Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 31, 2026, 2 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
250791 4.3 警告 jxtended
Joomla!
- Joomla の JXtended Comments コンポーネントにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-4516 2012-03-27 18:42 2010-12-9 Show GitHub Exploit DB Packet Storm
250792 4.3 警告 シトリックス・システムズ - Citrix Web Interface におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-4515 2012-03-27 18:42 2010-12-8 Show GitHub Exploit DB Packet Storm
250793 4.3 警告 DNN - DotNetNuke の Install/InstallWizard.aspx におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-4514 2012-03-27 18:42 2010-12-9 Show GitHub Exploit DB Packet Storm
250794 4.3 警告 zimplit - Zimplit CMS におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-4513 2012-03-27 18:42 2010-12-9 Show GitHub Exploit DB Packet Storm
250795 7.2 危険 Cobbler project - Cobbler における詳細不明な脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2010-4512 2012-03-27 18:42 2010-04-23 Show GitHub Exploit DB Packet Storm
250796 10 危険 シックス・アパート株式会社 - Movable Type における詳細不明な脆弱性 CWE-noinfo
情報不足
CVE-2010-4511 2012-03-27 18:42 2010-12-9 Show GitHub Exploit DB Packet Storm
250797 10 危険 シックス・アパート株式会社 - Movable Type における詳細不明な脆弱性 CWE-noinfo
情報不足
CVE-2010-4509 2012-03-27 18:42 2010-12-9 Show GitHub Exploit DB Packet Storm
250798 10 危険 Mozilla Foundation - Mozilla Firefox の WebSockets 実装における脆弱性 CWE-noinfo
情報不足
CVE-2010-4508 2012-03-27 18:42 2010-12-9 Show GitHub Exploit DB Packet Storm
250799 9.3 危険 clear - ClearSpot の iSpot における管理者の認証をクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2010-4507 2012-03-27 18:42 2010-12-30 Show GitHub Exploit DB Packet Storm
250800 6.8 警告 injader - Injader の login.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-4505 2012-03-27 18:42 2010-12-8 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 31, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
208941 6.5 MEDIUM
Network
observium observium An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to SQL Injection due to the fact that it is possible to inject malicious SQL statements in malfo… CWE-89
SQL Injection
CVE-2020-25130 2024-11-21 14:17 2020-09-25 Show GitHub Exploit DB Packet Storm
208942 5.0 MEDIUM
Local
qemu
debian
qemu
debian_linux
QEMU 5.0.0 has a heap-based Buffer Overflow in flatview_read_continue in exec.c because hw/sd/sdhci.c mishandles a write operation in the SDHC_BLKSIZE case. CWE-787
 Out-of-bounds Write
CVE-2020-25085 2024-11-21 14:17 2020-09-25 Show GitHub Exploit DB Packet Storm
208943 3.2 LOW
Local
qemu
debian
qemu
debian_linux
QEMU 5.0.0 has a use-after-free in hw/usb/hcd-xhci.c because the usb_packet_map return value is not checked. CWE-416
 Use After Free
CVE-2020-25084 2024-11-21 14:17 2020-09-25 Show GitHub Exploit DB Packet Storm
208944 9.8 CRITICAL
Network
sophos unified_threat_management A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11 CWE-78
OS Command 
CVE-2020-25223 2024-11-21 14:17 2020-09-25 Show GitHub Exploit DB Packet Storm
208945 5.5 MEDIUM
Local
framer framer_preview The Framer Preview application 12 for Android exposes com.framer.viewer.FramerViewActivity to other applications. By calling the intent with the action set to android.intent.action.VIEW, any other ap… NVD-CWE-Other
CVE-2020-25203 2024-11-21 14:17 2020-09-25 Show GitHub Exploit DB Packet Storm
208946 9.8 CRITICAL
Network
yworks yed yWorks yEd Desktop before 3.20.1 allows code execution via an XSL Transformation when using an XML file in conjunction with a custom stylesheet. CWE-91
Blind XPath Injection
CVE-2020-25216 2024-11-21 14:17 2020-09-18 Show GitHub Exploit DB Packet Storm
208947 9.8 CRITICAL
Network
yworks yed yWorks yEd Desktop before 3.20.1 allows XXE attacks via an XML or GraphML document. CWE-611
XXE
CVE-2020-25215 2024-11-21 14:17 2020-09-18 Show GitHub Exploit DB Packet Storm
208948 9.8 CRITICAL
Network
gnuplot_project gnuplot com_line() in command.c in gnuplot 5.4 leads to an out-of-bounds-write from strncpy() that may lead to arbitrary code execution. CWE-787
 Out-of-bounds Write
CVE-2020-25412 2024-11-21 14:17 2020-09-16 Show GitHub Exploit DB Packet Storm
208949 8.8 HIGH
Network
blackcat-cms blackcat_cms An issue was discovered in BlackCat CMS before 1.4. There is a CSRF vulnerability (bypass csrf_token) that allows remote arbitrary code execution. CWE-352
 Origin Validation Error
CVE-2020-25453 2024-11-21 14:17 2020-09-16 Show GitHub Exploit DB Packet Storm
208950 5.4 MEDIUM
Network
niftypm nifty Nifty Project Management Web Application 2020-08-26 allows XSS, via Add Task, that is rendered upon a Project Home visit. Note: It has been argued that this is not reproducible. "The original issue w… CWE-79
Cross-site Scripting
CVE-2020-25071 2024-11-21 14:17 2020-09-16 Show GitHub Exploit DB Packet Storm