Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 4, 2026, 12:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228761 7.5 危険 sopinet - Joomla! 用の JBudgetsMagic コンポーネントにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-3332 2012-12-20 19:28 2009-09-23 Show GitHub Exploit DB Packet Storm
228762 4.3 警告 webilix - WX-Guestbook の sign.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-3328 2012-12-20 19:28 2009-09-23 Show GitHub Exploit DB Packet Storm
228763 7.5 危険 webilix - WX-Guestbook における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-3327 2012-12-20 19:28 2009-09-23 Show GitHub Exploit DB Packet Storm
228764 7.5 危険 robig - BAROSmini における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2009-3323 2012-12-20 19:28 2009-09-23 Show GitHub Exploit DB Packet Storm
228765 7.8 危険 シーメンス - Siemens Gigaset SE361 WLAN ルータにおけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2009-3322 2012-12-20 19:28 2009-09-23 Show GitHub Exploit DB Packet Storm
228766 6.8 警告 saphplesson - SaphpLesson における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-3321 2012-12-20 19:28 2009-09-23 Show GitHub Exploit DB Packet Storm
228767 4.3 警告 zenas - Zenas PaoLink の scrivi.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-3320 2012-12-20 19:28 2009-09-23 Show GitHub Exploit DB Packet Storm
228768 7.5 危険 thecodeweasel - OpenSiteAdmin の pages/pageHeader.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2009-3317 2012-12-20 19:28 2009-09-23 Show GitHub Exploit DB Packet Storm
228769 6.8 警告 tomex - phpPollScript の php/init.poll.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2009-3312 2012-12-20 19:28 2009-09-23 Show GitHub Exploit DB Packet Storm
228770 4.3 警告 rssmediascript - RSSMediaScript の index.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-3311 2012-12-20 19:28 2009-09-23 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 4, 2026, 4:17 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
202691 5.5 MEDIUM
Local
taskautomation carbonftp CarbonFTP v1.4 uses insecure proprietary password encryption with a hard-coded weak encryption key. The key for local FTP server passwords is hard-coded in the binary. CWE-798
CWE-327
 Use of Hard-coded Credentials
 Use of a Broken or Risky Cryptographic Algorithm
CVE-2020-6857 2024-11-21 14:36 2020-01-22 Show GitHub Exploit DB Packet Storm
202692 8.8 HIGH
Network
qdpm qdpm A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code file via the profile photo functionality, by leveraging a path traversal vulner… CWE-22
CWE-434
Path Traversal
 Unrestricted Upload of File with Dangerous Type 
CVE-2020-7246 2024-11-21 14:36 2020-01-21 Show GitHub Exploit DB Packet Storm
202693 6.1 MEDIUM
Network
ibm chatbot_with_ibm_watson The conversation-watson plugin before 0.8.21 for WordPress has a DOM-based XSS vulnerability that is executed when a chat message containing JavaScript is sent. CWE-79
Cross-site Scripting
CVE-2020-7239 2024-11-21 14:36 2020-01-21 Show GitHub Exploit DB Packet Storm
202694 4.8 MEDIUM
Network
smc d3g0804_firmware SMC D3G0804W 3.5.2.5-LAT_GA devices allow XSS via the SSID field on the WiFi Network Configuration page (after a successful login to the admin account). CWE-79
Cross-site Scripting
CVE-2020-7249 2024-11-21 14:36 2020-01-21 Show GitHub Exploit DB Packet Storm
202695 7.2 HIGH
Network
comtechtel stampede_fx-1010_firmware Comtech Stampede FX-1010 7.4.3 devices allow remote authenticated administrators to achieve remote code execution by navigating to the Poll Routes page and entering shell metacharacters in the Router… CWE-78
OS Command 
CVE-2020-7244 2024-11-21 14:36 2020-01-21 Show GitHub Exploit DB Packet Storm
202696 7.2 HIGH
Network
comtechtel stampede_fx-1010_firmware Comtech Stampede FX-1010 7.4.3 devices allow remote authenticated administrators to achieve remote code execution by navigating to the Fetch URL page and entering shell metacharacters in the URL fiel… CWE-78
OS Command 
CVE-2020-7243 2024-11-21 14:36 2020-01-21 Show GitHub Exploit DB Packet Storm
202697 7.2 HIGH
Network
comtechtel stampede_fx-1010_firmware Comtech Stampede FX-1010 7.4.3 devices allow remote authenticated administrators to achieve remote code execution by navigating to the Diagnostics Trace Route page and entering shell metacharacters i… CWE-78
OS Command 
CVE-2020-7242 2024-11-21 14:36 2020-01-21 Show GitHub Exploit DB Packet Storm
202698 7.5 HIGH
Network
wpseeds wp_database_backup The WP Database Backup plugin through 5.5 for WordPress stores downloads by default locally in the directory wp-content/uploads/db-backup/. This might allow attackers to read ZIP archives by guessing… CWE-330
 Use of Insufficiently Random Values
CVE-2020-7241 2024-11-21 14:36 2020-01-21 Show GitHub Exploit DB Packet Storm
202699 5.5 MEDIUM
Local
gallagher command_centre An issue was discovered in Gallagher Command Centre 7.x before 7.90.991(MR5), 8.00 before 8.00.1161(MR5), and 8.10 before 8.10.1134(MR4). External system configuration data (used for third party inte… CWE-532
 Inclusion of Sensitive Information in Log Files
CVE-2020-7215 2024-11-21 14:36 2020-01-20 Show GitHub Exploit DB Packet Storm
202700 8.8 HIGH
Network
cacti cacti Cacti 1.2.8 allows Remote Code Execution (by privileged users) via shell metacharacters in the Performance Boost Debug Log field of poller_automation.php. OS commands are executed when a new poller c… CWE-78
OS Command 
CVE-2020-7237 2024-11-21 14:36 2020-01-20 Show GitHub Exploit DB Packet Storm