Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 30, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
250881 9.3 危険 Novell - Novell ZHM の ZfHIPCND.exe におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2010-4299 2012-03-27 18:42 2010-11-2 Show GitHub Exploit DB Packet Storm
250882 7.5 危険 dustincowell - Free Simple Software の download モジュールにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-4298 2012-03-27 18:42 2010-11-26 Show GitHub Exploit DB Packet Storm
250883 7.5 危険 Artica ST - Pandora FMS における任意の PHP コードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2010-4283 2012-03-27 18:42 2010-12-2 Show GitHub Exploit DB Packet Storm
250884 7.5 危険 Artica ST - Pandora FMS におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2010-4282 2012-03-27 18:42 2010-12-2 Show GitHub Exploit DB Packet Storm
250885 7.5 危険 Artica ST - Pandora FMS の safe_url_extraclean 関数における任意の PHP コードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2010-4281 2012-03-27 18:42 2010-12-2 Show GitHub Exploit DB Packet Storm
250886 7.5 危険 Artica ST - Pandora FMS における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-4280 2012-03-27 18:42 2010-12-2 Show GitHub Exploit DB Packet Storm
250887 10 危険 Artica ST - Pandora FMS のディフォルト設定における認証を回避される脆弱性 CWE-287
不適切な認証
CVE-2010-4279 2012-03-27 18:42 2010-12-2 Show GitHub Exploit DB Packet Storm
250888 7.5 危険 accimoveis - DescargarVista ACC Imoveis における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-4273 2012-03-27 18:42 2010-11-16 Show GitHub Exploit DB Packet Storm
250889 7.5 危険 pulseinfotech
Joomla!
- Joomla! 用の Pulse Infotech Sponsor Wall コンポーネントにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-4272 2012-03-27 18:42 2010-11-16 Show GitHub Exploit DB Packet Storm
250890 7.5 危険 ImpressCMS - ImpressCMS における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-4271 2012-03-27 18:42 2010-11-16 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 31, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
208821 7.5 HIGH
Network
online_shopping_alphaware_project online_shopping_alphaware The id paramater in Online Shopping Alphaware 1.0 has been discovered to be vulnerable to an Error-Based blind SQL injection in the /alphaware/details.php path. This allows an attacker to retrieve al… CWE-89
SQL Injection
CVE-2020-25362 2024-11-21 14:17 2021-06-3 Show GitHub Exploit DB Packet Storm
208822 6.5 MEDIUM
Network
online_examination_system_project online_examination_system Projectworlds Online Examination System 1.0 is vulnerable to CSRF, which allows a remote attacker to delete the existing user. CWE-352
 Origin Validation Error
CVE-2020-25411 2024-11-21 14:17 2021-05-24 Show GitHub Exploit DB Packet Storm
208823 9.8 CRITICAL
Network
college_management_system_project college_management_system Projectsworlds College Management System Php 1.0 is vulnerable to SQL injection issues over multiple parameters. CWE-89
SQL Injection
CVE-2020-25409 2024-11-21 14:17 2021-05-24 Show GitHub Exploit DB Packet Storm
208824 6.5 MEDIUM
Network
college_management_system_project college_management_system A Cross-Site Request Forgery (CSRF) vulnerability exists in ProjectWorlds College Management System Php 1.0 that allows a remote attacker to modify, delete, or make a new entry of the student, facult… CWE-352
 Origin Validation Error
CVE-2020-25408 2024-11-21 14:17 2021-05-24 Show GitHub Exploit DB Packet Storm
208825 7.5 HIGH
Network
siemens simatic_net_cp_343-1_advanced_firmware
simatic_net_cp_343-1_lean_firmware
simatic_net_cp_343-1_standard_firmware
A vulnerability has been identified in SIMATIC NET CP 343-1 Advanced (incl. SIPLUS variants) (All versions), SIMATIC NET CP 343-1 Lean (incl. SIPLUS variants) (All versions), SIMATIC NET CP 343-1 Sta… - CVE-2020-25242 2024-11-21 14:17 2021-05-12 Show GitHub Exploit DB Packet Storm
208826 8.4 HIGH
Local
siemens logo\!_soft_comfort A vulnerability has been identified in LOGO! Soft Comfort (All versions < V8.4). The software insecurely loads libraries which makes it vulnerable to DLL hijacking. Successful exploitation by a local… CWE-427
 Uncontrolled Search Path Element
CVE-2020-25244 2024-11-21 14:17 2021-04-23 Show GitHub Exploit DB Packet Storm
208827 5.1 MEDIUM
Local
siemens logo\!_soft_comfort A vulnerability has been identified in LOGO! Soft Comfort (All versions < V8.4). A zip slip vulnerability could be triggered while importing a compromised project file to the affected software. Chain… - CVE-2020-25243 2024-11-21 14:17 2021-04-23 Show GitHub Exploit DB Packet Storm
208828 9.8 CRITICAL
Network
grandstream grp2612_firmware
grp2612p_firmware
grp2612w_firmware
grp2613_firmware
grp2614_firmware
grp2615_firmware
grp2616_firmware
Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allow Authentication Bypass in its administrative web interface. CWE-306
Missing Authentication for Critical Function
CVE-2020-25218 2024-11-21 14:17 2021-03-30 Show GitHub Exploit DB Packet Storm
208829 7.2 HIGH
Network
grandstream grp2612_firmware
grp2612p_firmware
grp2612w_firmware
grp2613_firmware
grp2614_firmware
grp2615_firmware
grp2616_firmware
Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allows Command Injection as root in its administrative web interface. CWE-77
Command Injection
CVE-2020-25217 2024-11-21 14:17 2021-03-30 Show GitHub Exploit DB Packet Storm
208830 8.6 HIGH
Network
squid-cache
debian
fedoraproject
netapp
squid
debian_linux
fedora
cloud_manager
An issue was discovered in Squid through 4.13 and 5.x through 5.0.4. Due to improper input validation, it allows a trusted client to perform HTTP Request Smuggling and access services otherwise forbi… CWE-20
CWE-444
 Improper Input Validation 
HTTP Request Smuggling
CVE-2020-25097 2024-11-21 14:17 2021-03-19 Show GitHub Exploit DB Packet Storm