Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 5, 2026, noon

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
226741 4.3 警告 vBulletin Solutions, Inc. - vBulletin におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-3184 2012-12-20 18:52 2008-07-7 Show GitHub Exploit DB Packet Storm
226742 9.3 危険 speedbit - DAP の DAP.exe におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-3182 2012-12-20 18:52 2008-07-15 Show GitHub Exploit DB Packet Storm
226743 7.5 危険 w2b - W2B phpDatingClub の website.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-3179 2012-12-20 18:52 2008-07-15 Show GitHub Exploit DB Packet Storm
226744 7.5 危険 webxell - WebXell Editor の upload_pictures.php における任意のコードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2008-3178 2012-12-20 18:52 2008-07-15 Show GitHub Exploit DB Packet Storm
226745 5 警告 ソフォス - Linux および Unix 上で稼動している Sophos ウィルス検出エンジンにおけるサービス運用妨害 (DoS) の脆弱性 CWE-16
環境設定
CVE-2008-3177 2012-12-20 18:52 2008-07-15 Show GitHub Exploit DB Packet Storm
226746 6.8 警告 regretless - DodosMail の dodosmail.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-3163 2012-12-20 18:52 2008-07-14 Show GitHub Exploit DB Packet Storm
226747 7.5 危険 webblizzard - WebBlizzard CMS の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3154 2012-12-20 18:52 2008-07-11 Show GitHub Exploit DB Packet Storm
226748 7.5 危険 tritoncms - Triton CMS Pro における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3153 2012-12-20 18:52 2008-07-11 Show GitHub Exploit DB Packet Storm
226749 7.5 危険 warpspeed
PHPNUKE
- PHP-Nuke 用の 4ndvddb モジュールにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3151 2012-12-20 18:52 2008-07-11 Show GitHub Exploit DB Packet Storm
226750 4.7 警告 wefi - WeFi における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2008-3147 2012-12-20 18:52 2008-07-11 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 5, 2026, 4:51 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
197431 6.1 MEDIUM
Network
ibm business_process_manager
business_automation_workflow
IBM Business Automation Workflow 18 and 19, and IBM Business Process Manager 8.0, 8.5, and 8.6 could allow a remote attacker to bypass security restrictions, caused by a reverse tabnabbing flaw. An a… NVD-CWE-Other
CVE-2020-4490 2024-11-21 14:32 2020-05-29 Show GitHub Exploit DB Packet Storm
197432 7.0 HIGH
Local
ibm mq_for_hpe_nonstop IBM MQ on HPE NonStop 8.0.4 and 8.1.0 is vulnerable to a privilege escalation attack when running in restricted mode. IBM X-Force ID: 178427. NVD-CWE-noinfo
CVE-2020-4352 2024-11-21 14:32 2020-05-29 Show GitHub Exploit DB Packet Storm
197433 5.4 MEDIUM
Network
ibm planning_analytics_local IBM Planning Analytics Local 2.0.0 through 2.0.9 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended fun… CWE-79
Cross-site Scripting
CVE-2020-4306 2024-11-21 14:32 2020-05-29 Show GitHub Exploit DB Packet Storm
197434 2.7 LOW
Network
ibm security_identity_governance_and_intelligence IBM Security Identity Governance and Intelligence 5.2.6 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This informat… CWE-209
Information Exposure Through an Error Message
CVE-2020-4248 2024-11-21 14:32 2020-05-29 Show GitHub Exploit DB Packet Storm
197435 5.4 MEDIUM
Network
ibm jazz_reporting_service IBM Jazz Reporting Service 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended f… CWE-79
Cross-site Scripting
CVE-2020-4419 2024-11-21 14:32 2020-05-29 Show GitHub Exploit DB Packet Storm
197436 6.5 MEDIUM
Network
ibm security_identity_governance_and_intelligence IBM Security Identity Governance and Intelligence 5.2.6 could disclose highly sensitive information to other authenticated users on the sytem due to incorrect authorization. IBM X-Force ID: 175485. CWE-863
 Incorrect Authorization
CVE-2020-4249 2024-11-21 14:32 2020-05-29 Show GitHub Exploit DB Packet Storm
197437 7.1 HIGH
Network
ibm security_identity_governance_and_intelligence IBM Security Identity Governance and Intelligence 5.2.6 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to … CWE-611
XXE
CVE-2020-4246 2024-11-21 14:32 2020-05-29 Show GitHub Exploit DB Packet Storm
197438 7.5 HIGH
Network
ibm security_identity_governance_and_intelligence IBM Security Identity Governance and Intelligence 5.2.6 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-For… CWE-521
Weak Password Requirements 
CVE-2020-4245 2024-11-21 14:32 2020-05-29 Show GitHub Exploit DB Packet Storm
197439 5.3 MEDIUM
Network
ibm security_identity_governance_and_intelligence IBM Security Identity Governance and Intelligence 5.2.6 could allow an unauthorized user to obtain sensitive information through user enumeration. IBM X-Force ID: 175422. NVD-CWE-noinfo
CVE-2020-4244 2024-11-21 14:32 2020-05-29 Show GitHub Exploit DB Packet Storm
197440 5.3 MEDIUM
Network
ibm security_identity_governance_and_intelligence IBM Security Identity Governance and Intelligence 5.2.6 could allow a remote attacker to obtain sensitive information, caused by the failure to set the secure flag for the session cookie in SSL mode.… CWE-311
Missing Encryption of Sensitive Data
CVE-2020-4233 2024-11-21 14:32 2020-05-29 Show GitHub Exploit DB Packet Storm