Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 6, 2026, 2 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
226061 7.5 危険 rasihbahar - Bahar Download Script の aspkat.asp における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6075 2012-12-20 19:10 2009-02-6 Show GitHub Exploit DB Packet Storm
226062 5.1 警告 phpcrs - phpcrs の frame.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-6074 2012-12-20 19:10 2009-02-6 Show GitHub Exploit DB Packet Storm
226063 7.5 危険 web design hero - Joomla! 用の JoomlaDate コンポーネントにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6068 2012-12-20 19:10 2009-02-10 Show GitHub Exploit DB Packet Storm
226064 4.3 警告 テックスミス株式会社 - Techsmith Camtasia Studio が作成した任意の SWF コントローラーファイルにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-6061 2012-12-20 19:10 2009-02-4 Show GitHub Exploit DB Packet Storm
226065 5 警告 syslserve - Syslserve におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2008-6058 2012-12-20 19:10 2009-02-4 Show GitHub Exploit DB Packet Storm
226066 5 警告 PreProject.com - PreProjects Pre Classified Listings におけるパスワードを取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-6055 2012-12-20 19:10 2009-02-4 Show GitHub Exploit DB Packet Storm
226067 5 警告 PreProject.com - PreProjects Pre Courier and Cargo Business におけるパスワードを取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-6054 2012-12-20 19:10 2009-02-4 Show GitHub Exploit DB Packet Storm
226068 5 警告 PreProject.com - PreProjects Pre Resume Submitter におけるパスワードを取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-6053 2012-12-20 19:10 2009-02-4 Show GitHub Exploit DB Packet Storm
226069 5 警告 PreProject.com - PreProjects Pre E-Learning Portal におけるパスワードを取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-6052 2012-12-20 19:10 2009-02-4 Show GitHub Exploit DB Packet Storm
226070 6.8 警告 xt:Commerce - xt:Commerce の shopping_cart.php におけるセッションをハイジャックされる脆弱性 CWE-287
不適切な認証
CVE-2008-6045 2012-12-20 19:10 2009-02-3 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 6, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
198591 9.1 CRITICAL
Network
tar-utils_project tar-utils Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory. CWE-22
Path Traversal
CVE-2020-36566 2024-11-21 14:29 2022-12-28 Show GitHub Exploit DB Packet Storm
198592 7.5 HIGH
Network
nosurf_project nosurf Due to improper validation of caller input, validation is silently disabled if the provided expected token is malformed, causing any user supplied token to be considered valid. CWE-20
 Improper Input Validation 
CVE-2020-36564 2024-11-21 14:29 2022-12-28 Show GitHub Exploit DB Packet Storm
198593 9.1 CRITICAL
Network
go-unzip_project go-unzip Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory. CWE-22
Path Traversal
CVE-2020-36560 2024-11-21 14:29 2022-12-28 Show GitHub Exploit DB Packet Storm
198594 7.5 HIGH
Network
aahframework aah Due to improper sanitization of user input, HTTPEngine.Handle allows for directory traversal, allowing an attacker to read files outside of the target directory that the server has permission to read. CWE-22
Path Traversal
CVE-2020-36559 2024-11-21 14:29 2022-12-28 Show GitHub Exploit DB Packet Storm
198595 7.5 HIGH
Network
gin-gonic gin Unsanitized input in the default logger in github.com/gin-gonic/gin before v1.6.0 allows remote attackers to inject arbitrary log lines. CWE-116
 Improper Encoding or Escaping of Output
CVE-2020-36567 2024-11-21 14:29 2022-12-28 Show GitHub Exploit DB Packet Storm
198596 6.1 MEDIUM
Network
tri panel_builder A vulnerability classified as critical has been found in Modern Tribe Panel Builder Plugin. Affected is the function add_post_content_filtered_to_search_sql of the file ModularContent/SearchFilter.ph… CWE-79
Cross-site Scripting
CVE-2020-36626 2024-11-21 14:29 2022-12-28 Show GitHub Exploit DB Packet Storm
198597 6.5 MEDIUM
Network
moodle-block_sitenews_project moodle-block_sitenews A vulnerability was found in moodle-block_sitenews 1.0. It has been classified as problematic. This affects the function get_content of the file block_sitenews.php. The manipulation leads to cross-si… - CVE-2020-36633 2024-11-21 14:29 2022-12-27 Show GitHub Exploit DB Packet Storm
198598 9.8 CRITICAL
Network
flat_project flat A vulnerability, which was classified as critical, was found in hughsk flat up to 5.0.0. This affects the function unflatten of the file index.js. The manipulation leads to improperly controlled modi… - CVE-2020-36632 2024-11-21 14:29 2022-12-26 Show GitHub Exploit DB Packet Storm
198599 9.8 CRITICAL
Network
dwc_network_server_emulator_project dwc_network_server_emulator A vulnerability was found in barronwaffles dwc_network_server_emulator. It has been declared as critical. This vulnerability affects the function update_profile of the file gamespy/gs_database.py. Th… - CVE-2020-36631 2024-11-21 14:29 2022-12-26 Show GitHub Exploit DB Packet Storm
198600 9.8 CRITICAL
Network
sangoma freepbx A vulnerability was found in FreePBX cdr 14.0. It has been classified as critical. This affects the function ajaxHandler of the file ucp/Cdr.class.php. The manipulation of the argument limit/offset l… - CVE-2020-36630 2024-11-21 14:29 2022-12-26 Show GitHub Exploit DB Packet Storm