Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 10, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
227761 9.3 危険 watchfire - WatchFire AppScan の特定の ActiveX コントロールにおける絶対パストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-2015 2012-12-20 18:52 2008-04-29 Show GitHub Exploit DB Packet Storm
227762 6.8 警告 pnflashgames - PostNuke 用の pnFlashGames モジュールの index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2013 2012-12-20 18:52 2008-04-29 Show GitHub Exploit DB Packet Storm
227763 7.5 危険 postnuke software foundation - PostNuke 用の PostSchedule モジュールにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2012 2012-12-20 18:52 2008-04-29 Show GitHub Exploit DB Packet Storm
227764 7.5 危険 サン・マイクロシステムズ - Sun Java System Directory Proxy Server におけるサーバに対するアクセス制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-1995 2012-12-20 18:52 2008-04-25 Show GitHub Exploit DB Packet Storm
227765 4.3 警告 pixel motion - Blog Pixel Motion の liste_article.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-1986 2012-12-20 18:52 2008-04-27 Show GitHub Exploit DB Packet Storm
227766 8.5 危険 サン・マイクロシステムズ - Sun Ray Kiosk Mode におけるルートの権限を取得される脆弱性 CWE-noinfo
情報不足
CVE-2008-2112 2012-12-20 18:52 2008-05-5 Show GitHub Exploit DB Packet Storm
227767 9.3 危険 Yahoo! - Yahoo! Assistant の ActiveX コントロールにおける任意のコードを実行される脆弱性 CWE-399
リソース管理の問題
CVE-2008-2111 2012-12-20 18:52 2008-05-7 Show GitHub Exploit DB Packet Storm
227768 7.5 危険 qto - QTOFileManager の qtofm.php における任意の PHP コードをアップロードされる脆弱性 CWE-20
不適切な入力確認
CVE-2008-2110 2012-12-20 18:52 2008-05-7 Show GitHub Exploit DB Packet Storm
227769 7.5 危険 phpforge - PHP Forge の admin/news.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2088 2012-12-20 18:52 2008-05-6 Show GitHub Exploit DB Packet Storm
227770 6.8 警告 softbiz - Softbiz Web Host Directory Script の search_result.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2087 2012-12-20 18:52 2008-05-6 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 10, 2026, 4:58 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
196251 9.8 CRITICAL
Network
deep-get-set_project deep-get-set All versions of package deep-get-set are vulnerable to Prototype Pollution via the main function. CWE-1321
 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVE-2020-7715 2024-11-21 14:37 2020-09-1 Show GitHub Exploit DB Packet Storm
196252 9.8 CRITICAL
Network
realseriousgames confucious All versions of package confucious are vulnerable to Prototype Pollution via the set function. CWE-1321
 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVE-2020-7714 2024-11-21 14:37 2020-09-1 Show GitHub Exploit DB Packet Storm
196253 9.8 CRITICAL
Network
arr-flatten-unflatten_project arr-flatten-unflatten All versions of package arr-flatten-unflatten are vulnerable to Prototype Pollution via the constructor. CWE-1321
 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVE-2020-7713 2024-11-21 14:37 2020-09-1 Show GitHub Exploit DB Packet Storm
196254 7.8 HIGH
Local
schneider-electric somove Incorrect Default Permission vulnerability exists in SoMove (V2.8.1) and prior which could cause elevation of privilege and provide full access control to local system users to SoMove component and s… - CVE-2020-7527 2024-11-21 14:37 2020-09-1 Show GitHub Exploit DB Packet Storm
196255 8.8 HIGH
Network
apc powerchute Improper Input Validation vulnerability exists in PowerChute Business Edition (software V9.0.x and earlier) which could cause remote code execution when a script is executed during a shutdown event. - CVE-2020-7526 2024-11-21 14:37 2020-09-1 Show GitHub Exploit DB Packet Storm
196256 7.5 HIGH
Network
schneider-electric spacelynk_firmware
wiser_for_knx_firmware
Improper Restriction of Excessive Authentication Attempts vulnerability exists in all hardware versions of spaceLYnk and Wiser for KNX (formerly homeLYnk) which could allow an attacker to guess a pas… - CVE-2020-7525 2024-11-21 14:37 2020-09-1 Show GitHub Exploit DB Packet Storm
196257 7.5 HIGH
Network
schneider-electric modicon_m218_firmware Out-of-bounds Write vulnerability exists in Modicon M218 Logic Controller (V5.0.0.7 and prior) which could cause Denial of Service when sending specific crafted IPV4 packet to the controller: Sending… - CVE-2020-7524 2024-11-21 14:37 2020-09-1 Show GitHub Exploit DB Packet Storm
196258 7.8 HIGH
Local
schneider-electric modbus_driver_suite
modbus_serial_driver
Improper Privilege Management vulnerability exists in Schneider Electric Modbus Serial Driver (see security notification for versions) which could cause local privilege escalation when the Modbus Ser… - CVE-2020-7523 2024-11-21 14:37 2020-09-1 Show GitHub Exploit DB Packet Storm
196259 9.8 CRITICAL
Network
schneider-electric apc_easy_ups_online_software Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in SFAPV9601 - APC Easy UPS On-Line Software (V2.0 and earlier) when accessing a vulnerable method … - CVE-2020-7522 2024-11-21 14:37 2020-09-1 Show GitHub Exploit DB Packet Storm
196260 9.8 CRITICAL
Network
schneider-electric apc_easy_ups_online_software Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in SFAPV9601 - APC Easy UPS On-Line Software (V2.0 and earlier) when accessing a vulnerable method … - CVE-2020-7521 2024-11-21 14:37 2020-09-1 Show GitHub Exploit DB Packet Storm