Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 3, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
226361 7.5 危険 Smarty - Smarty の libs/Smarty_Compiler.class.php における任意の PHP コードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2008-4810 2012-12-20 18:52 2008-10-31 Show GitHub Exploit DB Packet Storm
226362 4.3 警告 simple php scripts - Simple PHP Scripts gallery の index.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-4803 2012-12-20 18:52 2008-10-31 Show GitHub Exploit DB Packet Storm
226363 4.3 警告 simple php scripts - Simple PHP Scripts ブログの complete.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-4802 2012-12-20 18:52 2008-10-31 Show GitHub Exploit DB Packet Storm
226364 9.3 危険 webgui - WebGUI の lib/WebGUI/Asset.pm における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2008-4798 2012-12-20 18:52 2008-10-27 Show GitHub Exploit DB Packet Storm
226365 10 危険 tguzip - TUGzip におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-4779 2012-12-20 18:52 2008-10-29 Show GitHub Exploit DB Packet Storm
226366 4.3 警告 Wojtek Kaniewski - libgadu におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2008-4776 2012-12-20 18:52 2008-10-24 Show GitHub Exploit DB Packet Storm
226367 2.6 注意 The phpMyAdmin Project - phpMyAdmin の pmd_pdf.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-4775 2012-12-20 18:52 2008-10-28 Show GitHub Exploit DB Packet Storm
226368 4.3 警告 questwork - QuestCMS の main/main.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-4774 2012-12-20 18:52 2008-10-28 Show GitHub Exploit DB Packet Storm
226369 5 警告 questwork - QuestCMS の main/main.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-4773 2012-12-20 18:52 2008-10-28 Show GitHub Exploit DB Packet Storm
226370 7.5 危険 questwork - QuestCMS の main/main.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-4772 2012-12-20 18:52 2008-10-28 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 3, 2026, 4:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
198991 5.5 MEDIUM
Local
gnu
fedoraproject
netapp
broadcom
binutils
fedora
cloud_backup
ontap_select_deploy_administration_utility
solidfire_\&_hci_management_node
solidfire\
_enterprise_sds_\&_hci_storage_node
brocade_fabric_ope…
There's a flaw in bfd_pef_scan_start_address() of bfd/pef.c in binutils which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dereferen… - CVE-2020-35496 2024-11-21 14:27 2021-01-5 Show GitHub Exploit DB Packet Storm
198992 5.5 MEDIUM
Local
gnu
fedoraproject
netapp
broadcom
binutils
fedora
cloud_backup
ontap_select_deploy_administration_utility
solidfire_\&_hci_management_node
solidfire\
_enterprise_sds_\&_hci_storage_node
brocade_fabric_ope…
There's a flaw in binutils /bfd/pef.c. An attacker who is able to submit a crafted input file to be processed by the objdump program could cause a null pointer dereference. The greatest threat from t… - CVE-2020-35495 2024-11-21 14:27 2021-01-5 Show GitHub Exploit DB Packet Storm
198993 6.1 MEDIUM
Local
gnu
fedoraproject
netapp
broadcom
binutils
fedora
cloud_backup
ontap_select_deploy_administration_utility
solidfire_\&_hci_management_node
solidfire\
_enterprise_sds_\&_hci_storage_node
brocade_fabric_ope…
There's a flaw in binutils /opcodes/tic4x-dis.c. An attacker who is able to submit a crafted input file to be processed by binutils could cause usage of uninitialized memory. The highest threat is to… - CVE-2020-35494 2024-11-21 14:27 2021-01-5 Show GitHub Exploit DB Packet Storm
198994 5.5 MEDIUM
Local
gnu
fedoraproject
netapp
broadcom
binutils
fedora
cloud_backup
ontap_select_deploy_administration_utility
solidfire_\&_hci_management_node
solidfire\
_enterprise_sds_\&_hci_storage_node
brocade_fabric_ope…
A flaw exists in binutils in bfd/pef.c. An attacker who is able to submit a crafted PEF file to be parsed by objdump could cause a heap buffer overflow -> out-of-bounds read that could lead to an imp… - CVE-2020-35493 2024-11-21 14:27 2021-01-5 Show GitHub Exploit DB Packet Storm
198995 9.0 CRITICAL
Network
electronjs zonote zonote through 0.4.0 allows XSS via a crafted note, with resultant Remote Code Execution (because nodeIntegration in webPreferences is true). CWE-79
Cross-site Scripting
CVE-2020-35717 2024-11-21 14:27 2021-01-1 Show GitHub Exploit DB Packet Storm
198996 6.5 MEDIUM
Adjacent
tenda f3_firmware Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_passwd line) via a direct request for cgi-bin/DownloadCfg/RouterCfm.cfg, a related… CWE-425
 Direct Request ('Forced Browsing')
CVE-2020-35391 2024-11-21 14:27 2021-01-1 Show GitHub Exploit DB Packet Storm
198997 7.6 HIGH
Network
hgiga msr45_isherlock-antispam
msr45_isherlock-user
ssr45_isherlock-antispam
ssr45_isherlock-user
HGiga MailSherlock contains a SQL injection flaw. Attackers can inject and launch SQL commands in a URL parameter of specific cgi pages. CWE-89
SQL Injection
CVE-2020-35743 2024-11-21 14:27 2020-12-31 Show GitHub Exploit DB Packet Storm
198998 7.6 HIGH
Network
hgiga msr45_isherlock-antispam
msr45_isherlock-user
ssr45_isherlock-antispam
ssr45_isherlock-user
HGiga MailSherlock contains a vulnerability of SQL Injection. Attackers can inject and launch SQL commands in a URL parameter. CWE-89
SQL Injection
CVE-2020-35742 2024-11-21 14:27 2020-12-31 Show GitHub Exploit DB Packet Storm
198999 6.1 MEDIUM
Network
hgiga msr45_isherlock-antispam
msr45_isherlock-user
ssr45_isherlock-antispam
ssr45_isherlock-user
HGiga MailSherlock does not validate user parameters on multiple login pages. Attackers can use the vulnerability to inject JavaScript syntax for XSS attacks. CWE-79
Cross-site Scripting
CVE-2020-35741 2024-11-21 14:27 2020-12-31 Show GitHub Exploit DB Packet Storm
199000 6.1 MEDIUM
Network
hgiga msr45_isherlock-antispam
msr45_isherlock-user
ssr45_isherlock-antispam
ssr45_isherlock-user
HGiga MailSherlock does not validate specific URL parameters properly that allows attackers to inject JavaScript syntax for XSS attacks. CWE-79
Cross-site Scripting
CVE-2020-35740 2024-11-21 14:27 2020-12-31 Show GitHub Exploit DB Packet Storm