Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 5, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228681 7.5 危険 xstate - Xstate Real Estate の page.html における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-4477 2012-12-20 19:28 2009-12-30 Show GitHub Exploit DB Packet Storm
228682 7.5 危険 phpope - PHPope における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2009-4472 2012-12-20 19:28 2009-12-30 Show GitHub Exploit DB Packet Storm
228683 4.3 警告 Redmine - Redmine におけるクロスサイトスクリプティング (XSS) を実行される脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4459 2012-12-20 19:28 2009-12-30 Show GitHub Exploit DB Packet Storm
228684 7.5 危険 Provider4u - Vsftpd サーバ用の Vsftpd Webmin モジュールにおける脆弱性 CWE-noinfo
情報不足
CVE-2009-4457 2012-12-20 19:28 2009-12-29 Show GitHub Exploit DB Packet Storm
228685 3.3 注意 saini - VideoCache の vccleaner における任意のファイルを上書きされる脆弱性 CWE-59
リンク解釈の問題
CVE-2009-4454 2012-12-20 19:28 2009-12-29 Show GitHub Exploit DB Packet Storm
228686 8.8 危険 softcab - SoftCab Sound Converter ActiveX コントロール における任意のファイルを作成される脆弱性 CWE-Other
その他
CVE-2009-4453 2012-12-20 19:28 2009-12-29 Show GitHub Exploit DB Packet Storm
228687 4.3 警告 サン・マイクロシステムズ - Sun Java System Directory Server Enterprise Edition の DPS におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2009-4443 2012-12-20 19:28 2009-12-23 Show GitHub Exploit DB Packet Storm
228688 5 警告 サン・マイクロシステムズ - Sun Java System Directory Server Enterprise Edition の DPS におけるサービス運用妨害 (DoS) の脆弱性 CWE-16
環境設定
CVE-2009-4442 2012-12-20 19:28 2009-12-23 Show GitHub Exploit DB Packet Storm
228689 5 警告 サン・マイクロシステムズ - Sun Java System Directory Server Enterprise Edition の DPS におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2009-4441 2012-12-20 19:28 2009-12-23 Show GitHub Exploit DB Packet Storm
228690 6.8 警告 サン・マイクロシステムズ - Sun Java System Directory Server Enterprise Edition の DPS における認証されたユーザのバックエンドの接続をハイジャックされる脆弱性 CWE-362
競合状態
CVE-2009-4440 2012-12-20 19:28 2009-12-23 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 5, 2026, 4:11 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
207851 6.1 MEDIUM
Network
xuxueli xxl-job XXL-JOB 2.2.0 allows Stored XSS (in Add User) to bypass the 20-character limit via xxl-job-admin/src/main/java/com/xxl/job/admin/controller/UserController.java. CWE-79
Cross-site Scripting
CVE-2020-29204 2024-11-21 14:23 2020-12-27 Show GitHub Exploit DB Packet Storm
207852 9.8 CRITICAL
Network
struct2json_project struct2json struct2json before 2020-11-18 is affected by a Buffer Overflow because strcpy is used for S2J_STRUCT_GET_string_ELEMENT. CWE-120
Classic Buffer Overflow
CVE-2020-29203 2024-11-21 14:23 2020-12-27 Show GitHub Exploit DB Packet Storm
207853 5.5 MEDIUM
Local
tengine_project tengine The serializer module in OAID Tengine lite-v1.0 has a Buffer Overflow and crash. NOTE: another person has stated "I don't think there is an proof of overflow so far. CWE-120
Classic Buffer Overflow
CVE-2020-28759 2024-11-21 14:23 2020-12-27 Show GitHub Exploit DB Packet Storm
207854 6.1 MEDIUM
Network
litespeedtech litespeed_cache A cross-site scripting (XSS) vulnerability in the LiteSpeed Cache plugin before 3.6.1 for WordPress can be exploited via the Server IP setting. CWE-79
Cross-site Scripting
CVE-2020-29172 2024-11-21 14:23 2020-12-26 Show GitHub Exploit DB Packet Storm
207855 5.5 MEDIUM
Local
gnome
canonical
fedoraproject
gdk-pixbuf
ubuntu_linux
fedora
GNOME gdk-pixbuf (aka GdkPixbuf) before 2.42.2 allows a denial of service (infinite loop) in lzw.c in the function write_indexes. if c->self_code equals 10, self->code_table[10].extends will assign t… CWE-835
 Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2020-29385 2024-11-21 14:23 2020-12-26 Show GitHub Exploit DB Packet Storm
207856 4.8 MEDIUM
Network
wondercms wondercms WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Admin Panel. An attacker can inject the XSS payload in Page keywords and each time any user will visit the website, the XSS triggers, … CWE-79
Cross-site Scripting
CVE-2020-29247 2024-11-21 14:23 2020-12-25 Show GitHub Exploit DB Packet Storm
207857 7.0 HIGH
Local
mariadb mariadb With MariaDB running on Windows, when local clients connect to the server over named pipes, it's possible for an unprivileged user with an ability to run code on the server machine to intercept the n… NVD-CWE-Other
CVE-2020-28912 2024-11-21 14:23 2020-12-25 Show GitHub Exploit DB Packet Storm
207858 8.1 HIGH
Network
terra-master tos Incorrect Access Control vulnerability in TerraMaster TOS <= 4.2.06 allows remote authenticated attackers to bypass read-only restriction and obtain full access to any folder within the NAS NVD-CWE-noinfo
CVE-2020-29189 2024-11-21 14:23 2020-12-25 Show GitHub Exploit DB Packet Storm
207859 7.1 HIGH
Local
malwarebytes malwarebytes
endpoint_protection
In Malwarebytes Free 4.1.0.56, a symbolic link may be used delete an arbitrary file on the system by exploiting the local quarantine system. CWE-59
Link Following
CVE-2020-28641 2024-11-21 14:23 2020-12-23 Show GitHub Exploit DB Packet Storm
207860 8.8 HIGH
Network
odoo odoo A sandboxing issue in Odoo Community 11.0 through 13.0 and Odoo Enterprise 11.0 through 13.0, when running with Python 3.6 or later, allows remote authenticated users to execute arbitrary code, leadi… NVD-CWE-noinfo
CVE-2020-29396 2024-11-21 14:23 2020-12-23 Show GitHub Exploit DB Packet Storm