Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 8, 2026, 12:07 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228781 4.3 警告 wowd - Wowd クライアントの index.html におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4586 2012-12-20 19:28 2010-01-7 Show GitHub Exploit DB Packet Storm
228782 7.5 危険 XOOPS - XOOPS 用の Dictionary モジュールにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-4582 2012-12-20 19:28 2010-01-6 Show GitHub Exploit DB Packet Storm
228783 6.8 警告 roseonlinecms - RoseOnlineCMS の modules/admincp.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2009-4581 2012-12-20 19:28 2010-01-6 Show GitHub Exploit DB Packet Storm
228784 4.3 警告 qproje - Joomla! 用の qpersonel コンポーネントにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4575 2012-12-20 19:28 2010-01-6 Show GitHub Exploit DB Packet Storm
228785 6.8 警告 phpshop - PhpShop におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2009-4572 2012-12-20 19:28 2010-01-5 Show GitHub Exploit DB Packet Storm
228786 7.5 危険 phpshop - PhpShop の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-4571 2012-12-20 19:28 2010-01-5 Show GitHub Exploit DB Packet Storm
228787 4.3 警告 phpshop - PhpShop におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4570 2012-12-20 19:28 2010-01-5 Show GitHub Exploit DB Packet Storm
228788 3.5 注意 Viscacha - Viscacha の editprofile.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4567 2012-12-20 19:28 2010-01-5 Show GitHub Exploit DB Packet Storm
228789 7.5 危険 Zenphoto - Zenphoto の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-4566 2012-12-20 19:28 2010-01-4 Show GitHub Exploit DB Packet Storm
228790 6.8 警告 Zenphoto - Zenphoto の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-4564 2012-12-20 19:28 2010-01-4 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 8, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
216161 7.8 HIGH
Local
win911 win-911 An exploitable local privilege elevation vulnerability exists in the file system permissions of the Win-911 Enterprise V4.20.13 install directory via WIN-911 Account Change Utility. Depending on the … CWE-276
Incorrect Default Permissions 
CVE-2020-13540 2024-11-21 14:01 2021-01-6 Show GitHub Exploit DB Packet Storm
216162 7.8 HIGH
Local
win911 win-911 An exploitable local privilege elevation vulnerability exists in the file system permissions of the Win-911 Enterprise V4.20.13 install directory via “WIN-911 Mobile Runtime” service. Depending on th… CWE-276
Incorrect Default Permissions 
CVE-2020-13539 2024-11-21 14:01 2021-01-6 Show GitHub Exploit DB Packet Storm
216163 7.5 HIGH
Network
xwiki xwiki XWiki Platform before 12.8 mishandles escaping in the property displayer. CWE-116
 Improper Encoding or Escaping of Output
CVE-2020-13654 2024-11-21 14:01 2020-12-31 Show GitHub Exploit DB Packet Storm
216164 4.8 MEDIUM
Network
nchsoftware express_invoice NCH Express Invoice 8.06 to 8.24 is vulnerable to Reflected XSS in the Quotes List module. CWE-79
Cross-site Scripting
CVE-2020-13476 2024-11-21 14:01 2020-12-29 Show GitHub Exploit DB Packet Storm
216165 6.5 MEDIUM
Network
nchsoftware express_accounts In NCH Express Accounts 8.24 and earlier, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functionalities such as Add/Edit users. CWE-425
 Direct Request ('Forced Browsing')
CVE-2020-13474 2024-11-21 14:01 2020-12-29 Show GitHub Exploit DB Packet Storm
216166 5.5 MEDIUM
Local
nchsoftware express_accounts NCH Express Accounts 8.24 and earlier allows local users to discover the cleartext password by reading the configuration file. CWE-312
 Cleartext Storage of Sensitive Information
CVE-2020-13473 2024-11-21 14:01 2020-12-29 Show GitHub Exploit DB Packet Storm
216167 8.8 HIGH
Network
foxitsoftware foxit_reader A type confusion vulnerability exists in the JavaScript engine of Foxit Software’s Foxit PDF Reader, version 10.1.0.37527. A specially crafted PDF document can trigger an improper use of an object, r… CWE-787
CWE-843
 Out-of-bounds Write
Type Confusion
CVE-2020-13547 2024-11-21 14:01 2020-12-23 Show GitHub Exploit DB Packet Storm
216168 8.8 HIGH
Network
foxitsoftware foxit_reader A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 10.1.0.37527. A specially crafted PDF document can trigger the reuse of previously free memory w… CWE-416
 Use After Free
CVE-2020-13570 2024-11-21 14:01 2020-12-23 Show GitHub Exploit DB Packet Storm
216169 8.8 HIGH
Network
foxitsoftware foxit_reader A use after free vulnerability exists in the JavaScript engine of Foxit Software’s Foxit PDF Reader, version 10.1.0.37527. A specially crafted PDF document can trigger reuse of previously free memory… CWE-416
 Use After Free
CVE-2020-13560 2024-11-21 14:01 2020-12-23 Show GitHub Exploit DB Packet Storm
216170 8.8 HIGH
Network
foxitsoftware foxit_reader A use after free vulnerability exists in the JavaScript engine of Foxit Software’s Foxit PDF Reader, version 10.1.0.37527. A specially crafted PDF document can trigger reuse of previously free memory… CWE-416
 Use After Free
CVE-2020-13557 2024-11-21 14:01 2020-12-23 Show GitHub Exploit DB Packet Storm