Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 14, 2026, 2:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
226511 9.3 危険 Pegasus Mail - PMail におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-3838 2012-12-20 19:28 2009-11-2 Show GitHub Exploit DB Packet Storm
226512 7.5 危険 whorl ltd - Joomla! 用の JShop コンポーネントにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-3835 2012-12-20 19:28 2009-11-2 Show GitHub Exploit DB Packet Storm
226513 7.5 危険 webguerilla - Joomla! 用の Photoblog コンポーネントにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-3834 2012-12-20 19:28 2009-11-2 Show GitHub Exploit DB Packet Storm
226514 4.3 警告 tftgallery - TFTgallery の index.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-3833 2012-12-20 19:28 2009-11-2 Show GitHub Exploit DB Packet Storm
226515 5 警告 squidguard - squidGuard におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-3826 2012-12-20 19:28 2009-10-28 Show GitHub Exploit DB Packet Storm
226516 7.5 危険 thomas graber - GenCMS におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2009-3825 2012-12-20 19:28 2009-10-28 Show GitHub Exploit DB Packet Storm
226517 10 危険 Urs Maag - TYPO3 用の maag_randomimage エクステンションにおける任意のシェルコマンドを実行される脆弱性 CWE-noinfo
情報不足
CVE-2009-3819 2012-12-20 19:28 2009-10-28 Show GitHub Exploit DB Packet Storm
226518 10 危険 Stanislas Rolland - TYPO3 用の sr_freecap エクステンションのセッションハンドリング機能における脆弱性 CWE-noinfo
情報不足
CVE-2009-3818 2012-12-20 19:28 2009-10-28 Show GitHub Exploit DB Packet Storm
226519 5 警告 runcms - RunCMS における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2009-3815 2012-12-20 19:28 2009-10-27 Show GitHub Exploit DB Packet Storm
226520 6.5 警告 runcms - RunCMS における任意の PHP コードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2009-3814 2012-12-20 19:28 2009-10-27 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 14, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
196571 7.4 HIGH
Network
nodejs
opensuse
fedoraproject
node.js
leap
fedora
Node.js < 12.18.4 and < 14.11 can be exploited to perform HTTP desync attacks and deliver malicious payloads to unsuspecting users. The payloads can be crafted by an attacker to hijack user sessions,… CWE-444
HTTP Request Smuggling
CVE-2020-8201 2024-11-21 14:38 2020-09-19 Show GitHub Exploit DB Packet Storm
196572 6.5 MEDIUM
Network
citrix storefront_server Improper authentication in Citrix StoreFront Server < 1912.0.1000 allows an attacker who is authenticated on the same Microsoft Active Directory domain as a Citrix StoreFront server to read arbitrary… CWE-287
Improper Authentication
CVE-2020-8200 2024-11-21 14:38 2020-09-19 Show GitHub Exploit DB Packet Storm
196573 6.1 MEDIUM
Network
citrix application_delivery_controller_firmware
gateway
netscaler_gateway
Improper Input Validation on Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and Net… CWE-79
Cross-site Scripting
CVE-2020-8245 2024-11-21 14:38 2020-09-19 Show GitHub Exploit DB Packet Storm
196574 9.8 CRITICAL
Network
typeorm typeorm Prototype pollution vulnerability in the TypeORM package < 0.2.25 may allow attackers to add or modify Object properties leading to further denial of service or SQL injection attacks. CWE-1321
 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVE-2020-8158 2024-11-21 14:38 2020-09-19 Show GitHub Exploit DB Packet Storm
196575 5.5 MEDIUM
Local
puppet continuous_delivery Local registry credentials were included directly in the CD4PE deployment definition, which could expose these credentials to users who should not have access to them. This is resolved in Continuous … CWE-522
 Insufficiently Protected Credentials
CVE-2020-7945 2024-11-21 14:38 2020-09-19 Show GitHub Exploit DB Packet Storm
196576 9.3 CRITICAL
Local
suse salt-netapi-client A Improper Access Control vulnerability in the configuration of salt of SUSE Linux Enterprise Module for SUSE Manager Server 4.1, SUSE Manager Proxy 4.0, SUSE Manager Retail Branch Server 4.0, SUSE M… - CVE-2020-8028 2024-11-21 14:38 2020-09-17 Show GitHub Exploit DB Packet Storm
196577 5.5 MEDIUM
Local
lenovo system_interface_foundation A denial of service vulnerability was reported in the Lenovo Vantage component called Lenovo System Interface Foundation prior to version 1.1.19.5 that could allow configuration files to be written t… CWE-276
Incorrect Default Permissions 
CVE-2020-8346 2024-11-21 14:38 2020-09-16 Show GitHub Exploit DB Packet Storm
196578 7.0 HIGH
Local
lenovo system_update A race condition vulnerability was reported in Lenovo System Update prior to version 5.07.0106 that could allow escalation of privilege. CWE-362
Race Condition
CVE-2020-8342 2024-11-21 14:38 2020-09-16 Show GitHub Exploit DB Packet Storm
196579 6.1 MEDIUM
Network
lenovo integrated_management_module_2 A cross-site scripting (XSS) vulnerability was discovered in the legacy IBM and Lenovo System x IMM2 (Integrated Management Module 2), prior to version 5.60, embedded Baseboard Management Controller … CWE-79
Cross-site Scripting
CVE-2020-8340 2024-11-21 14:38 2020-09-16 Show GitHub Exploit DB Packet Storm
196580 6.1 MEDIUM
Network
ibm bladecenter_advanced_management_module_firmware A cross-site scripting inclusion (XSSI) vulnerability was reported in the legacy IBM BladeCenter Advanced Management Module (AMM) web interface prior to version 3.68n [BPET68N]. This vulnerability co… CWE-79
Cross-site Scripting
CVE-2020-8339 2024-11-21 14:38 2020-09-16 Show GitHub Exploit DB Packet Storm