Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 9, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
227741 7.5 危険 WordPress.org - Wordpress の wp-includes/vars.php における特定のページに対するアクセス制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-2146 2012-12-20 18:52 2008-05-12 Show GitHub Exploit DB Packet Storm
227742 2.6 注意 rPath, Inc - rPath Appliance Platform Agent の rootpw プラグインにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2008-2140 2012-12-20 18:52 2008-04-25 Show GitHub Exploit DB Packet Storm
227743 6.5 警告 rPath, Inc - rPath Appliance Platform Agent の rootpw プラグインにおける権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-2139 2012-12-20 18:52 2008-04-25 Show GitHub Exploit DB Packet Storm
227744 7.5 危険 visualshapers - VisualShapers ezContents における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2135 2012-12-20 18:52 2008-05-9 Show GitHub Exploit DB Packet Storm
227745 6.8 警告 tru-zone - Tru-Zone Nuke ET の Journal モジュールにおける任意のユーザアカウントへのアクセス権を取得される脆弱性 CWE-20
不適切な入力確認
CVE-2008-2134 2012-12-20 18:52 2008-05-9 Show GitHub Exploit DB Packet Storm
227746 4.3 警告 tru-zone - Tru-Zone Nuke ET の Journal モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-2133 2012-12-20 18:52 2008-05-9 Show GitHub Exploit DB Packet Storm
227747 7.5 危険 systementor - Systementor PostcardMentor の step1.asp における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2132 2012-12-20 18:52 2008-05-9 Show GitHub Exploit DB Packet Storm
227748 4.3 警告 tux cms - Tux CMS におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-2126 2012-12-20 18:52 2008-05-9 Show GitHub Exploit DB Packet Storm
227749 4.3 警告 SAP - SAP ITS の WGate におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-2123 2012-12-20 18:52 2008-05-9 Show GitHub Exploit DB Packet Storm
227750 7.5 危険 project alumni - Project Alumni の info.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2118 2012-12-20 18:52 2008-05-8 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 9, 2026, 5:07 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
196361 9.8 CRITICAL
Network
install-package_project
umount_project
install-package
umount
umount through 1.1.6 is vulnerable to Command Injection. The argument device can be controlled by users without any sanitization. CWE-78
OS Command 
CVE-2020-7628 2024-11-21 14:37 2020-04-3 Show GitHub Exploit DB Packet Storm
196362 9.8 CRITICAL
Network
node-key-sender_project node-key-sender node-key-sender through 1.0.11 is vulnerable to Command Injection. It allows execution of arbitrary commands via the 'arrParams' argument in the 'execute()' function. CWE-78
OS Command 
CVE-2020-7627 2024-11-21 14:37 2020-04-3 Show GitHub Exploit DB Packet Storm
196363 9.8 CRITICAL
Network
karma-mojo_project karma-mojo karma-mojo through 1.0.1 is vulnerable to Command Injection. It allows execution of arbitrary commands via the config argument. CWE-78
OS Command 
CVE-2020-7626 2024-11-21 14:37 2020-04-3 Show GitHub Exploit DB Packet Storm
196364 9.8 CRITICAL
Network
op-browser_project op-browser op-browser through 1.0.6 is vulnerable to Command Injection. It allows execution of arbitrary commands via the url function. CWE-78
OS Command 
CVE-2020-7625 2024-11-21 14:37 2020-04-3 Show GitHub Exploit DB Packet Storm
196365 9.8 CRITICAL
Network
effect_project effect effect through 1.0.4 is vulnerable to Command Injection. It allows execution of arbitrary command via the options argument. CWE-78
OS Command 
CVE-2020-7624 2024-11-21 14:37 2020-04-3 Show GitHub Exploit DB Packet Storm
196366 9.8 CRITICAL
Network
jscover_project jscover jscover through 1.0.0 is vulnerable to Command Injection. It allows execution of arbitrary command via the source argument. CWE-78
OS Command 
CVE-2020-7623 2024-11-21 14:37 2020-04-3 Show GitHub Exploit DB Packet Storm
196367 9.8 CRITICAL
Network
ibm strongloop_nginx_controller strong-nginx-controller through 1.0.2 is vulnerable to Command Injection. It allows execution of arbitrary command as part of the '_nginxCmd()' function. CWE-78
OS Command 
CVE-2020-7621 2024-11-21 14:37 2020-04-3 Show GitHub Exploit DB Packet Storm
196368 9.8 CRITICAL
Network
netease pomelo-monitor pomelo-monitor through 0.3.7 is vulnerable to Command Injection.It allows injection of arbitrary commands as part of 'pomelo-monitor' params. CWE-78
OS Command 
CVE-2020-7620 2024-11-21 14:37 2020-04-3 Show GitHub Exploit DB Packet Storm
196369 9.8 CRITICAL
Network
get-git-data_project get-git-data get-git-data through 1.3.1 is vulnerable to Command Injection. It is possible to inject arbitrary commands as part of the arguments provided to get-git-data. CWE-78
OS Command 
CVE-2020-7619 2024-11-21 14:37 2020-04-3 Show GitHub Exploit DB Packet Storm
196370 9.8 CRITICAL
Network
ini-parser_project ini-parser ini-parser through 0.0.2 is vulnerable to Prototype Pollution.The library could be tricked into adding or modifying properties of Object.prototype using a '__proto__' payload. CWE-1321
 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVE-2020-7617 2024-11-21 14:37 2020-04-3 Show GitHub Exploit DB Packet Storm