Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 7, 2026, 12:09 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
226821 4.3 警告 Pligg - Pligg の index.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-3572 2012-12-20 18:52 2008-08-10 Show GitHub Exploit DB Packet Storm
226822 7.8 危険 Xerox - Xerox Phaser におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2008-3571 2012-12-20 18:52 2008-08-10 Show GitHub Exploit DB Packet Storm
226823 7.5 危険 unak - UNAK-CMS の fckeditor/editor/filemanager/browser/default/connectors/php/connector.php における絶対パストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-3568 2012-12-20 18:52 2008-08-10 Show GitHub Exploit DB Packet Storm
226824 4.3 警告 ZoneO-soft - ZoneO-soft freeForum におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-3566 2012-12-20 18:52 2008-08-10 Show GitHub Exploit DB Packet Storm
226825 7.5 危険 Plogger Project - Plogger における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3563 2012-12-20 18:52 2008-07-29 Show GitHub Exploit DB Packet Storm
226826 6.8 警告 powergap - Powergap Shopsystem の s03.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3561 2012-12-20 18:52 2008-08-10 Show GitHub Exploit DB Packet Storm
226827 6.8 警告 wsnlinks - WSN Forum などの index.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-3555 2012-12-20 18:52 2008-08-8 Show GitHub Exploit DB Packet Storm
226828 10 危険 サン・マイクロシステムズ - Nokia Series 40 3rd エディションデバイスにおける任意のコードを実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-3553 2012-12-20 18:52 2008-08-8 Show GitHub Exploit DB Packet Storm
226829 10 危険 サン・マイクロシステムズ - Sun Wireless Toolkit で同梱されている Sun Java Platform Micro Edition における任意のコードを実行される脆弱性 CWE-noinfo
情報不足
CVE-2008-3551 2012-12-20 18:52 2008-08-8 Show GitHub Exploit DB Packet Storm
226830 4.9 警告 サン・マイクロシステムズ - Sun Netra T5220 Server におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2008-3548 2012-12-20 18:52 2008-08-4 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 7, 2026, 4:22 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
197031 7.5 HIGH
Network
yamaha rtx830_firmware
nvr510_firmware
nvr700w_firmware
rtx1210_firmware
rtx5000_firmware
rtx3500_firmware
fwx120_firmware
rtx810_firmware
nvr500_firmware
rtx1200_firmware
Yamaha LTE VoIP Router(NVR700W firmware Rev.15.00.15 and earlier), Yamaha Gigabit VoIP Router(NVR510 firmware Rev.15.01.14 and earlier), Yamaha Gigabit VPN Router(RTX810 firmware Rev.11.01.33 and ear… NVD-CWE-noinfo
CVE-2020-5548 2024-11-21 14:34 2020-04-1 Show GitHub Exploit DB Packet Storm
197032 9.8 CRITICAL
Network
lifterlms lifterlms LifterLMS Wordpress plugin version below 3.37.15 is vulnerable to arbitrary file write leading to remote code execution CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2020-6008 2024-11-21 14:34 2020-04-1 Show GitHub Exploit DB Packet Storm
197033 7.5 HIGH
Network
grandstream ucm6202_firmware
ucm6204_firmware
ucm6208_firmware
The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the CTI server on port 8888. A remote unauthenticated attacker can invoke the challenge action with a crafted use… CWE-89
SQL Injection
CVE-2020-5726 2024-11-21 14:34 2020-03-31 Show GitHub Exploit DB Packet Storm
197034 5.9 MEDIUM
Network
grandstream ucm6202_firmware
ucm6204_firmware
ucm6208_firmware
The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpoint. A remote unauthenticated attacker can invoke the login action with a craft… CWE-89
SQL Injection
CVE-2020-5725 2024-11-21 14:34 2020-03-31 Show GitHub Exploit DB Packet Storm
197035 7.5 HIGH
Network
grandstream ucm6202_firmware
ucm6204_firmware
ucm6208_firmware
The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpoint. A remote unauthenticated attacker can invoke the challenge action with a c… CWE-89
SQL Injection
CVE-2020-5724 2024-11-21 14:34 2020-03-31 Show GitHub Exploit DB Packet Storm
197036 9.8 CRITICAL
Network
grandstream ucm6202_firmware
ucm6204_firmware
ucm6208_firmware
The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database. This could allow an attacker to retrieve all passwords and possibly gain elevated privileges. CWE-312
 Cleartext Storage of Sensitive Information
CVE-2020-5723 2024-11-21 14:34 2020-03-31 Show GitHub Exploit DB Packet Storm
197037 7.5 HIGH
Network
mitsubishielectric cr800-q_firmware
fx3g_firmware
fx3gc_firmware
fx3s_firmware
fx3u_firmware
fx3uc_firmware
fx5u_firmware
fx5uc_firmware
fx5uj_firmware
l02cpu_firmware
l02cpu-p_firmware
When MELSOFT transmission port (UDP/IP) of Mitsubishi Electric MELSEC iQ-R series (all versions), MELSEC iQ-F series (all versions), MELSEC Q series (all versions), MELSEC L series (all versions), an… CWE-400
 Uncontrolled Resource Consumption
CVE-2020-5527 2024-11-21 14:34 2020-03-30 Show GitHub Exploit DB Packet Storm
197038 8.8 HIGH
Adjacent
toyota display_control_unit Toyota 2017 Model Year DCU (Display Control Unit) allows an unauthenticated attacker within Bluetooth range to cause a denial of service attack and/or execute an arbitrary command. The affected DCUs … CWE-276
Incorrect Default Permissions 
CVE-2020-5551 2024-11-21 14:34 2020-03-30 Show GitHub Exploit DB Packet Storm
197039 8.6 HIGH
Network
f5
netapp
nginx_controller
cloud_backup
In NGINX Controller versions prior to 3.2.0, an unauthenticated attacker with network access to the Controller API can create unprivileged user accounts. The user which is created is only able to upl… NVD-CWE-noinfo
CVE-2020-5863 2024-11-21 14:34 2020-03-28 Show GitHub Exploit DB Packet Storm
197040 7.5 HIGH
Network
f5 big-ip_access_policy_manager
big-ip_advanced_firewall_manager
big-ip_analytics
big-ip_application_acceleration_manager
big-ip_application_security_manager
big-ip_domain_name_system
On BIG-IP 15.1.0-15.1.0.1, 15.0.0-15.0.1.1, and 14.1.0-14.1.2.2, under certain conditions, TMM may crash or stop processing new traffic with the DPDK/ENA driver on AWS systems while sending traffic. … NVD-CWE-noinfo
CVE-2020-5862 2024-11-21 14:34 2020-03-28 Show GitHub Exploit DB Packet Storm