Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 6, 2026, noon

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
226041 4.3 警告 Web-Empowered Church Team - TYPO3 用の WEC Discussion Forum エクステンションにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-6144 2012-12-20 19:10 2009-02-16 Show GitHub Exploit DB Packet Storm
226042 5 警告 webbiscuits - WebBiscuits Modules Controller の faqsupport/wce.download.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-6139 2012-12-20 19:10 2009-02-13 Show GitHub Exploit DB Packet Storm
226043 7.5 危険 webbiscuits - WebBiscuits Modules Controller の adminhead.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2008-6138 2012-12-20 19:10 2009-02-13 Show GitHub Exploit DB Packet Storm
226044 7.5 危険 socialengine - SocialEngine における CRLF インジェクションの脆弱性 CWE-20
不適切な入力確認
CVE-2008-6121 2012-12-20 19:10 2009-02-11 Show GitHub Exploit DB Packet Storm
226045 7.5 危険 socialengine - SocialEngine の profile_comments.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6120 2012-12-20 19:10 2009-02-11 Show GitHub Exploit DB Packet Storm
226046 7.5 危険 pilotgroup - PG Job Site Pro の homepage.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6117 2012-12-20 19:10 2009-02-11 Show GitHub Exploit DB Packet Storm
226047 7.5 危険 prozilla - Prozilla Hosting Index の directory.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6115 2012-12-20 19:10 2009-02-11 Show GitHub Exploit DB Packet Storm
226048 4.3 警告 SemanticScuttle - SemanticScuttle におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-6113 2012-12-20 19:10 2009-02-11 Show GitHub Exploit DB Packet Storm
226049 5 警告 Scriptsez.net - Ez Ringtone Manager におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-6112 2012-12-20 19:10 2009-02-11 Show GitHub Exploit DB Packet Storm
226050 10 危険 SemanticScuttle - SemanticScuttle における脆弱性 CWE-noinfo
情報不足
CVE-2008-6110 2012-12-20 19:10 2009-02-10 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 6, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
199091 7.5 HIGH
Network
google flatbuffers An issue was discovered in the flatbuffers crate through 2020-04-11 for Rust. read_scalar (and read_scalar_at) can transmute values without unsafe blocks. NVD-CWE-noinfo
CVE-2020-35864 2024-11-21 14:28 2020-12-31 Show GitHub Exploit DB Packet Storm
199092 9.8 CRITICAL
Network
hyper hyper An issue was discovered in the hyper crate before 0.12.34 for Rust. HTTP request smuggling can occur. Remote code execution can occur in certain situations with an HTTP server on the loopback interfa… CWE-444
HTTP Request Smuggling
CVE-2020-35863 2024-11-21 14:28 2020-12-31 Show GitHub Exploit DB Packet Storm
199093 9.8 CRITICAL
Network
bitvec_project bitvec An issue was discovered in the bitvec crate before 0.17.4 for Rust. BitVec to BitBox conversion leads to a use-after-free or double free. CWE-415
CWE-416
 Double Free
 Use After Free
CVE-2020-35862 2024-11-21 14:28 2020-12-31 Show GitHub Exploit DB Packet Storm
199094 7.5 HIGH
Network
bumpalo_project bumpalo An issue was discovered in the bumpalo crate before 3.2.1 for Rust. The realloc feature allows the reading of unknown memory. Attackers can potentially read cryptographic keys. CWE-125
Out-of-bounds Read
CVE-2020-35861 2024-11-21 14:28 2020-12-31 Show GitHub Exploit DB Packet Storm
199095 9.8 CRITICAL
Network
cbox_project cbox An issue was discovered in the cbox crate through 2020-03-19 for Rust. The CBox API allows dereferencing raw pointers without a requirement for unsafe code. CWE-476
 NULL Pointer Dereference
CVE-2020-35860 2024-11-21 14:28 2020-12-31 Show GitHub Exploit DB Packet Storm
199096 9.1 CRITICAL
Network
lucet-runtime-internals_project lucet-runtime-internals An issue was discovered in the lucet-runtime-internals crate before 0.5.1 for Rust. It mishandles sigstack allocation. Guest programs may be able to obtain sensitive information, or guest programs ca… CWE-125
CWE-787
Out-of-bounds Read
 Out-of-bounds Write
CVE-2020-35859 2024-11-21 14:28 2020-12-31 Show GitHub Exploit DB Packet Storm
199097 9.8 CRITICAL
Network
prost_project prost An issue was discovered in the prost crate before 0.6.1 for Rust. There is stack consumption via a crafted message, causing a denial of service (e.g., x86) or possibly remote code execution (e.g., AR… CWE-787
 Out-of-bounds Write
CVE-2020-35858 2024-11-21 14:28 2020-12-31 Show GitHub Exploit DB Packet Storm
199098 7.5 HIGH
Network
trust-dns-server_project trust-dns-server An issue was discovered in the trust-dns-server crate before 0.18.1 for Rust. DNS MX and SRV null targets are mishandled, causing stack consumption. CWE-400
 Uncontrolled Resource Consumption
CVE-2020-35857 2024-11-21 14:28 2020-12-31 Show GitHub Exploit DB Packet Storm
199099 4.7 MEDIUM
Local
concread_project concread An issue was discovered in the concread crate before 0.2.6 for Rust. Attackers can cause an ARCache<K,V> data race by sending types that do not implement Send/Sync. CWE-362
Race Condition
CVE-2020-35928 2024-11-21 14:28 2020-12-31 Show GitHub Exploit DB Packet Storm
199100 5.5 MEDIUM
Local
thex_project thex An issue was discovered in the thex crate through 2020-12-08 for Rust. Thex<T> allows cross-thread data races of non-Send types. NVD-CWE-noinfo
CVE-2020-35927 2024-11-21 14:28 2020-12-31 Show GitHub Exploit DB Packet Storm