Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 17, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
226861 6.8 警告 zenas - Zenas PaoBacheca Guestbook の login.php における認証を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2009-3421 2012-12-20 19:28 2009-09-25 Show GitHub Exploit DB Packet Storm
226862 6.5 警告 Plume CMS - Plume CMS における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-3418 2012-12-20 19:28 2009-09-25 Show GitHub Exploit DB Packet Storm
226863 4.3 警告 Plohni - An image gallery におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-3367 2012-12-20 19:28 2009-09-24 Show GitHub Exploit DB Packet Storm
226864 5 警告 Plohni - An image gallery の navigation.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2009-3366 2012-12-20 19:28 2009-09-24 Show GitHub Exploit DB Packet Storm
226865 7.5 危険 traza - Aurora CMS の add-ons/modules/sysmanager/plugins/install.plugin.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2009-3365 2012-12-20 19:28 2009-09-24 Show GitHub Exploit DB Packet Storm
226866 4.3 警告 ufku bayburt - Drupal 用の BUEditor モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-3363 2012-12-20 19:28 2009-09-9 Show GitHub Exploit DB Packet Storm
226867 7.5 危険 sznews - SZNews の printnews.php3 における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2009-3362 2012-12-20 19:28 2009-09-24 Show GitHub Exploit DB Packet Storm
226868 7.5 危険 tourismscripts - Tourism Scripts Adult Portal エスコートリストの profile.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-3358 2012-12-20 19:28 2009-09-24 Show GitHub Exploit DB Packet Storm
226869 7.5 危険 Plohni - Image voting の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-3356 2012-12-20 19:28 2009-09-24 Show GitHub Exploit DB Packet Storm
226870 10 危険 Steve Lockwood - Drupal 用の Node2Node モジュールにおける脆弱性 CWE-noinfo
情報不足
CVE-2009-3353 2012-12-20 19:28 2009-09-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 17, 2026, 4:15 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
214301 5.3 MEDIUM
Network
zammad zammad An issue was discovered in Zammad 3.0 through 3.2. It returns source code of static resources when submitting an OPTIONS request, rather than a GET request. Disclosure of source code allows for an at… CWE-552
 Files or Directories Accessible to External Parties
CVE-2020-10105 2024-11-21 13:54 2020-03-5 Show GitHub Exploit DB Packet Storm
214302 4.3 MEDIUM
Network
zammad zammad An issue was discovered in Zammad 3.0 through 3.2. After authentication, it transmits sensitive information to the user that may be compromised and used by an attacker to gain unauthorized access. Ha… CWE-200
Information Exposure
CVE-2020-10104 2024-11-21 13:54 2020-03-5 Show GitHub Exploit DB Packet Storm
214303 5.4 MEDIUM
Network
zammad zammad An XSS issue was discovered in Zammad 3.0 through 3.2. Malicious code can be provided by a low-privileged user through the File Upload functionality in Zammad. The malicious JavaScript will execute w… CWE-79
Cross-site Scripting
CVE-2020-10103 2024-11-21 13:54 2020-03-5 Show GitHub Exploit DB Packet Storm
214304 7.5 HIGH
Network
zammad zammad An issue was discovered in Zammad 3.0 through 3.2. The WebSocket server crashes when messages in non-JSON format are sent by an attacker. The message format is not properly checked and parsing errors… CWE-20
CWE-755
 Improper Input Validation 
 Improper Handling of Exceptional Conditions
CVE-2020-10101 2024-11-21 13:54 2020-03-5 Show GitHub Exploit DB Packet Storm
214305 5.4 MEDIUM
Network
zammad zammad An XSS issue was discovered in Zammad 3.0 through 3.2. Malicious code can be provided by a low-privileged user through the Ticket functionality in Zammad. The malicious JavaScript will execute within… CWE-79
Cross-site Scripting
CVE-2020-10099 2024-11-21 13:54 2020-03-5 Show GitHub Exploit DB Packet Storm
214306 5.4 MEDIUM
Network
zammad zammad An XSS issue was discovered in Zammad 3.0 through 3.2. Malicious code can be provided by a low-privileged user through the Email functionality. The malicious JavaScript will execute within the browse… CWE-79
Cross-site Scripting
CVE-2020-10098 2024-11-21 13:54 2020-03-5 Show GitHub Exploit DB Packet Storm
214307 5.3 MEDIUM
Network
zammad zammad An issue was discovered in Zammad 3.0 through 3.2. It may respond with verbose error messages that disclose internal application or infrastructure information. This information could aid attackers in… CWE-209
Information Exposure Through an Error Message
CVE-2020-10097 2024-11-21 13:54 2020-03-5 Show GitHub Exploit DB Packet Storm
214308 7.5 HIGH
Network
zammad zammad An issue was discovered in Zammad 3.0 through 3.2. It does not prevent caching of confidential data within browser memory. An attacker who either remotely compromises or obtains physical access to a … CWE-200
Information Exposure
CVE-2020-10096 2024-11-21 13:54 2020-03-5 Show GitHub Exploit DB Packet Storm
214309 8.8 HIGH
Network
metalgenix genixcms GeniXCMS 1.1.7 is vulnerable to user privilege escalation due to broken access control. This issue exists because of an incomplete fix for CVE-2015-2680, in which "token" is used as a CSRF protection… CWE-352
 Origin Validation Error
CVE-2020-10057 2024-11-21 13:54 2020-03-5 Show GitHub Exploit DB Packet Storm
214310 5.3 MEDIUM
Network
zammad zammad An issue was discovered in Zammad 3.0 through 3.2. The Forgot Password functionality is implemented in a way that would enable an anonymous user to guess valid user emails. In the current implementat… CWE-203
 Information Exposure Through Discrepancy
CVE-2020-10102 2024-11-21 13:54 2020-03-5 Show GitHub Exploit DB Packet Storm