2020-25097 2024-11-21 14:17 2021-03-19 Show GitHub Exploit DB Packet Storm