Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 18, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228271 6.8 警告 xt:Commerce - xt:Commerce における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6304 2012-12-20 19:10 2008-11-20 Show GitHub Exploit DB Packet Storm
228272 7.5 危険 TYPO3 Association - TYPO3 用の TU-Clausthal Staff エクステンションにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6344 2012-12-20 19:10 2009-02-27 Show GitHub Exploit DB Packet Storm
228273 4.3 警告 TYPO3 Association - TYPO3 用の TU-Clausthal ODIN エクステンションにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-6343 2012-12-20 19:10 2009-02-27 Show GitHub Exploit DB Packet Storm
228274 4.3 警告 TYPO3 Association - TYPO3 用の SB Universal Plugin エクステンションにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-6341 2012-12-20 19:10 2009-02-27 Show GitHub Exploit DB Packet Storm
228275 7.5 危険 weber-ebusiness - TYPO3 用の WEBERkommunal Facilities エクステンションにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6338 2012-12-20 19:10 2009-02-27 Show GitHub Exploit DB Packet Storm
228276 4.3 警告 rightscripts - Text Lines Rearrange Script の download.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-6336 2012-12-20 19:10 2009-02-27 Show GitHub Exploit DB Packet Storm
228277 7.5 危険 simplecustomer - Simple Customer の login.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6332 2012-12-20 19:10 2009-02-27 Show GitHub Exploit DB Packet Storm
228278 6 警告 streber-pm - Streber におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2008-6331 2012-12-20 19:10 2009-02-27 Show GitHub Exploit DB Packet Storm
228279 7.5 危険 PreProject.com - Pre ASP Job Board の Employee/login.asp における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6329 2012-12-20 19:10 2009-02-27 Show GitHub Exploit DB Packet Storm
228280 7.5 危険 simplecustomer - Simple Customer の login.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6326 2012-12-20 19:10 2009-02-27 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 19, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
221291 6.5 MEDIUM
Network
atlassian jira
jira_software_data_center
jira_server
jira_data_center
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view sensitive information via an Information Disclosure vulnerability in the comment restriction feature. The aff… NVD-CWE-noinfo
CVE-2019-20410 2024-11-21 13:38 2020-06-29 Show GitHub Exploit DB Packet Storm
221292 9.8 CRITICAL
Network
atlassian jira_software_data_center
jira
The way in which velocity templates were used in Atlassian Jira Server and Data Center prior to version 8.8.0 allowed remote attackers to gain remote code execution if they were able to exploit a ser… CWE-74
Injection
CVE-2019-20409 2024-11-21 13:38 2020-06-23 Show GitHub Exploit DB Packet Storm
221293 8.1 HIGH
Network
intelliants subrion A Cross-Site Request Forgery (CSRF) vulnerability was discovered in Subrion CMS 4.2.1 that allows a remote attacker to remove files on the server without a victim's knowledge, by enticing an authenti… CWE-352
 Origin Validation Error
CVE-2019-20390 2024-11-21 13:38 2020-05-16 Show GitHub Exploit DB Packet Storm
221294 6.1 MEDIUM
Network
intelliants subrion An XSS issue was identified on the Subrion CMS 4.2.1 /panel/configuration/general settings page. A remote attacker can inject arbitrary JavaScript code in the v[language_switch] parameter (within mul… CWE-79
Cross-site Scripting
CVE-2019-20389 2024-11-21 13:38 2020-05-16 Show GitHub Exploit DB Packet Storm
221295 6.1 MEDIUM
Network
atlassian confluence_server The attachment-uploading feature in Atlassian Confluence Server from version 6.14.0 through version 6.14.3, and version 6.15.0 before version 6.15.5 allows remote attackers to achieve stored cross-si… CWE-79
Cross-site Scripting
CVE-2019-20102 2024-11-21 13:38 2020-04-22 Show GitHub Exploit DB Packet Storm
221296 4.8 MEDIUM
Network
netgear rbr50_firmware
rbk50_firmware
rbs50_firmware
Certain NETGEAR devices are affected by stored XSS. This affects RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, and RBK50 before 2.3.5.30. CWE-79
Cross-site Scripting
CVE-2019-20661 2024-11-21 13:38 2020-04-16 Show GitHub Exploit DB Packet Storm
221297 4.8 MEDIUM
Network
netgear rbr20_firmware
rbs20_firmware
rbk20_firmware
rbr40_firmware
rbs40_firmware
rbk40_firmware
rbr50_firmware
rbs50_firmware
rbk50_firmware
Certain NETGEAR devices are affected by stored XSS. This affects RBR20 before 2.3.5.26, RBS20 before 2.3.5.26, RBK20 before 2.3.5.26, RBR40 before 2.3.5.30, RBS40 before 2.3.5.30, RBK40 before 2.3.5.… CWE-79
Cross-site Scripting
CVE-2019-20660 2024-11-21 13:38 2020-04-16 Show GitHub Exploit DB Packet Storm
221298 7.2 HIGH
Network
netgear r6400_firmware
r6700_firmware
r6900_firmware
r7900_firmware
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6400v2 before 1.0.4.84, R6700 before 1.0.2.8, R6700v3 before 1.0.4.84, R6900 before 1.0.2.8, and R790… CWE-77
Command Injection
CVE-2019-20659 2024-11-21 13:38 2020-04-16 Show GitHub Exploit DB Packet Storm
221299 6.5 MEDIUM
Adjacent
netgear fs728tlp_firmware
gs105e_firmware
gs105pe_firmware
gs108e_firmware
gs108pe_firmware
gs110emx_firmware
gs116e_firmware
gs408epp_firmware
gs808e_firmware
gs810emx_firmware
Certain NETGEAR devices are affected by disclosure of sensitive information. This affects FS728TLP before 1.0.1.26, GS105Ev2 before 1.6.0.4, GS105PE before 1.6.0.4, GS108Ev3 before 2.06.08, GS108PEv3… NVD-CWE-noinfo
CVE-2019-20658 2024-11-21 13:38 2020-04-16 Show GitHub Exploit DB Packet Storm
221300 7.8 HIGH
Local
netgear xr500_firmware
xr700_firmware
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects XR500 before 2.3.2.56 and XR700 before 1.0.1.20. CWE-77
Command Injection
CVE-2019-20655 2024-11-21 13:38 2020-04-16 Show GitHub Exploit DB Packet Storm