Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 11, 2026, 12:16 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
226881 7.5 危険 thehockeystop - TheHockeyStop HockeySTATS Online における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-7085 2012-12-20 19:10 2009-08-26 Show GitHub Exploit DB Packet Storm
226882 7.5 危険 revou - ReVou Micro Blogging Twitter クローンにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-7083 2012-12-20 19:10 2009-08-25 Show GitHub Exploit DB Packet Storm
226883 4.3 警告 Simple Machines
phpraider
- Simple Machines phpRaider の不特定のコンポーネントにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-7035 2012-12-20 19:10 2009-08-24 Show GitHub Exploit DB Packet Storm
226884 7.5 危険 tigran abrahamyan - PHPEcho CMS の kernel/smarty/Smarty.class.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2008-7034 2012-12-20 19:10 2009-08-24 Show GitHub Exploit DB Packet Storm
226885 7.5 危険 site2nite - Site2Nite Real Estate Web における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-7030 2012-12-20 19:10 2009-08-24 Show GitHub Exploit DB Packet Storm
226886 10 危険 skalinks - Skalfa Software SkaLinks Exchange Script における管理者を追加される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-7010 2012-12-20 19:10 2009-08-19 Show GitHub Exploit DB Packet Storm
226887 7.5 危険 phpversion - Free PHP VX Guestbook における管理者アクセス権を取得される脆弱性 CWE-287
不適切な認証
CVE-2008-7007 2012-12-20 19:10 2009-08-19 Show GitHub Exploit DB Packet Storm
226888 5 警告 phpversion - Free PHP VX Guestbook におけるデータベースのバックアップをダウンロードされる脆弱性 CWE-287
不適切な認証
CVE-2008-7006 2012-12-20 19:10 2009-08-19 Show GitHub Exploit DB Packet Storm
226889 7.5 危険 the-rat-cms - The Rat CMS の login.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-7003 2012-12-20 19:10 2009-08-19 Show GitHub Exploit DB Packet Storm
226890 7.5 危険 phpauction - PHPAuction の index.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2008-7000 2012-12-20 19:10 2009-08-19 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 11, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
196551 7.8 HIGH
Local
schneider-electric vijeo_designer A CWE-426: Untrusted Search Path vulnerability exists in Vijeo Designer Basic (V1.1 HotFix 15 and prior) and Vijeo Designer (V6.9 SP9 and prior), which could cause arbitrary code execution on the sys… CWE-426
 Untrusted Search Path
CVE-2020-7490 2024-11-21 14:37 2020-04-23 Show GitHub Exploit DB Packet Storm
196552 9.8 CRITICAL
Network
schneider-electric somachine_basic
ecostruxure_machine_expert
modicon_m100_firmware
modicon_m200_firmware
modicon_m221_firmware
A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability exists on EcoStruxure Machine Expert – Basic or SoMachine Basic programming … CWE-74
Injection
CVE-2020-7489 2024-11-21 14:37 2020-04-23 Show GitHub Exploit DB Packet Storm
196553 7.5 HIGH
Network
schneider-electric somachine
somachine_motion
ecostruxure_machine_expert
modicon_m218_firmware
modicon_m241_firmware
modicon_m251_firmware
modicon_m258_firmware
A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists which could leak sensitive information transmitted between the software and the Modicon M218, M241, M251, and M258 cont… CWE-319
Cleartext Transmission of Sensitive Information
CVE-2020-7488 2024-11-21 14:37 2020-04-23 Show GitHub Exploit DB Packet Storm
196554 9.8 CRITICAL
Network
schneider-electric somachine
somachine_motion
ecostruxure_machine_expert
modicon_m218_firmware
modicon_m241_firmware
modicon_m251_firmware
modicon_m258_firmware
A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists which could allow the attacker to execute malicious code on the Modicon M218, M241, M251, and M258 controllers. CWE-345
 Insufficient Verification of Data Authenticity
CVE-2020-7487 2024-11-21 14:37 2020-04-23 Show GitHub Exploit DB Packet Storm
196555 5.4 MEDIUM
Network
lazysizes_project lazysizes lazysizes through 5.2.0 allows execution of malicious JavaScript. The following attributes are not sanitized by the video-embed plugin: data-vimeo, data-vimeoparams, data-youtube and data-ytparams wh… CWE-79
Cross-site Scripting
CVE-2020-7642 2024-11-21 14:37 2020-04-23 Show GitHub Exploit DB Packet Storm
196556 7.5 HIGH
Network
schneider-electric tricon_tcm_4351_firmware
tricon_tcm_4352_firmware
tricon_tcm_4351a_firmware
tricon_tcm_4351b_firmware
tricon_tcm_4352a_firmware
tricon_tcm_4352b_firmware
**VERSION NOT SUPPORTED WHEN ASSIGNED** A vulnerability could cause TCM modules to reset when under high network load in TCM v10.4.x and in system v10.3.x. This vulnerability was discovered and remed… CWE-400
 Uncontrolled Resource Consumption
CVE-2020-7486 2024-11-21 14:37 2020-04-17 Show GitHub Exploit DB Packet Storm
196557 9.8 CRITICAL
Network
schneider-electric tristation_1131 **VERSION NOT SUPPORTED WHEN ASSIGNED** A legacy support account in the TriStation software version v4.9.0 and earlier could cause improper access to the TriStation host machine. This was addressed i… NVD-CWE-noinfo
CVE-2020-7485 2024-11-21 14:37 2020-04-17 Show GitHub Exploit DB Packet Storm
196558 7.5 HIGH
Network
schneider-electric tristation_1131 **VERSION NOT SUPPORTED WHEN ASSIGNED** A vulnerability with the former 'password' feature could allow a denial of service attack if the user is not following documented guidelines pertaining to dedi… NVD-CWE-noinfo
CVE-2020-7484 2024-11-21 14:37 2020-04-17 Show GitHub Exploit DB Packet Storm
196559 7.5 HIGH
Network
schneider-electric tristation_1131 **VERSION NOT SUPPORTED WHEN ASSIGNED** A vulnerability could cause certain data to be visible on the network when the 'password' feature is enabled. This vulnerability was discovered in and remediat… CWE-319
Cleartext Transmission of Sensitive Information
CVE-2020-7483 2024-11-21 14:37 2020-04-17 Show GitHub Exploit DB Packet Storm
196560 5.3 MEDIUM
Network
s3india husky_rtu_6049-e70_firmware The Synergy Systems & Solutions (SSS) HUSKY RTU 6049-E70, with firmware Versions 5.0 and prior, has an Incorrect Default Permissions (CWE-276) vulnerability. The affected product is vulnerable to ins… CWE-276
Incorrect Default Permissions 
CVE-2020-7802 2024-11-21 14:37 2020-04-15 Show GitHub Exploit DB Packet Storm