Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 8, 2026, 4:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228951 7.5 危険 winterwebs - EZ Webitor の login.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-4933 2012-12-20 19:28 2010-07-12 Show GitHub Exploit DB Packet Storm
228952 4.3 警告 sungard - SunGard Banner Student System の twbkwbis.P_SecurityQuestion ページにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4930 2012-12-20 19:28 2010-07-12 Show GitHub Exploit DB Packet Storm
228953 7.5 危険 sweetphp - TotalCalendar の admin/manage_users.php における任意のパスワードを変更される脆弱性 CWE-287
不適切な認証
CVE-2009-4929 2012-12-20 19:28 2010-07-12 Show GitHub Exploit DB Packet Storm
228954 7.5 危険 sweetphp - TotalCalendar の config.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2009-4928 2012-12-20 19:28 2010-07-12 Show GitHub Exploit DB Packet Storm
228955 7.5 危険 webmobo - WB News における認証を回避される脆弱性 CWE-287
不適切な認証
CVE-2009-4927 2012-12-20 19:28 2010-07-12 Show GitHub Exploit DB Packet Storm
228956 6.8 警告 UnrealIRCd - UnrealIRCd におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-4893 2012-12-20 19:28 2010-06-15 Show GitHub Exploit DB Packet Storm
228957 7.5 危険 webjump - Content Management System WEBjump! における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-4892 2012-12-20 19:28 2010-06-11 Show GitHub Exploit DB Packet Storm
228958 4.3 警告 retrieve - vBook のログインアプリケーションにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4890 2012-12-20 19:28 2010-06-11 Show GitHub Exploit DB Packet Storm
228959 6.8 警告 sbuilder - CMS S.Builder の index.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2009-4887 2012-12-20 19:28 2010-06-11 Show GitHub Exploit DB Packet Storm
228960 7.5 危険 todd rogers - PHPRecipeBook の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-4883 2012-12-20 19:28 2010-06-11 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 8, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
202701 9.8 CRITICAL
Network
ksystem k-system_wellcomm Download of code without integrity check vulnerability in ActiveX control of Younglimwon Co., Ltd allows the attacker to cause a arbitrary file download and execution. CWE-494
 Download of Code Without Integrity Check
CVE-2020-7873 2024-11-21 14:37 2021-09-9 Show GitHub Exploit DB Packet Storm
202702 9.8 CRITICAL
Network
inoguard execm_coreb2b A vulnerability(improper input validation) in the ExECM CoreB2B solution allows an unauthenticated attacker to download and execute an arbitrary file via httpDownload function. A successful exploit c… CWE-20
 Improper Input Validation 
CVE-2020-7865 2024-11-21 14:37 2021-09-8 Show GitHub Exploit DB Packet Storm
202703 9.8 CRITICAL
Network
dext5 dext5 A vulnerability (improper input validation) in the DEXT5 Upload solution allows an unauthenticated attacker to download and execute an arbitrary file via AddUploadFile, SetSelectItem, DoOpenFile func… CWE-20
 Improper Input Validation 
CVE-2020-7832 2024-11-21 14:37 2021-09-8 Show GitHub Exploit DB Packet Storm
202704 7.5 HIGH
Network
ntracker ntracker_usb_enterprise A SQL-Injection vulnerability in the nTracker USB Enterprise(secure USB management solution) allows a remote unauthenticated attacker to perform SQL query to access username password and other sessio… CWE-89
SQL Injection
CVE-2020-7819 2024-11-21 14:37 2021-09-8 Show GitHub Exploit DB Packet Storm
202705 8.8 HIGH
Network
mastersoft zook_agent
zook_viewer
A buffer overflow issue was discovered in ZOOK solution(remote administration tool) through processing 'ConnectMe' command while parsing a crafted OUTERIP value because of missing boundary check. Thi… CWE-120
Classic Buffer Overflow
CVE-2020-7877 2024-11-21 14:37 2021-09-7 Show GitHub Exploit DB Packet Storm
202706 8.8 HIGH
Network
raonwiz raon_k_upload A vulnerability in File Transfer Solution of Raonwiz could allow arbitrary command execution as the result of viewing a specially-crafted web page. This vulnerability is due to insufficient validatio… CWE-20
 Improper Input Validation 
CVE-2020-7863 2024-11-21 14:37 2021-08-6 Show GitHub Exploit DB Packet Storm
202707 5.4 MEDIUM
Network
sage syracuse Sage X3 Stored XSS Vulnerability on ‘Edit’ Page of User Profile. An authenticated user can pass XSS strings the "First Name," "Last Name," and "Email Address" fields of this web application component… CWE-79
Cross-site Scripting
CVE-2020-7390 2024-11-21 14:37 2021-07-23 Show GitHub Exploit DB Packet Storm
202708 7.2 HIGH
Network
sage syracuse Sage X3 System CHAINE Variable Script Command Injection. An authenticated user with developer access can pass OS commands via this variable used by the web application. Note, this developer configura… CWE-78
OS Command 
CVE-2020-7389 2024-11-21 14:37 2021-07-23 Show GitHub Exploit DB Packet Storm
202709 9.8 CRITICAL
Network
sage adxadmin Sage X3 Unauthenticated Remote Command Execution (RCE) as SYSTEM in AdxDSrv.exe component. By editing the client side authentication request, an attacker can bypass credential validation. While explo… CWE-290
 Authentication Bypass by Spoofing
CVE-2020-7388 2024-11-21 14:37 2021-07-23 Show GitHub Exploit DB Packet Storm
202710 5.3 MEDIUM
Network
sage adxadmin Sage X3 Installation Pathname Disclosure. A specially crafted packet can elicit a response from the AdxDSrv.exe component that reveals the installation directory of the product. Note that this vulner… NVD-CWE-noinfo
CVE-2020-7387 2024-11-21 14:37 2021-07-23 Show GitHub Exploit DB Packet Storm