Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 14, 2026, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
227831 7.1 危険 Xine - xine-lib の demux_real.c の real_parse_mdpr 関数における整数オーバーフローの脆弱性 CWE-189
数値処理の問題
CVE-2008-5238 2012-12-20 18:52 2008-09-10 Show GitHub Exploit DB Packet Storm
227832 10 危険 Xine - xine-lib における整数オーバーフローの脆弱性 CWE-189
数値処理の問題
CVE-2008-5237 2012-12-20 18:52 2008-09-10 Show GitHub Exploit DB Packet Storm
227833 9.3 危険 Xine - xine-lib におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-5236 2012-12-20 18:52 2008-09-10 Show GitHub Exploit DB Packet Storm
227834 9.3 危険 Xine - xine-lib の src/demuxers/demux_real.c におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-5235 2012-12-20 18:52 2008-11-25 Show GitHub Exploit DB Packet Storm
227835 9.3 危険 Xine - xine-lib におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-5234 2012-12-20 18:52 2008-09-10 Show GitHub Exploit DB Packet Storm
227836 4.3 警告 Xine - xine-lib におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2008-5233 2012-12-20 18:52 2008-09-10 Show GitHub Exploit DB Packet Storm
227837 10 危険 phpcow - PHPCow における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2008-5227 2012-12-20 18:52 2008-11-25 Show GitHub Exploit DB Packet Storm
227838 7.5 危険 wportfolio - wPortfolio の admin/userinfo.php における admin アカウントのパスワードを変更される脆弱性 CWE-287
不適切な認証
CVE-2008-5221 2012-12-20 18:52 2008-11-25 Show GitHub Exploit DB Packet Storm
227839 10 危険 wportfolio - wPortfolio の admin/upload_form.php における任意のコードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2008-5220 2012-12-20 18:52 2008-11-25 Show GitHub Exploit DB Packet Storm
227840 7.5 危険 videoscript - VVideoScript のパスワード変更機能における admin アカウントパスワードを変更される脆弱性 CWE-287
不適切な認証
CVE-2008-5219 2012-12-20 18:52 2008-11-25 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 15, 2026, 4:28 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
201521 5.4 MEDIUM
Network
cmsmadesimple cms_made_simple A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Add Shortcut" pa… CWE-79
Cross-site Scripting
CVE-2020-36408 2024-11-21 14:29 2021-07-3 Show GitHub Exploit DB Packet Storm
201522 5.4 MEDIUM
Network
phplist phplist A stored cross site scripting (XSS) vulnerability in phplist 3.5.4 and below allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the "rule1" parameter under the "Bounce… CWE-79
Cross-site Scripting
CVE-2020-36399 2024-11-21 14:29 2021-07-3 Show GitHub Exploit DB Packet Storm
201523 5.4 MEDIUM
Network
phplist phplist A stored cross site scripting (XSS) vulnerability in phplist 3.5.4 and below allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the "Campaign" field under the "Send a … CWE-79
Cross-site Scripting
CVE-2020-36398 2024-11-21 14:29 2021-07-3 Show GitHub Exploit DB Packet Storm
201524 5.4 MEDIUM
Network
lavalite lavalite A stored cross site scripting (XSS) vulnerability in the /admin/contact/contact component of LavaLite 5.8.0 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted paylo… CWE-79
Cross-site Scripting
CVE-2020-36397 2024-11-21 14:29 2021-07-3 Show GitHub Exploit DB Packet Storm
201525 5.4 MEDIUM
Network
lavalite lavalite A stored cross site scripting (XSS) vulnerability in the /admin/roles/role component of LavaLite 5.8.0 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload en… CWE-79
Cross-site Scripting
CVE-2020-36396 2024-11-21 14:29 2021-07-3 Show GitHub Exploit DB Packet Storm
201526 5.4 MEDIUM
Network
lavalite lavalite A stored cross site scripting (XSS) vulnerability in the /admin/user/team component of LavaLite 5.8.0 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload ent… CWE-79
Cross-site Scripting
CVE-2020-36395 2024-11-21 14:29 2021-07-3 Show GitHub Exploit DB Packet Storm
201527 8.8 HIGH
Network
aomedia libavif libavif 0.8.0 and 0.8.1 has an out-of-bounds write in avifDecoderDataFillImageGrid. CWE-787
 Out-of-bounds Write
CVE-2020-36407 2024-11-21 14:29 2021-07-1 Show GitHub Exploit DB Packet Storm
201528 8.8 HIGH
Network
uwebsockets_project uwebsockets uWebSockets 18.11.0 and 18.12.0 has a stack-based buffer overflow in uWS::TopicTree::trimTree (called from uWS::TopicTree::unsubscribeAll). NOTE: the vendor's position is that this is "a minor issue … CWE-787
 Out-of-bounds Write
CVE-2020-36406 2024-11-21 14:29 2021-07-1 Show GitHub Exploit DB Packet Storm
201529 7.8 HIGH
Local
keystone-engine keystone_engine Keystone Engine 0.9.2 has a use-after-free in llvm_ks::X86Operand::getToken. CWE-416
 Use After Free
CVE-2020-36405 2024-11-21 14:29 2021-07-1 Show GitHub Exploit DB Packet Storm
201530 7.8 HIGH
Local
keystone-engine keystone Keystone Engine 0.9.2 has an invalid free in llvm_ks::SmallVectorImpl<llvm_ks::MCFixup>::~SmallVectorImpl. CWE-763
 Release of Invalid Pointer or Reference
CVE-2020-36404 2024-11-21 14:29 2021-07-1 Show GitHub Exploit DB Packet Storm