Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 27, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
250511 7.5 危険 Micronetsoft - MicroNetsoft RV Dealer Website における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-4362 2012-03-27 18:42 2010-12-1 Show GitHub Exploit DB Packet Storm
250512 4.3 警告 jurpo - Jurpopage の url-gateway.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-4361 2012-03-27 18:42 2010-12-1 Show GitHub Exploit DB Packet Storm
250513 7.5 危険 jurpo - Jurpopage の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-4360 2012-03-27 18:42 2010-12-1 Show GitHub Exploit DB Packet Storm
250514 7.5 危険 jurpo - Jurpopage の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-4359 2012-03-27 18:42 2010-12-1 Show GitHub Exploit DB Packet Storm
250515 4.3 警告 mrcgiguy - MCG Guestbook の gb.cgi におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-4358 2012-03-27 18:42 2010-12-1 Show GitHub Exploit DB Packet Storm
250516 7.5 危険 boka - SiteEngine の comments.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-4357 2012-03-27 18:42 2010-12-1 Show GitHub Exploit DB Packet Storm
250517 7.5 危険 site2nite - Site2Nite Big Truck Broker の news_default.asp における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-4356 2012-03-27 18:42 2010-12-1 Show GitHub Exploit DB Packet Storm
250518 3.5 注意 dadabik - DaDaBIK におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-4355 2012-03-27 18:42 2010-12-1 Show GitHub Exploit DB Packet Storm
250519 5.1 警告 MantisBT Group - MantisBT の admin/upgrade_unattended.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2010-4350 2012-03-27 18:42 2010-12-14 Show GitHub Exploit DB Packet Storm
250520 5 警告 MantisBT Group - MantisBT の admin/upgrade_unattended.php における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2010-4349 2012-03-27 18:42 2010-12-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 28, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
209161 9.8 CRITICAL
Network
thinkadmin thinkadmin An insecure unserialize vulnerability was discovered in ThinkAdmin versions 4.x through 6.x in app/admin/controller/api/Update.php and app/wechat/controller/api/Push.php, which may lead to arbitrary … CWE-502
 Deserialization of Untrusted Data
CVE-2020-23653 2024-11-21 14:13 2021-01-14 Show GitHub Exploit DB Packet Storm
209162 6.1 MEDIUM
Network
wdja wdja_cms Cross-site request forgery (CSRF) in admin/global/manage.php in WDJA CMS 1.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via the tongji parameter. CWE-352
 Origin Validation Error
CVE-2020-23631 2024-11-21 14:13 2021-01-12 Show GitHub Exploit DB Packet Storm
209163 8.8 HIGH
Network
zzcms zzcms A blind SQL injection vulnerability exists in zzcms ver201910 based on time (cookie injection). CWE-89
SQL Injection
CVE-2020-23630 2024-11-21 14:13 2021-01-12 Show GitHub Exploit DB Packet Storm
209164 6.1 MEDIUM
Network
jizhicms jizhicms XSS exists in JIZHICMS 1.7.1 via index.php/Error/index?msg={XSS] to Home/c/ErrorController.php. CWE-79
Cross-site Scripting
CVE-2020-23644 2024-11-21 14:13 2021-01-11 Show GitHub Exploit DB Packet Storm
209165 6.1 MEDIUM
Network
jizhicms jizhicms XSS exists in JIZHICMS 1.7.1 via index.php/Wechat/checkWeixin?signature=1&echostr={XSS] to Home/c/WechatController.php. CWE-79
Cross-site Scripting
CVE-2020-23643 2024-11-21 14:13 2021-01-11 Show GitHub Exploit DB Packet Storm
209166 2.3 LOW
Local
gigamon gigavue-os GigaVUE-OS (GVOS) 5.4 - 5.9 uses a weak algorithm for a hash stored in internal database. CWE-327
 Use of a Broken or Risky Cryptographic Algorithm
CVE-2020-23250 2024-11-21 14:13 2021-01-6 Show GitHub Exploit DB Packet Storm
209167 4.7 MEDIUM
Network
gigamon gigavue-os GigaVUE-OS (GVOS) 5.4 - 5.9 stores a Redis database password in plaintext. CWE-312
 Cleartext Storage of Sensitive Information
CVE-2020-23249 2024-11-21 14:13 2021-01-6 Show GitHub Exploit DB Packet Storm
209168 7.5 HIGH
Network
veno_file_manager_project veno_file_manager Veno File Manager 3.5.6 is affected by a directory traversal vulnerability. Using the traversal allows an attacker to download sensitive files from the server. CWE-22
Path Traversal
CVE-2020-22550 2024-11-21 14:13 2021-01-5 Show GitHub Exploit DB Packet Storm
209169 9.8 CRITICAL
Network
jsonpickle_project jsonpickle jsonpickle through 1.4.1 allows remote code execution during deserialization of a malicious payload through the decode() function. Note: It has been argued that this is expected and clearly documente… CWE-502
 Deserialization of Untrusted Data
CVE-2020-22083 2024-11-21 14:13 2020-12-18 Show GitHub Exploit DB Packet Storm
209170 7.2 HIGH
Network
txjia imcat imcat 5.2 allows an authenticated file upload and consequently remote code execution via the picture functionality. CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2020-23520 2024-11-21 14:13 2020-12-10 Show GitHub Exploit DB Packet Storm