Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 11, 2026, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
227331 9.3 危険 Realtek Semiconductor Corp - Realtek Media Player におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-5664 2012-12-20 18:52 2008-12-18 Show GitHub Exploit DB Packet Storm
227332 7.5 危険 Quassel IRC - Quassel Core における CRLF インジェクションの脆弱性 CWE-20
不適切な入力確認
CVE-2008-5657 2012-12-20 18:52 2008-10-27 Show GitHub Exploit DB Packet Storm
227333 4.3 警告 TYPO3 Association - TYPO3 の felogin system エクステンション用の frontend プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-5656 2012-12-20 18:52 2008-12-17 Show GitHub Exploit DB Packet Storm
227334 5 警告 Edgewall Software - Trac の HTML サニタイズフィルタにおけるフィッシング攻撃を実行される脆弱性 CWE-noinfo
情報不足
CVE-2008-5647 2012-12-20 18:52 2008-12-17 Show GitHub Exploit DB Packet Storm
227335 7.5 危険 Edgewall Software - Trac におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2008-5646 2012-12-20 18:52 2008-12-17 Show GitHub Exploit DB Packet Storm
227336 4.3 警告 TYPO3 Association - TYPO3 用の file backend モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-5644 2012-12-20 18:52 2008-12-17 Show GitHub Exploit DB Packet Storm
227337 4.3 警告 txtblogcms - TxtBlog の index.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-5639 2012-12-20 18:52 2008-12-17 Show GitHub Exploit DB Packet Storm
227338 6.8 警告 qualityunit - Post Affiliate Pro の merchants/index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-5630 2012-12-20 18:52 2008-12-17 Show GitHub Exploit DB Packet Storm
227339 7.5 危険 turnkeyarcade - Turnkey Arcade Script の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-5629 2012-12-20 18:52 2008-12-17 Show GitHub Exploit DB Packet Storm
227340 7.8 危険 Roundcube.net - roundcubemail におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2008-5620 2012-12-20 18:52 2008-12-16 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 11, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
196281 5.3 MEDIUM
Network
absolunet kafe This affects the package @absolunet/kafe before 3.2.10. It allows cause a denial of service when validating crafted invalid emails. NVD-CWE-noinfo
CVE-2020-7761 2024-11-21 14:37 2020-11-5 Show GitHub Exploit DB Packet Storm
196282 7.5 HIGH
Network
browserless chrome This affects versions of package browserless-chrome before 1.40.2-chrome-stable. User input flowing from the workspace endpoint gets used to create a file path filePath and this is fetched and then s… CWE-22
Path Traversal
CVE-2020-7758 2024-11-21 14:37 2020-11-3 Show GitHub Exploit DB Packet Storm
196283 6.5 MEDIUM
Network
droppy_project droppy This affects all versions of package droppy. It is possible to traverse directories to fetch configuration files from a droopy server. CWE-22
Path Traversal
CVE-2020-7757 2024-11-21 14:37 2020-11-3 Show GitHub Exploit DB Packet Storm
196284 9.8 CRITICAL
Network
vbulletin vbulletin vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. NOTE: this issue exists because of an incomplete … CWE-94
Code Injection
CVE-2020-7373 2024-11-21 14:37 2020-10-31 Show GitHub Exploit DB Packet Storm
196285 7.5 HIGH
Network
codemirror
oracle
codemirror
application_express
essbase
enterprise_manager_express_user_interface
hyperion_data_relationship_management
spatial_studio
This affects the package codemirror before 5.58.2; the package org.apache.marmotta.webjars:codemirror before 5.58.2. The vulnerable regular expression is located in https://github.com/codemirror/Code… CWE-400
 Uncontrolled Resource Consumption
CVE-2020-7760 2024-11-21 14:37 2020-10-30 Show GitHub Exploit DB Packet Storm
196286 7.2 HIGH
Network
pimcore pimcore The package pimcore/pimcore from 6.7.2 and before 6.8.3 are vulnerable to SQL Injection in data classification functionality in ClassificationstoreController. This can be exploited by sending a speci… CWE-89
SQL Injection
CVE-2020-7759 2024-11-21 14:37 2020-10-30 Show GitHub Exploit DB Packet Storm
196287 7.8 HIGH
Local
rapid7 metasploit Rapid7's Metasploit msfvenom framework handles APK files in a way that allows for a malicious user to craft and publish a file that would execute arbitrary commands on a victim's machine. CWE-77
Command Injection
CVE-2020-7384 2024-11-21 14:37 2020-10-30 Show GitHub Exploit DB Packet Storm
196288 9.8 CRITICAL
Network
chartjs chart.js This affects the package chart.js before 2.9.4. The options parameter is not properly sanitized when it is processed. When the options are processed, the existing options (or the defaults options) ar… CWE-1321
 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVE-2020-7746 2024-11-21 14:37 2020-10-29 Show GitHub Exploit DB Packet Storm
196289 7.5 HIGH
Network
dat.gui_project dat.gui All versions of package dat.gui are vulnerable to Regular Expression Denial of Service (ReDoS) via specifically crafted rgb and rgba values. CWE-400
 Uncontrolled Resource Consumption
CVE-2020-7755 2024-11-21 14:37 2020-10-28 Show GitHub Exploit DB Packet Storm
196290 7.5 HIGH
Network
npmjs npm-user-validate This affects the package npm-user-validate before 1.0.1. The regex that validates user emails took exponentially longer to process long input strings beginning with @ characters. NVD-CWE-noinfo
CVE-2020-7754 2024-11-21 14:37 2020-10-28 Show GitHub Exploit DB Packet Storm