Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 7, 2026, 2:09 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
226211 5 警告 RSAセキュリティ - RSA EnVision における管理者のパスワードハッシュを取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-6886 2012-12-20 19:10 2009-08-3 Show GitHub Exploit DB Packet Storm
226212 7.5 危険 scripts-for-sites - SFS EZ Career の content.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6867 2012-12-20 19:10 2009-07-14 Show GitHub Exploit DB Packet Storm
226213 7.5 危険 PHPNUKE - PHP-Nuke 用の Current_Issue モジュールにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6866 2012-12-20 19:10 2009-07-14 Show GitHub Exploit DB Packet Storm
226214 7.5 危険 PHPNUKE - PHP-Nuke 用の Sectionsnew モジュールにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6865 2012-12-20 19:10 2009-07-14 Show GitHub Exploit DB Packet Storm
226215 7.5 危険 xigla - Xigla Software Absolute Live Support .NET における認証を回避される脆弱性 CWE-287
不適切な認証
CVE-2008-6864 2012-12-20 19:10 2009-07-14 Show GitHub Exploit DB Packet Storm
226216 7.5 危険 xigla - Xigla Software Absolute Form Processor .NET における認証を回避される脆弱性 CWE-287
不適切な認証
CVE-2008-6863 2012-12-20 19:10 2009-07-14 Show GitHub Exploit DB Packet Storm
226217 7.5 危険 xigla - Absolute Content Rotator における認証を回避される脆弱性 CWE-287
不適切な認証
CVE-2008-6862 2012-12-20 19:10 2009-07-14 Show GitHub Exploit DB Packet Storm
226218 7.5 危険 xigla - Xigla Software Absolute Newsletter における認証を回避される脆弱性 CWE-287
不適切な認証
CVE-2008-6861 2012-12-20 19:10 2009-07-14 Show GitHub Exploit DB Packet Storm
226219 7.5 危険 xigla - Xigla Software Absolute Poll Manager XE における認証を回避される脆弱性 CWE-287
不適切な認証
CVE-2008-6860 2012-12-20 19:10 2009-07-14 Show GitHub Exploit DB Packet Storm
226220 7.5 危険 xigla - Xigla Software Absolute Control Panel XE における認証を回避される脆弱性 CWE-287
不適切な認証
CVE-2008-6859 2012-12-20 19:10 2009-07-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 7, 2026, 4:22 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
199661 7.4 HIGH
Network
djangoproject channels Django Channels 3.x before 3.0.3 allows remote attackers to obtain sensitive information from a different request scope. The legacy channels.http.AsgiHandler class, used for handling HTTP type reques… CWE-200
Information Exposure
CVE-2020-35681 2024-11-21 14:27 2021-02-22 Show GitHub Exploit DB Packet Storm
199662 6.7 MEDIUM
Local
linux linux_kernel A NULL pointer dereference flaw in Linux kernel versions prior to 5.11 may be seen if sco_sock_getsockopt function in net/bluetooth/sco.c do not have a sanity check for a socket connection, when usin… CWE-476
 NULL Pointer Dereference
CVE-2020-35499 2024-11-21 14:27 2021-02-20 Show GitHub Exploit DB Packet Storm
199663 5.4 MEDIUM
Network
pi-hole pi-hole Pi-hole 5.0, 5.1, and 5.1.1 allows XSS via the Options header to the admin/ URI. A remote user is able to inject arbitrary web script or HTML due to incorrect sanitization of user-supplied data and a… CWE-79
Cross-site Scripting
CVE-2020-35592 2024-11-21 14:27 2021-02-19 Show GitHub Exploit DB Packet Storm
199664 5.4 MEDIUM
Network
pi-hole pi-hole Pi-hole 5.0, 5.1, and 5.1.1 allows Session Fixation. The application does not generate a new session cookie after the user is logged in. A malicious user is able to create a new session cookie value … CWE-384
 Session Fixation
CVE-2020-35591 2024-11-21 14:27 2021-02-19 Show GitHub Exploit DB Packet Storm
199665 6.5 MEDIUM
Network
endalia selection_portal In Endalia Selection Portal before 4.205.0, an Insecure Direct Object Reference (IDOR) allows any authenticated user to download every file uploaded to the platform by changing the value of the file … NVD-CWE-Other
CVE-2020-35577 2024-11-21 14:27 2021-02-18 Show GitHub Exploit DB Packet Storm
199666 9.8 CRITICAL
Network
74cms 74cms In 74cms version 5.0.1, there is a remote code execution vulnerability in /Application/Admin/Controller/ConfigController.class.php and /ThinkPHP/Common/functions.php where attackers can obtain server… CWE-94
Code Injection
CVE-2020-35339 2024-11-21 14:27 2021-02-18 Show GitHub Exploit DB Packet Storm
199667 5.3 MEDIUM
Network
mbconnectline
helmholz
mbconnect24
mymbconnect24
myrex24.virtual
myrex24
An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual through 2.11.2. An unauthenticated attacker is able to access files (that should have be… CWE-425
 Direct Request ('Forced Browsing')
CVE-2020-35570 2024-11-21 14:27 2021-02-17 Show GitHub Exploit DB Packet Storm
199668 6.1 MEDIUM
Network
mbconnectline mbconnect24
mymbconnect24
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is a self XSS issue with a crafted cookie in the login page. CWE-79
Cross-site Scripting
CVE-2020-35569 2024-11-21 14:27 2021-02-17 Show GitHub Exploit DB Packet Storm
199669 4.3 MEDIUM
Network
mbconnectline
helmholz
mbconnect24
mymbconnect24
myrex24.virtual
myrex24
An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. An incomplete filter applied to a database response all… CWE-200
Information Exposure
CVE-2020-35568 2024-11-21 14:27 2021-02-17 Show GitHub Exploit DB Packet Storm
199670 7.8 HIGH
Local
mbconnectline mbconnect24
mymbconnect24
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. The software uses a secure password for database access, but this password is shared across instances. CWE-798
 Use of Hard-coded Credentials
CVE-2020-35567 2024-11-21 14:27 2021-02-17 Show GitHub Exploit DB Packet Storm