Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 9, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228121 6.8 警告 softpedia - Small Axe Weblog の inc/linkbar.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2008-0376 2012-12-20 18:34 2008-01-22 Show GitHub Exploit DB Packet Storm
228122 6.8 警告 Pixelpost.org - Pixelpost の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0358 2012-12-20 18:34 2008-01-16 Show GitHub Exploit DB Packet Storm
228123 7.5 危険 phpecho cms - PHPEcho CMS の forum モジュールにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0355 2012-12-20 18:34 2008-01-18 Show GitHub Exploit DB Packet Storm
228124 7.5 危険 php-residence - php-residence の visualizza_tabelle.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0353 2012-12-20 18:34 2008-01-18 Show GitHub Exploit DB Packet Storm
228125 2.6 注意 pmachine - PMachine Pro の pm/language/spanish/preferences.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-0334 2012-12-20 18:34 2008-01-17 Show GitHub Exploit DB Packet Storm
228126 7.8 危険 radiator - OSC Radiator におけるサービス運用妨害 (DoS) の脆弱性 CWE-287
不適切な認証
CVE-2008-0330 2012-12-20 18:34 2008-01-17 Show GitHub Exploit DB Packet Storm
228127 6.8 警告 シマンテック - Norton 360 などの Symantec Norton 製品の ActiveDataInfo.LaunchProcess メソッドにおける任意のコードを実行される脆弱性 CWE-DesignError
CVE-2008-0313 2012-12-20 18:34 2008-04-2 Show GitHub Exploit DB Packet Storm
228128 9.3 危険 シマンテック - Norton 360 などの Symantec Norton 製品の AutoFix Support Tool ActiveX コントロールにおけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-0312 2012-12-20 18:34 2008-04-2 Show GitHub Exploit DB Packet Storm
228129 6.9 警告 SCO - SCO UnixWare の pkgadd におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-0310 2012-12-20 18:34 2008-02-27 Show GitHub Exploit DB Packet Storm
228130 6.8 警告 シマンテック - Symantec Scan Engine を含む特定の Symantec アンチウイルス製品で使用される Symantec Decomposer におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-0309 2012-12-20 18:34 2008-02-26 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 10, 2026, 4:58 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
201091 7.2 HIGH
Network
qnap qts If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. QTS versions prior to 4.4.3.1421 on build 20200907. CWE-77
Command Injection
CVE-2020-2490 2024-11-21 14:25 2020-11-16 Show GitHub Exploit DB Packet Storm
201092 6.5 MEDIUM
Network
jenkins vmware_lab_manager_slaves Jenkins VMware Lab Manager Slaves Plugin 0.2.8 and earlier stores a password unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by users with access to the Jen… CWE-522
 Insufficiently Protected Credentials
CVE-2020-2319 2024-11-21 14:25 2020-11-5 Show GitHub Exploit DB Packet Storm
201093 6.5 MEDIUM
Network
jenkins mail_commander Jenkins Mail Commander Plugin for Jenkins-ci Plugin 1.0.0 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Re… CWE-522
 Insufficiently Protected Credentials
CVE-2020-2318 2024-11-21 14:25 2020-11-5 Show GitHub Exploit DB Packet Storm
201094 5.4 MEDIUM
Network
jenkins findbugs Jenkins FindBugs Plugin 5.0.0 and earlier does not escape the annotation message in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide r… CWE-79
Cross-site Scripting
CVE-2020-2317 2024-11-21 14:25 2020-11-5 Show GitHub Exploit DB Packet Storm
201095 5.4 MEDIUM
Network
jenkins static_analysis_utilities Jenkins Static Analysis Utilities Plugin 1.96 and earlier does not escape the annotation message in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers w… CWE-79
Cross-site Scripting
CVE-2020-2316 2024-11-21 14:25 2020-11-5 Show GitHub Exploit DB Packet Storm
201096 6.5 MEDIUM
Network
jenkins visualworks_store Jenkins Visualworks Store Plugin 1.1.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. - CVE-2020-2315 2024-11-21 14:25 2020-11-5 Show GitHub Exploit DB Packet Storm
201097 5.5 MEDIUM
Local
jenkins appspider Jenkins AppSpider Plugin 1.0.12 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins control… CWE-522
 Insufficiently Protected Credentials
CVE-2020-2314 2024-11-21 14:25 2020-11-5 Show GitHub Exploit DB Packet Storm
201098 4.3 MEDIUM
Network
jenkins azure_key_vault A missing permission check in Jenkins Azure Key Vault Plugin 2.0 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. - CVE-2020-2313 2024-11-21 14:25 2020-11-5 Show GitHub Exploit DB Packet Storm
201099 6.5 MEDIUM
Network
jenkins sqlplus_script_runner Jenkins SQLPlus Script Runner Plugin 2.0.12 and earlier does not mask a password provided as command line argument in build logs. - CVE-2020-2312 2024-11-21 14:25 2020-11-5 Show GitHub Exploit DB Packet Storm
201100 4.3 MEDIUM
Network
jenkins aws_global_configuration A missing permission check in Jenkins AWS Global Configuration Plugin 1.5 and earlier allows attackers with Overall/Read permission to replace the global AWS configuration. - CVE-2020-2311 2024-11-21 14:25 2020-11-5 Show GitHub Exploit DB Packet Storm