Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 9, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228161 4.3 警告 pro search - PRO-Search におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-0207 2012-12-20 18:34 2008-01-9 Show GitHub Exploit DB Packet Storm
228162 4.3 警告 WordPress.org - WordPress 用の Captcha! プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-0206 2012-12-20 18:34 2008-01-9 Show GitHub Exploit DB Packet Storm
228163 4.3 警告 WordPress.org - WordPress 用の Math Comment Spam Protection プラグインにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-0205 2012-12-20 18:34 2008-01-9 Show GitHub Exploit DB Packet Storm
228164 4.3 警告 WordPress.org - WordPress 用の Math Comment Spam Protection プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-0204 2012-12-20 18:34 2008-01-9 Show GitHub Exploit DB Packet Storm
228165 4.3 警告 WordPress.org - WordPress 用の Cryptographp プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-0203 2012-12-20 18:34 2008-01-9 Show GitHub Exploit DB Packet Storm
228166 5 警告 pro search - PRO-Search におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2008-0199 2012-12-20 18:34 2008-01-9 Show GitHub Exploit DB Packet Storm
228167 4.3 警告 WordPress.org - WordPress 用の WP-ContactForm プラグインにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2008-0198 2012-12-20 18:34 2008-01-9 Show GitHub Exploit DB Packet Storm
228168 4.3 警告 WordPress.org - WordPress 用の WP-ContactForm プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-0197 2012-12-20 18:34 2008-01-9 Show GitHub Exploit DB Packet Storm
228169 5 警告 WordPress.org - WordPress におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-0196 2012-12-20 18:34 2008-01-9 Show GitHub Exploit DB Packet Storm
228170 5 警告 WordPress.org - WordPress における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2008-0195 2012-12-20 18:34 2008-01-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 10, 2026, 4:58 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
209511 9.8 CRITICAL
Network
opener_project opener An out-of-bounds write vulnerability exists in the Ethernet/IP server functionality of EIP Stack Group OpENer 2.3 and development commit 8c73bf3. A specially crafted series of network requests can le… CWE-787
 Out-of-bounds Write
CVE-2020-13556 2024-11-21 14:01 2020-12-11 Show GitHub Exploit DB Packet Storm
209512 7.5 HIGH
Network
opener_project opener A denial-of-service vulnerability exists in the Ethernet/IP server functionality of the EIP Stack Group OpENer 2.3 and development commit 8c73bf3. A large number of network requests in a small span o… CWE-672
 Operation on a Resource after Expiration or Release
CVE-2020-13530 2024-11-21 14:01 2020-12-11 Show GitHub Exploit DB Packet Storm
209513 7.8 HIGH
Local
pixar
apple
openusd
macos
An out of bounds memory corruption vulnerability exists in the way Pixar OpenUSD 20.05 reconstructs paths from binary USD files. A specially crafted malformed file can trigger an out of bounds memory… CWE-787
 Out-of-bounds Write
CVE-2020-13520 2024-11-21 14:01 2020-12-11 Show GitHub Exploit DB Packet Storm
209514 4.3 MEDIUM
Network
gitlab gitlab An issue was discovered in Gitlab CE/EE versions >= 13.1 to <13.4.7, >= 13.5 to <13.5.5, and >= 13.6 to <13.6.2 allowed an unauthorized user to access the user list corresponding to a feature flag in… CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2020-13357 2024-11-21 14:01 2020-12-11 Show GitHub Exploit DB Packet Storm
209515 8.8 HIGH
Network
processmaker processmaker SQL injection vulnerability exists in the handling of sort parameters in ProcessMaker 3.4.11. A specially crafted HTTP request can cause an SQL injection. The reportTables_Ajax and clientSetupAjax pa… CWE-89
SQL Injection
CVE-2020-13526 2024-11-21 14:01 2020-12-11 Show GitHub Exploit DB Packet Storm
209516 8.8 HIGH
Network
processmaker processmaker The sort parameter in the download page /sysworkflow/en/neoclassic/reportTables/reportTables_Ajax is vulnerable to SQL injection in ProcessMaker 3.4.11. A specially crafted HTTP request can cause an … CWE-89
SQL Injection
CVE-2020-13525 2024-11-21 14:01 2020-12-4 Show GitHub Exploit DB Packet Storm
209517 5.5 MEDIUM
Local
pixar
apple
openusd
mac_os_x
macos
An out-of-bounds memory corruption vulnerability exists in the way Pixar OpenUSD 20.05 uses SPECS data from binary USD files. A specially crafted malformed file can trigger an out-of-bounds memory ac… CWE-787
 Out-of-bounds Write
CVE-2020-13524 2024-11-21 14:01 2020-12-4 Show GitHub Exploit DB Packet Storm
209518 8.8 HIGH
Network
webkitgtk
fedoraproject
webkitgtk
fedora
An exploitable use-after-free vulnerability exists in WebKitGTK browser version 2.30.1 x64. A specially crafted HTML web page can cause a use-after-free condition, resulting in a remote code executio… CWE-416
 Use After Free
CVE-2020-13584 2024-11-21 14:01 2020-12-4 Show GitHub Exploit DB Packet Storm
209519 8.8 HIGH
Network
webkitgtk webkitgtk A code execution vulnerability exists in the WebSocket functionality of Webkit WebKitGTK 2.30.0. A specially crafted web page can trigger a use-after-free vulnerability which can lead to remote code … CWE-416
 Use After Free
CVE-2020-13543 2024-11-21 14:01 2020-12-4 Show GitHub Exploit DB Packet Storm
209520 7.8 HIGH
Local
logicaldoc logicaldoc A local privilege elevation vulnerability exists in the file system permissions of LogicalDoc 8.5.1 installation. Depending on the vector chosen, an attacker can either replace the service binary or … CWE-276
Incorrect Default Permissions 
CVE-2020-13542 2024-11-21 14:01 2020-12-4 Show GitHub Exploit DB Packet Storm