Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 5, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
227351 5 警告 webwiz - Web Wiz NewsPad の RTE_file_browser.asp におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-0479 2012-12-20 18:34 2008-01-29 Show GitHub Exploit DB Packet Storm
227352 6.8 警告 setcms - SetCMS の index.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-0478 2012-12-20 18:34 2008-01-29 Show GitHub Exploit DB Packet Storm
227353 6.4 警告 webwiz - Web Wiz Rich Text Editor の RTE_popup_save_file.asp における .html ファイルなどをアップロードされる脆弱性 CWE-20
不適切な入力確認
CVE-2008-0473 2012-12-20 18:34 2008-01-29 Show GitHub Exploit DB Packet Storm
227354 4.3 警告 woltlab - wBB の modcp.php におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2008-0472 2012-12-20 18:34 2008-01-29 Show GitHub Exploit DB Packet Storm
227355 4.3 警告 phpBB - phpBB の privmsg.php におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2008-0471 2012-12-20 18:34 2008-01-29 Show GitHub Exploit DB Packet Storm
227356 7.5 危険 tiger php news system - TPNS の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0469 2012-12-20 18:34 2008-01-29 Show GitHub Exploit DB Packet Storm
227357 5 警告 webwiz - Web Wiz Rich Text Edito などで使用されている Web Wiz RTE_file_browser.asp におけるディレクトリトラバーサルの脆弱性 CWE-287
不適切な認証
CVE-2008-0466 2012-12-20 18:34 2008-01-28 Show GitHub Exploit DB Packet Storm
227358 5 警告 seagullproject.org - Seagull の optimizer.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-0465 2012-12-20 18:34 2008-01-25 Show GitHub Exploit DB Packet Storm
227359 6.8 警告 slaed - SLAED CMS の function/sources.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-0458 2012-12-20 18:34 2008-01-25 Show GitHub Exploit DB Packet Storm
227360 10 危険 シマンテック - Symantec Backup Exec System Recovery Manager で使用される Symantec LiveState Apache Tomcat サーバで稼動している FileUpload クラスにおける任意の JSP ファイルをアップロードされる脆弱性 CWE-20
不適切な入力確認
CVE-2008-0457 2012-12-20 18:34 2008-02-4 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 6, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
196761 9.8 CRITICAL
Network
vaaip freelancy Freelancy v1.0.0 allows remote command execution via the "file":"data:application/x-php;base64 substring (in conjunction with "type":"application/x-php"} to the /api/files/ URI. CWE-78
OS Command 
CVE-2020-5505 2024-11-21 14:34 2020-01-15 Show GitHub Exploit DB Packet Storm
196762 5.4 MEDIUM
Network
f5 big-ip_access_policy_manager In BIG-IP APM portal access on versions 15.0.0-15.1.0, 14.0.0-14.1.2.3, 13.1.0-13.1.3.2, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, when backend servers serve HTTP pages with special JavaScript code, this c… CWE-79
Cross-site Scripting
CVE-2020-5853 2024-11-21 14:34 2020-01-15 Show GitHub Exploit DB Packet Storm
196763 7.5 HIGH
Network
f5 big-ip_local_traffic_manager
big-ip_advanced_firewall_manager
big-ip_application_acceleration_manager
big-ip_analytics
big-ip_access_policy_manager
big-ip_application_security_manager<…
Undisclosed traffic patterns received may cause a disruption of service to the Traffic Management Microkernel (TMM). This vulnerability affects TMM through a virtual server configured with a FastL4 p… NVD-CWE-noinfo
CVE-2020-5852 2024-11-21 14:34 2020-01-15 Show GitHub Exploit DB Packet Storm
196764 4.6 MEDIUM
Physics
f5 big-ip_local_traffic_manager
big-ip_advanced_firewall_manager
big-ip_application_acceleration_manager
big-ip_analytics
big-ip_access_policy_manager
big-ip_application_security_manager<…
On impacted versions and platforms the Trusted Platform Module (TPM) system integrity check cannot detect modifications to specific system components. This issue only impacts specific engineering hot… NVD-CWE-Other
CVE-2020-5851 2024-11-21 14:34 2020-01-15 Show GitHub Exploit DB Packet Storm
196765 7.5 HIGH
Network
pysaml2_project
canonical
debian
pysaml2
ubuntu_linux
debian_linux
PySAML2 before 5.0.0 does not check that the signature in a SAML document is enveloped and thus signature wrapping is effective, i.e., it is affected by XML Signature Wrapping (XSW). The signature in… CWE-347
 Improper Verification of Cryptographic Signature
CVE-2020-5390 2024-11-21 14:34 2020-01-14 Show GitHub Exploit DB Packet Storm
196766 8.8 HIGH
Network
phpmyadmin
suse
debian
phpmyadmin
suse_linux_enterprise_server
debian_linux
In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of their own username when creating queries to this … CWE-89
SQL Injection
CVE-2020-5504 2024-11-21 14:34 2020-01-10 Show GitHub Exploit DB Packet Storm
196767 8.8 HIGH
Network
small_crm_project small_crm PHPGurukul Small CRM v2.0 was found vulnerable to authentication bypass via SQL injection when logging into the administrator login page. CWE-89
SQL Injection
CVE-2020-5511 2024-11-21 14:34 2020-01-9 Show GitHub Exploit DB Packet Storm
196768 9.8 CRITICAL
Network
phpgurukul hostel_management_system PHPGurukul Hostel Management System v2.0 allows SQL injection via the id parameter in the full-profile.php file. CWE-89
SQL Injection
CVE-2020-5510 2024-11-21 14:34 2020-01-9 Show GitHub Exploit DB Packet Storm
196769 9.8 CRITICAL
Network
opservices opmon An issue was discovered in OpServices OpMon 9.3.1-1. Using password change parameters, an attacker could perform SQL injection without authentication. CWE-89
SQL Injection
CVE-2020-5841 2024-11-21 14:34 2020-01-8 Show GitHub Exploit DB Packet Storm
196770 6.1 MEDIUM
Network
codologic codoforum Codoforum 4.8.3 allows XSS in the user registration page: via the username field to the index.php?u=/user/register URI. The payload is, for example, executed on the admin/index.php?page=users/manage … CWE-79
Cross-site Scripting
CVE-2020-5842 2024-11-21 14:34 2020-01-8 Show GitHub Exploit DB Packet Storm