Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 11, 2026, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
227531 5 警告 php-daily - PHP-Daily の download_file.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-4758 2012-12-20 18:52 2008-10-27 Show GitHub Exploit DB Packet Storm
227532 7.5 危険 php-daily - PHP-Daily における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-4757 2012-12-20 18:52 2008-10-27 Show GitHub Exploit DB Packet Storm
227533 4.3 警告 php-daily - PHP-Daily の add_prest_date.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-4756 2012-12-20 18:52 2008-10-27 Show GitHub Exploit DB Packet Storm
227534 7.5 危険 pozscripts - PozScripts Classified Auctions Script の gotourl.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-4755 2012-12-20 18:52 2008-10-27 Show GitHub Exploit DB Packet Storm
227535 5.8 警告 scripts-for-sites - SFS Ez Forum の forum.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-4754 2012-12-20 18:52 2008-10-27 Show GitHub Exploit DB Packet Storm
227536 7.5 危険 tech logic - TlNews における認証を回避される脆弱性 CWE-287
不適切な認証
CVE-2008-4752 2012-12-20 18:52 2008-10-27 Show GitHub Exploit DB Packet Storm
227537 7.5 危険 uniwin - Uniwin eCart Professional における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-4746 2012-12-20 18:52 2008-10-27 Show GitHub Exploit DB Packet Storm
227538 4.3 警告 uniwin - Uniwin eCart Professional の emailFriend.asp におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-4745 2012-12-20 18:52 2008-10-27 Show GitHub Exploit DB Packet Storm
227539 7.5 危険 quidascript - QuidaScript FAQ Management Script の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-4743 2012-12-20 18:52 2008-10-27 Show GitHub Exploit DB Packet Storm
227540 4.3 警告 timetrex - TimeTrex の interface/Login.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-4742 2012-12-20 18:52 2008-10-27 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 11, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
222121 8.8 HIGH
Network
sugarcrm sugarcrm SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the MergeRecords module by a Regular user. CWE-94
Code Injection
CVE-2019-17305 2024-11-21 13:32 2019-10-8 Show GitHub Exploit DB Packet Storm
222122 7.2 HIGH
Network
sugarcrm sugarcrm SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the MergeRecords module by an Admin user. CWE-94
Code Injection
CVE-2019-17304 2024-11-21 13:32 2019-10-8 Show GitHub Exploit DB Packet Storm
222123 8.8 HIGH
Network
sugarcrm sugarcrm SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the MergeRecords module by a Developer user. CWE-94
Code Injection
CVE-2019-17303 2024-11-21 13:32 2019-10-8 Show GitHub Exploit DB Packet Storm
222124 8.8 HIGH
Network
sugarcrm sugarcrm SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the ModuleBuilder module by a Developer user. CWE-94
Code Injection
CVE-2019-17302 2024-11-21 13:32 2019-10-8 Show GitHub Exploit DB Packet Storm
222125 7.2 HIGH
Network
sugarcrm sugarcrm SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the ModuleBuilder module by an Admin user. CWE-94
Code Injection
CVE-2019-17301 2024-11-21 13:32 2019-10-8 Show GitHub Exploit DB Packet Storm
222126 8.8 HIGH
Network
sugarcrm sugarcrm SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Administration module by a Developer user. CWE-94
Code Injection
CVE-2019-17300 2024-11-21 13:32 2019-10-8 Show GitHub Exploit DB Packet Storm
222127 7.2 HIGH
Network
sugarcrm sugarcrm SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Administration module by an Admin user. CWE-94
Code Injection
CVE-2019-17299 2024-11-21 13:32 2019-10-8 Show GitHub Exploit DB Packet Storm
222128 8.8 HIGH
Network
sugarcrm sugarcrm SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the Administration module by a Developer user. CWE-89
SQL Injection
CVE-2019-17298 2024-11-21 13:32 2019-10-8 Show GitHub Exploit DB Packet Storm
222129 8.8 HIGH
Network
sugarcrm sugarcrm SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the Quotes module by a Regular user. CWE-89
SQL Injection
CVE-2019-17297 2024-11-21 13:32 2019-10-8 Show GitHub Exploit DB Packet Storm
222130 8.8 HIGH
Network
sugarcrm sugarcrm SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the Contacts module by a Regular user. CWE-89
SQL Injection
CVE-2019-17296 2024-11-21 13:32 2019-10-8 Show GitHub Exploit DB Packet Storm