Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 8, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228621 7.5 危険 shopex - ECShop の search.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-2042 2012-12-20 19:29 2010-05-25 Show GitHub Exploit DB Packet Storm
228622 4.3 警告 php-calendar project - PHP-Calendar の index.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-2041 2012-12-20 19:29 2010-05-25 Show GitHub Exploit DB Packet Storm
228623 4.3 警告 V-EVA - V-EVA Shopzilla Affiliate Script PHP の search.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-2040 2012-12-20 19:29 2010-05-25 Show GitHub Exploit DB Packet Storm
228624 1.9 注意 wolfram research - Mathematica における任意のファイルを上書きされる脆弱性 CWE-59
リンク解釈の問題
CVE-2010-2027 2012-12-20 19:29 2010-05-24 Show GitHub Exploit DB Packet Storm
228625 6.8 警告 sebrac.webcindario - MigasCMS の function.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-2012 2012-12-20 19:29 2010-05-24 Show GitHub Exploit DB Packet Storm
228626 4.3 警告 proxy2 - Advanced Poll の misc/get_admin.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-2003 2012-12-20 19:29 2010-05-20 Show GitHub Exploit DB Packet Storm
228627 2.1 注意 ron jerome - Drupal 用の Bibliography モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-2000 2012-12-20 19:29 2010-05-12 Show GitHub Exploit DB Packet Storm
228628 2.1 注意 Saurused Ltd. - Saurus CMS の admin/edit.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-1997 2012-12-20 19:29 2010-05-20 Show GitHub Exploit DB Packet Storm
228629 2.1 注意 tomatocms - TomatoCMS の index.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-1996 2012-12-20 19:29 2010-05-20 Show GitHub Exploit DB Packet Storm
228630 2.1 注意 tomatocms - TomatoCMS の index.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-1995 2012-12-20 19:29 2010-05-20 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 8, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
226171 8.1 HIGH
Network
openlambda_project openlambda OpenLambda 2019-09-10 allows DNS rebinding attacks against the OL server for the REST API on TCP port 5000. CWE-346
 Origin Validation Error
CVE-2019-20329 2024-11-21 13:38 2020-01-3 Show GitHub Exploit DB Packet Storm
226172 6.1 MEDIUM
Network
mybb mybb MyBB before 1.8.22 allows an open redirect on login. CWE-601
Open Redirect
CVE-2019-20225 2024-11-21 13:38 2020-01-3 Show GitHub Exploit DB Packet Storm
226173 8.8 HIGH
Network
miniupnp_project ngiflib ngiflib 0.4 has a heap-based buffer over-read in GifIndexToTrueColor in ngiflib.c. CWE-125
Out-of-bounds Read
CVE-2019-20219 2024-11-21 13:38 2020-01-3 Show GitHub Exploit DB Packet Storm
226174 6.1 MEDIUM
Network
sitracker support_incident_tracker In Support Incident Tracker (SiT!) 3.67, the id parameter is affected by XSS on all endpoints that use this parameter, a related issue to CVE-2012-2235. CWE-79
Cross-site Scripting
CVE-2019-20223 2024-11-21 13:38 2020-01-2 Show GitHub Exploit DB Packet Storm
226175 6.1 MEDIUM
Network
sitracker support_incident_tracker In Support Incident Tracker (SiT!) 3.67, the Short Application Name and Application Name inputs in the config.php page are affected by XSS. CWE-79
Cross-site Scripting
CVE-2019-20222 2024-11-21 13:38 2020-01-2 Show GitHub Exploit DB Packet Storm
226176 6.1 MEDIUM
Network
sitracker support_incident_tracker In Support Incident Tracker (SiT!) 3.67, Load Plugins input in the config.php page is affected by XSS. The XSS payload is, for example, executed on the about.php page. CWE-79
Cross-site Scripting
CVE-2019-20221 2024-11-21 13:38 2020-01-2 Show GitHub Exploit DB Packet Storm
226177 6.1 MEDIUM
Network
sitracker support_incident_tracker In Support Incident Tracker (SiT!) 3.67, the search_id parameter in the search_incidents_advanced.php page is affected by XSS. CWE-79
Cross-site Scripting
CVE-2019-20220 2024-11-21 13:38 2020-01-2 Show GitHub Exploit DB Packet Storm
226178 7.5 HIGH
Network
sqlite
debian
canonical
oracle
sqlite
debian_linux
ubuntu_linux
mysql_workbench
selectExpander in select.c in SQLite 3.30.1 proceeds with WITH stack unwinding even after a parsing error. NVD-CWE-Other
CWE-755
 Improper Handling of Exceptional Conditions
CVE-2019-20218 2024-11-21 13:38 2020-01-2 Show GitHub Exploit DB Packet Storm
226179 7.5 HIGH
Network
dlink dir-859_firmware
dir-822_firmware
dir-823_firmware
dir-865l_firmware
dir-868l_firmware
dir-869_firmware
dir-880l_firmware
dir-890l_firmware
dir-890r_firmware
dir-885l_firmw…
D-Link DIR-859 routers before v1.07b03_beta allow Unauthenticated Information Disclosure via the AUTHORIZED_GROUP=1%0a value, as demonstrated by vpnconfig.php. CWE-74
CWE-863
Injection
 Incorrect Authorization
CVE-2019-20213 2024-11-21 13:38 2020-01-2 Show GitHub Exploit DB Packet Storm
226180 5.4 MEDIUM
Network
postieplugin postie The Postie plugin 1.9.40 for WordPress allows XSS, as demonstrated by a certain payload with jaVasCript:/* at the beginning and a crafted SVG element. CWE-79
Cross-site Scripting
CVE-2019-20204 2024-11-21 13:38 2020-01-2 Show GitHub Exploit DB Packet Storm