Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 20, 2026, 2 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
258371 5.5 警告 オラクル - Oracle Database Server の OLAP コンポーネントにおける脆弱性 CWE-noinfo
情報不足
CVE-2010-2412 2010-10-29 16:34 2010-10-12 Show GitHub Exploit DB Packet Storm
258372 6.5 警告 オラクル - Oracle Database Server の Java Virtual Machine コンポーネントにおける脆弱性 CWE-noinfo
情報不足
CVE-2010-2419 2010-10-29 16:34 2010-10-12 Show GitHub Exploit DB Packet Storm
258373 7.5 危険 オラクル - 複数の Oracle 製品の Database Control コンポーネントにおける脆弱性 CWE-noinfo
情報不足
CVE-2010-2390 2010-10-29 16:33 2010-10-12 Show GitHub Exploit DB Packet Storm
258374 7.5 危険 マイクロソフト - Microsoft Windows Server の Microsoft Cluster Service 内にあるユーザインターフェイスにおけるディスク上のデータを読まれるまたは編集される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2010-3223 2010-10-29 16:32 2010-10-12 Show GitHub Exploit DB Packet Storm
258375 9.3 危険 マイクロソフト - 複数の Microsoft 製品の UpdateFrameTitleForDocument メソッドにおけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2010-3227 2010-10-29 16:31 2010-10-12 Show GitHub Exploit DB Packet Storm
258376 7.1 危険 マイクロソフト - 複数の Microsoft 製品の Secure Channel におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2010-3229 2010-10-29 16:30 2010-10-12 Show GitHub Exploit DB Packet Storm
258377 7.2 危険 マイクロソフト - 複数の Microsoft 製品の Remote Procedure Call Subsystem におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2010-3222 2010-10-29 16:30 2010-10-12 Show GitHub Exploit DB Packet Storm
258378 9.3 危険 マイクロソフト - Microsoft Windows Media Player における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2010-2745 2010-10-29 16:27 2010-10-12 Show GitHub Exploit DB Packet Storm
258379 4.3 警告 トランスウエア - Active! mail 6 における HTTP ヘッダインジェクションの脆弱性 CWE-20
不適切な入力確認
CVE-2010-3913 2010-10-29 16:01 2010-10-29 Show GitHub Exploit DB Packet Storm
258380 6.8 警告 Schezo - Lhaplus における実行ファイル読み込みに関する脆弱性 CWE-Other
その他
CVE-2010-3158 2010-10-28 16:55 2010-10-15 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 20, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
214061 9.8 CRITICAL
Network
jsonpickle_project jsonpickle jsonpickle through 1.4.1 allows remote code execution during deserialization of a malicious payload through the decode() function. Note: It has been argued that this is expected and clearly documente… CWE-502
 Deserialization of Untrusted Data
CVE-2020-22083 2024-11-21 14:13 2020-12-18 Show GitHub Exploit DB Packet Storm
214062 7.2 HIGH
Network
txjia imcat imcat 5.2 allows an authenticated file upload and consequently remote code execution via the picture functionality. CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2020-23520 2024-11-21 14:13 2020-12-10 Show GitHub Exploit DB Packet Storm
214063 6.1 MEDIUM
Network
yzmcms yzmcms In YzmCMS v5.5 the member contribution function in the editor contains a cross-site scripting (XSS) vulnerability. CWE-79
Cross-site Scripting
CVE-2020-22394 2024-11-21 14:13 2020-11-20 Show GitHub Exploit DB Packet Storm
214064 6.1 MEDIUM
Network
ljcmsshop_project ljcmsshop A cross-site scripting (XSS) vulnerability in Beijing Liangjing Zhicheng Technology Co., Ltd ljcmsshop version 1.14 allows remote attackers to inject arbitrary web script or HTML via user.php by regi… CWE-79
Cross-site Scripting
CVE-2020-22723 2024-11-21 14:13 2020-11-19 Show GitHub Exploit DB Packet Storm
214065 7.5 HIGH
Network
wwbn avideo There was a local file disclosure vulnerability in AVideo < 8.9 via the proxy streaming. An unauthenticated attacker can exploit this issue to read an arbitrary file on the server. Which could leak d… NVD-CWE-noinfo
CVE-2020-23490 2024-11-21 14:13 2020-11-17 Show GitHub Exploit DB Packet Storm
214066 8.8 HIGH
Network
wwbn avideo The import.json.php file before 8.9 for Avideo is vulnerable to a File Deletion vulnerability. This allows the deletion of configuration.php, which leads to certain privilege checks not being in plac… CWE-862
 Missing Authorization
CVE-2020-23489 2024-11-21 14:13 2020-11-17 Show GitHub Exploit DB Packet Storm
214067 8.1 HIGH
Network
microweber microweber Microweber 1.1.18 is affected by insufficient session expiration. When changing passwords, both sessions for when a user changes email and old sessions in any other browser or device, the session doe… CWE-613
 Insufficient Session Expiration
CVE-2020-23140 2024-11-21 14:13 2020-11-10 Show GitHub Exploit DB Packet Storm
214068 5.5 MEDIUM
Local
microweber microweber Microweber 1.1.18 is affected by broken authentication and session management. Local session hijacking may occur, which could result in unauthorized access to system data or functionality, or a compl… CWE-287
Improper Authentication
CVE-2020-23139 2024-11-21 14:13 2020-11-10 Show GitHub Exploit DB Packet Storm
214069 9.8 CRITICAL
Network
microweber microweber An unrestricted file upload vulnerability was discovered in the Microweber 1.1.18 admin account page. An attacker can upload PHP code or any extension (eg- .exe) to the web server by providing image … CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2020-23138 2024-11-21 14:13 2020-11-10 Show GitHub Exploit DB Packet Storm
214070 5.5 MEDIUM
Local
microweber microweber Microweber v1.1.18 is affected by no session expiry after log-out. CWE-613
 Insufficient Session Expiration
CVE-2020-23136 2024-11-21 14:13 2020-11-10 Show GitHub Exploit DB Packet Storm