Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 10, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
227541 4.3 警告 TYPO3 Association - TYPO3 用の Address Directory エクステンションにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-3037 2012-12-20 18:52 2008-07-7 Show GitHub Exploit DB Packet Storm
227542 6.5 警告 xchangeboard - XchangeBoard の newThread.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3035 2012-12-20 18:52 2008-07-7 Show GitHub Exploit DB Packet Storm
227543 7.5 危険 rss aggregator - RSS-aggregator における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3034 2012-12-20 18:52 2008-07-7 Show GitHub Exploit DB Packet Storm
227544 9.3 危険 rss aggregator - RSS-aggregator における admin 関数へアクセスされ脆弱性 CWE-287
不適切な認証
CVE-2008-3033 2012-12-20 18:52 2008-07-7 Show GitHub Exploit DB Packet Storm
227545 4.3 警告 The phpMyAdmin Project - TYPO3 用の phpMyAdmin エクステンションにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-3032 2012-12-20 18:52 2008-07-7 Show GitHub Exploit DB Packet Storm
227546 7.5 危険 Thomas Abeel - Simple PHP Agenda の index.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-3031 2012-12-20 18:52 2008-07-7 Show GitHub Exploit DB Packet Storm
227547 4.3 警告 Web-Empowered Church Team - TYPO3 用の WEC Discussion Forum エクステンションにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-3029 2012-12-20 18:52 2008-07-7 Show GitHub Exploit DB Packet Storm
227548 4.3 警告 TYPO3 Association - TYPO3 用の Send-A-Card エクステンションにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-3028 2012-12-20 18:52 2008-07-7 Show GitHub Exploit DB Packet Storm
227549 7.5 危険 vangogh web cms - VanGogh Web CMS の get_article.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3027 2012-12-20 18:52 2008-07-7 Show GitHub Exploit DB Packet Storm
227550 7.5 危険 plx web studio - plx Ad Trader の ad.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3025 2012-12-20 18:52 2008-07-7 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 10, 2026, 4:58 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
209911 6.1 MEDIUM
Network
zulip zulip_server Zulip Server before 2.1.5 allows reflected XSS via the Dropbox webhook. CWE-79
Cross-site Scripting
CVE-2020-12759 2024-11-21 14:00 2020-08-21 Show GitHub Exploit DB Packet Storm
209912 6.1 MEDIUM
Network
teradici pcoip_management_console Reflected Cross Site Scripting in Teradici PCoIP Management Console prior to 20.07 could allow an attacker to take over the user's active session if the user is exposed to a malicious payload. CWE-79
Cross-site Scripting
CVE-2020-13183 2024-11-21 14:00 2020-08-18 Show GitHub Exploit DB Packet Storm
209913 8.8 HIGH
Network
noviflow noviware The novish command-line interface, included in NoviFlow NoviWare before NW500.2.12 and deployed on NoviSwitch devices, is vulnerable to command injection in the "show status destination ipaddr" comma… CWE-78
OS Command 
CVE-2020-13122 2024-11-21 14:00 2020-08-18 Show GitHub Exploit DB Packet Storm
209914 4.3 MEDIUM
Network
gitlab gitlab For GitLab before 13.0.12, 13.1.6, 13.2.3 user controlled git configuration settings can be modified to result in Server Side Request Forgery. CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2020-13286 2024-11-21 14:00 2020-08-13 Show GitHub Exploit DB Packet Storm
209915 6.5 MEDIUM
Network
gitlab gitlab For GitLab before 13.0.12, 13.1.6, 13.2.3 a denial of service exists in the project import feature CWE-400
 Uncontrolled Resource Consumption
CVE-2020-13281 2024-11-21 14:00 2020-08-13 Show GitHub Exploit DB Packet Storm
209916 5.4 MEDIUM
Network
gitlab gitlab For GitLab before 13.0.12, 13.1.6, 13.2.3 a cross-site scripting (XSS) vulnerability exists in the issue reference number tooltip. CWE-79
Cross-site Scripting
CVE-2020-13285 2024-11-21 14:00 2020-08-13 Show GitHub Exploit DB Packet Storm
209917 5.4 MEDIUM
Network
gitlab gitlab For GitLab before 13.0.12, 13.1.6, 13.2.3 a cross-site scripting vulnerability exists in the issues list via milestone title. CWE-79
Cross-site Scripting
CVE-2020-13283 2024-11-21 14:00 2020-08-13 Show GitHub Exploit DB Packet Storm
209918 3.5 LOW
Network
gitlab gitlab For GitLab before 13.0.12, 13.1.6, 13.2.3 after a group transfer occurs, members from a parent group keep their access level on the subgroup leading to improper access. CWE-281
 Improper Preservation of Permissions
CVE-2020-13282 2024-11-21 14:00 2020-08-13 Show GitHub Exploit DB Packet Storm
209919 6.5 MEDIUM
Network
gitlab gitlab For GitLab before 13.0.12, 13.1.6, 13.2.3 a memory exhaustion flaw exists due to excessive logging of an invite email error message. CWE-400
 Uncontrolled Resource Consumption
CVE-2020-13280 2024-11-21 14:00 2020-08-13 Show GitHub Exploit DB Packet Storm
209920 7.5 HIGH
Network
dovecot
debian
canonical
fedoraproject
dovecot
debian_linux
ubuntu_linux
fedora
In Dovecot before 2.3.11.3, sending a specially formatted RPA request will crash the auth service because a length of zero is mishandled. CWE-125
Out-of-bounds Read
CVE-2020-12674 2024-11-21 14:00 2020-08-13 Show GitHub Exploit DB Packet Storm