Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 11, 2026, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
226431 7.5 危険 rentventory - Rentventory の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-2339 2012-12-20 19:10 2009-07-7 Show GitHub Exploit DB Packet Storm
226432 6.8 警告 w3bcms - w3b|cms Gaestebuch Guestbook Module の includes/module/book/index.inc.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-2337 2012-12-20 19:10 2009-07-7 Show GitHub Exploit DB Packet Storm
226433 5 警告 WordPress.org - WordPress および WordPress MU における有効なユーザ名を列挙される脆弱性 CWE-16
環境設定
CVE-2009-2336 2012-12-20 19:10 2009-07-10 Show GitHub Exploit DB Packet Storm
226434 5 警告 WordPress.org - WordPress および WordPress MU における有効なユーザ名を列挙される脆弱性 CWE-16
環境設定
CVE-2009-2335 2012-12-20 19:10 2009-07-10 Show GitHub Exploit DB Packet Storm
226435 4.9 警告 WordPress.org - WordPress および WordPress MU の wp-admin/admin.php における重要な情報を取得される脆弱性 CWE-287
不適切な認証
CVE-2009-2334 2012-12-20 19:10 2009-07-9 Show GitHub Exploit DB Packet Storm
226436 2.1 注意 サン・マイクロシステムズ - Solaris 上の Sun Lightweight Availability Collection Tool における任意のファイルを上書きされる脆弱性 CWE-362
競合状態
CVE-2009-2314 2012-12-20 19:10 2009-07-2 Show GitHub Exploit DB Packet Storm
226437 7.5 危険 selbstzweck - WBB3 用の rGallery プラグインにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-2311 2012-12-20 19:10 2009-07-2 Show GitHub Exploit DB Packet Storm
226438 7.5 危険 punres - PunBB 用の Affiliation モジュールの affiliates.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-2308 2012-12-20 19:10 2009-07-2 Show GitHub Exploit DB Packet Storm
226439 7.5 危険 tutorial-share - Optimum Web Design Tutorial Share における認証を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2009-2293 2012-12-20 19:10 2009-07-1 Show GitHub Exploit DB Packet Storm
226440 4.3 警告 The phpMyAdmin Project - phpMyAdmin におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-2284 2012-12-20 19:10 2009-06-30 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 11, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
197021 8.8 HIGH
Network
hutchhouse marketo_forms_and_tracking The marketo-forms-and-tracking plugin through 1.0.2 for WordPress allows wp-admin/admin.php?page=marketo_fat CSRF with resultant XSS. CWE-352
 Origin Validation Error
CVE-2020-6849 2024-11-21 14:36 2020-01-22 Show GitHub Exploit DB Packet Storm
197022 9.8 CRITICAL
Network
simplejobscript simplejobscript An issue was discovered in Simplejobscript.com SJS before 1.65. There is unauthenticated SQL injection via the search engine. The parameter is landing_location. The function is countSearchedJobs(). T… CWE-89
SQL Injection
CVE-2020-7229 2024-11-21 14:36 2020-01-22 Show GitHub Exploit DB Packet Storm
197023 7.5 HIGH
Network
parallels parallels Parallels 13 uses cleartext HTTP as part of the update process, allowing man-in-the-middle attacks. Users of out-of-date versions are presented with a pop-up window for a parallels_updates.xml file o… CWE-312
 Cleartext Storage of Sensitive Information
CVE-2020-7213 2024-11-21 14:36 2020-01-22 Show GitHub Exploit DB Packet Storm
197024 7.5 HIGH
Network
libslirp_project
qemu
libslirp
qemu
tftp.c in libslirp 4.1.0, as used in QEMU 4.2.0, does not prevent ..\ directory traversal on Windows. CWE-22
Path Traversal
CVE-2020-7211 2024-11-21 14:36 2020-01-22 Show GitHub Exploit DB Packet Storm
197025 5.5 MEDIUM
Local
taskautomation carbonftp CarbonFTP v1.4 uses insecure proprietary password encryption with a hard-coded weak encryption key. The key for local FTP server passwords is hard-coded in the binary. CWE-798
CWE-327
 Use of Hard-coded Credentials
 Use of a Broken or Risky Cryptographic Algorithm
CVE-2020-6857 2024-11-21 14:36 2020-01-22 Show GitHub Exploit DB Packet Storm
197026 8.8 HIGH
Network
qdpm qdpm A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code file via the profile photo functionality, by leveraging a path traversal vulner… CWE-22
CWE-434
Path Traversal
 Unrestricted Upload of File with Dangerous Type 
CVE-2020-7246 2024-11-21 14:36 2020-01-21 Show GitHub Exploit DB Packet Storm
197027 6.1 MEDIUM
Network
ibm chatbot_with_ibm_watson The conversation-watson plugin before 0.8.21 for WordPress has a DOM-based XSS vulnerability that is executed when a chat message containing JavaScript is sent. CWE-79
Cross-site Scripting
CVE-2020-7239 2024-11-21 14:36 2020-01-21 Show GitHub Exploit DB Packet Storm
197028 4.8 MEDIUM
Network
smc d3g0804_firmware SMC D3G0804W 3.5.2.5-LAT_GA devices allow XSS via the SSID field on the WiFi Network Configuration page (after a successful login to the admin account). CWE-79
Cross-site Scripting
CVE-2020-7249 2024-11-21 14:36 2020-01-21 Show GitHub Exploit DB Packet Storm
197029 7.2 HIGH
Network
comtechtel stampede_fx-1010_firmware Comtech Stampede FX-1010 7.4.3 devices allow remote authenticated administrators to achieve remote code execution by navigating to the Poll Routes page and entering shell metacharacters in the Router… CWE-78
OS Command 
CVE-2020-7244 2024-11-21 14:36 2020-01-21 Show GitHub Exploit DB Packet Storm
197030 7.2 HIGH
Network
comtechtel stampede_fx-1010_firmware Comtech Stampede FX-1010 7.4.3 devices allow remote authenticated administrators to achieve remote code execution by navigating to the Fetch URL page and entering shell metacharacters in the URL fiel… CWE-78
OS Command 
CVE-2020-7243 2024-11-21 14:36 2020-01-21 Show GitHub Exploit DB Packet Storm