Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 27, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228131 6.8 警告 saphplesson - SaphpLesson における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-3321 2012-12-20 19:28 2009-09-23 Show GitHub Exploit DB Packet Storm
228132 4.3 警告 zenas - Zenas PaoLink の scrivi.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-3320 2012-12-20 19:28 2009-09-23 Show GitHub Exploit DB Packet Storm
228133 7.5 危険 thecodeweasel - OpenSiteAdmin の pages/pageHeader.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2009-3317 2012-12-20 19:28 2009-09-23 Show GitHub Exploit DB Packet Storm
228134 6.8 警告 tomex - phpPollScript の php/init.poll.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2009-3312 2012-12-20 19:28 2009-09-23 Show GitHub Exploit DB Packet Storm
228135 4.3 警告 rssmediascript - RSSMediaScript の index.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-3311 2012-12-20 19:28 2009-09-23 Show GitHub Exploit DB Packet Storm
228136 7.5 危険 shalwan - Zainu の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-3310 2012-12-20 19:28 2009-09-23 Show GitHub Exploit DB Packet Storm
228137 7.5 危険 richrumble - ClearSite の include/header.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2009-3306 2012-12-20 19:28 2009-09-23 Show GitHub Exploit DB Packet Storm
228138 5 警告 pps.jussieu - Polipo におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2009-3305 2012-12-20 19:28 2009-12-24 Show GitHub Exploit DB Packet Storm
228139 4.9 警告 QNAP Systems - QNAP TS-239 Pro および TS-639 Pro における重要な情報を取得される脆弱性 CWE-310
暗号の問題
CVE-2009-3279 2012-12-20 19:28 2009-09-21 Show GitHub Exploit DB Packet Storm
228140 4.9 警告 QNAP Systems - QNAP TS-239 Pro などにおける鍵を特定される脆弱性 CWE-310
暗号の問題
CVE-2009-3278 2012-12-20 19:28 2009-09-21 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 28, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
208241 6.1 MEDIUM
Network
blubrry subscribe_sidebar The Blubrry subscribe-sidebar (aka Subscribe Sidebar) plugin 1.3.1 for WordPress allows subscribe_sidebar.php&status= reflected XSS. CWE-79
Cross-site Scripting
CVE-2020-25033 2024-11-21 14:16 2020-08-31 Show GitHub Exploit DB Packet Storm
208242 7.5 HIGH
Network
flask-cors_project
debian
opensuse
flask-cors
debian_linux
leap
backports_sle
An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathna… CWE-22
Path Traversal
CVE-2020-25032 2024-11-21 14:16 2020-08-31 Show GitHub Exploit DB Packet Storm
208243 7.8 HIGH
Local
canonical checkinstall checkinstall 1.6.2, when used to create a package that contains a symlink, may trigger the creation of a mode 0777 executable file. CWE-59
Link Following
CVE-2020-25031 2024-11-21 14:16 2020-08-31 Show GitHub Exploit DB Packet Storm
208244 6.1 MEDIUM
Network
osticket osticket osTicket before 1.14.3 allows XSS via a crafted filename to DraftAjaxAPI::_uploadInlineImage() in include/ajax.draft.php. CWE-79
Cross-site Scripting
CVE-2020-24917 2024-11-21 14:16 2020-08-31 Show GitHub Exploit DB Packet Storm
208245 8.8 HIGH
Network
kleopatra_project
fedoraproject
opensuse
kleopatra
fedora
leap
backports_sle
The Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported without safe handling of command-line o… CWE-116
 Improper Encoding or Escaping of Output
CVE-2020-24972 2024-11-21 14:16 2020-08-30 Show GitHub Exploit DB Packet Storm
208246 5.3 MEDIUM
Network
premid premid managers/socketManager.ts in PreMiD through 2.1.3 has a locally hosted socketio web server (port 3020) open to all origins, which allows attackers to obtain sensitive Discord user information. CWE-862
 Missing Authorization
CVE-2020-24928 2024-11-21 14:16 2020-08-30 Show GitHub Exploit DB Packet Storm
208247 6.5 MEDIUM
Network
stiltsoft table_filter_and_charts_for_confluence_server The Table Filter and Charts for Confluence Server app before 5.3.26 (for Atlassian Confluence) allows SSRF via the "Table from CSV" macro (URL parameter). CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2020-24898 2024-11-21 14:16 2020-08-30 Show GitHub Exploit DB Packet Storm
208248 8.9 HIGH
Network
stiltsoft table_filter_and_charts_for_confluence_server The Table Filter and Charts for Confluence Server app before 5.3.25 (for Atlassian Confluence) allow remote attackers to inject arbitrary HTML or JavaScript via cross site scripting (XSS) through the… CWE-79
Cross-site Scripting
CVE-2020-24897 2024-11-21 14:16 2020-08-30 Show GitHub Exploit DB Packet Storm
208249 9.8 CRITICAL
Network
mpxj
oracle
mpxj
primavera_unifier
MPXJ through 8.1.3 allows XXE attacks. This affects the GanttProjectReader and PhoenixReader components. CWE-611
XXE
CVE-2020-25020 2024-11-21 14:16 2020-08-30 Show GitHub Exploit DB Packet Storm
208250 7.5 HIGH
Network
jitsi meet_electron jitsi-meet-electron (aka Jitsi Meet Electron) before 2.3.0 calls the Electron shell.openExternal function without verifying that the URL is for an http or https resource, in some circumstances. CWE-345
 Insufficient Verification of Data Authenticity
CVE-2020-25019 2024-11-21 14:16 2020-08-30 Show GitHub Exploit DB Packet Storm