Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 10, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
226741 7.5 危険 w3matter - W3matter AskPert の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6309 2012-12-20 19:10 2009-02-26 Show GitHub Exploit DB Packet Storm
226742 5.1 警告 PunBB - PunBB 用の PMS におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-6308 2012-12-20 19:10 2009-02-26 Show GitHub Exploit DB Packet Storm
226743 4.3 警告 SoftbizScripts - Softbiz Classifieds Script の signinform.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-6306 2012-12-20 19:10 2009-02-26 Show GitHub Exploit DB Packet Storm
226744 7.5 危険 toursmanager - ToursManager の tourview.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6303 2012-12-20 19:10 2009-02-26 Show GitHub Exploit DB Packet Storm
226745 7.5 危険 turnkeyforms - TurnkeyForms Local Classifieds における認証を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-6302 2012-12-20 19:10 2009-02-26 Show GitHub Exploit DB Packet Storm
226746 7.5 危険 prezmo - phpBB 用の Small ShoutBox モジュールにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6301 2012-12-20 19:10 2009-02-26 Show GitHub Exploit DB Packet Storm
226747 7.5 危険 toursmanager - Tours Manager の cityview.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6289 2012-12-20 19:10 2009-02-26 Show GitHub Exploit DB Packet Storm
226748 4.3 警告 subtextproject - Subtext におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-6283 2012-12-20 19:10 2009-02-25 Show GitHub Exploit DB Packet Storm
226749 7.8 危険 rakhisoftware - RakhiSoftware Price Comparison Script における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2008-6279 2012-12-20 19:10 2009-02-25 Show GitHub Exploit DB Packet Storm
226750 4.3 警告 rakhisoftware - RakhiSoftware Price Comparison Script の product.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-6278 2012-12-20 19:10 2009-02-25 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 11, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
210501 6.5 MEDIUM
Network
mozilla
canonical
opensuse
firefox
firefox_esr
thunderbird
ubuntu_linux
leap
Manipulating individual parts of a URL object could have caused an out-of-bounds read, leaking process memory to malicious JavaScript. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, an… CWE-125
Out-of-bounds Read
CVE-2020-12418 2024-11-21 13:59 2020-07-10 Show GitHub Exploit DB Packet Storm
210502 8.8 HIGH
Network
mozilla
canonical
opensuse
firefox
thunderbird
firefox_esr
ubuntu_linux
leap
Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier, resulting in memory corruption and a potentially exploitable crash. *Note: this issue only affects… CWE-787
CWE-617
CWE-681
 Out-of-bounds Write
 Reachable Assertion
 Incorrect Conversion between Numeric Types
CVE-2020-12417 2024-11-21 13:59 2020-07-10 Show GitHub Exploit DB Packet Storm
210503 8.8 HIGH
Network
mozilla
opensuse
firefox
leap
A VideoStreamEncoder may have been freed in a race condition with VideoBroadcaster::AddOrUpdateSink, resulting in a use-after-free, memory corruption, and a potentially exploitable crash. This vulner… CWE-362
CWE-416
Race Condition
 Use After Free
CVE-2020-12416 2024-11-21 13:59 2020-07-10 Show GitHub Exploit DB Packet Storm
210504 6.5 MEDIUM
Network
mozilla
opensuse
firefox
leap
When "%2F" was present in a manifest URL, Firefox's AppCache behavior may have become confused and allowed a manifest to be served from a subdirectory. This could cause the appcache to be used to ser… CWE-276
Incorrect Default Permissions 
CVE-2020-12415 2024-11-21 13:59 2020-07-10 Show GitHub Exploit DB Packet Storm
210505 6.5 MEDIUM
Network
mozilla firefox IndexedDB should be cleared when leaving private browsing mode and it is not, the API for WKWebViewConfiguration was being used incorrectly and requires the private instance of this object be deleted… CWE-459
 Incomplete Cleanup
CVE-2020-12414 2024-11-21 13:59 2020-07-10 Show GitHub Exploit DB Packet Storm
210506 4.3 MEDIUM
Network
mozilla firefox By navigating a tab using the history API, an attacker could cause the address bar to display the incorrect domain (with the https:// scheme, a blocked port number such as '1', and without a lock ico… NVD-CWE-Other
CVE-2020-12412 2024-11-21 13:59 2020-07-10 Show GitHub Exploit DB Packet Storm
210507 8.8 HIGH
Network
mozilla firefox Mozilla developers reported memory safety bugs present in Firefox 76. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been expl… CWE-787
 Out-of-bounds Write
CVE-2020-12411 2024-11-21 13:59 2020-07-10 Show GitHub Exploit DB Packet Storm
210508 8.8 HIGH
Network
mozilla
canonical
firefox
firefox_esr
ubuntu_linux
Mozilla developers reported memory safety bugs present in Firefox 76 and Firefox ESR 68.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these… CWE-787
 Out-of-bounds Write
CVE-2020-12410 2024-11-21 13:59 2020-07-10 Show GitHub Exploit DB Packet Storm
210509 8.8 HIGH
Network
mozilla firefox When using certain blank characters in a URL, they where incorrectly rendered as spaces instead of an encoded URL. This vulnerability affects Firefox < 77. NVD-CWE-Other
CVE-2020-12409 2024-11-21 13:59 2020-07-10 Show GitHub Exploit DB Packet Storm
210510 6.5 MEDIUM
Network
mozilla firefox When browsing a document hosted on an IP address, an attacker could insert certain characters to flip domain and path information in the address bar. This vulnerability affects Firefox < 77. NVD-CWE-noinfo
CVE-2020-12408 2024-11-21 13:59 2020-07-10 Show GitHub Exploit DB Packet Storm