Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 27, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228971 7.5 危険 TYPO3 Association - TYPO3 用の cm_rdfexport エクステンションにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6594 2012-12-20 19:10 2009-04-3 Show GitHub Exploit DB Packet Storm
228972 6.8 警告 Vuze, Inc. - Vuze の index.tmpl におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2008-6587 2012-12-20 19:10 2009-04-3 Show GitHub Exploit DB Packet Storm
228973 6.8 警告 BitTorrent, Inc. - uTorrent WebUI の gui/index.php におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2008-6586 2012-12-20 19:10 2009-04-3 Show GitHub Exploit DB Packet Storm
228974 6.8 警告 TorrentFlux - TorrentFlux の html/admin.php におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2008-6585 2012-12-20 19:10 2009-04-3 Show GitHub Exploit DB Packet Storm
228975 6 警告 TorrentFlux - TorrentFlux の html/index.php における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2008-6584 2012-12-20 19:10 2009-04-3 Show GitHub Exploit DB Packet Storm
228976 6.8 警告 yehe - Yehe における任意のコードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2008-6568 2012-12-20 19:10 2009-03-31 Show GitHub Exploit DB Packet Storm
228977 10 危険 puppetmaster - The Puppet Master WebUtil の cgi-bin/webutil.pl における任意のコマンドを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2008-6557 2012-12-20 19:10 2009-03-30 Show GitHub Exploit DB Packet Storm
228978 10 危険 puppetmaster - The Puppet Master WebUtil の cgi-bin/webutil.pl における任意のコマンドを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2008-6556 2012-12-20 19:10 2009-03-30 Show GitHub Exploit DB Packet Storm
228979 10 危険 puppetmaster - The Puppet Master WebUtil の cgi-bin/webutil.pl における任意のコマンドを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2008-6555 2012-12-20 19:10 2009-03-30 Show GitHub Exploit DB Packet Storm
228980 7.1 危険 vwsolutions - NULL FTP Server における任意のコマンドを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2008-6534 2012-12-20 19:10 2009-03-26 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 27, 2026, 4:52 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
208501 8.8 HIGH
Network
wuzhicms wuzhicms An issue in WUZHI CMS v.4.1.0 allows a remote attacker to execute arbitrary code via the set_chache method of the function\common.func.php file. CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2020-21325 2024-11-21 14:12 2023-06-21 Show GitHub Exploit DB Packet Storm
208502 6.1 MEDIUM
Network
easycorp zentao Cross Site Scripting vulnerability in EasySoft ZenTao v.11.6.4 allows a remote attacker to execute arbitrary code via the lastComment parameter. CWE-79
Cross-site Scripting
CVE-2020-21268 2024-11-21 14:12 2023-06-21 Show GitHub Exploit DB Packet Storm
208503 8.8 HIGH
Network
hongcms_project hongcms Cross Site Request Forgery vulnerability in Neeke HongCMS 3.0.0 allows a remote attacker to execute arbitrary code and escalate privileges via the updateusers parameter. CWE-352
 Origin Validation Error
CVE-2020-21252 2024-11-21 14:12 2023-06-21 Show GitHub Exploit DB Packet Storm
208504 5.4 MEDIUM
Network
yiicms_project yiicms Cross Site Scripting vulnerability in YiiCMS v.1.0 allows a remote attacker to execute arbitrary code via the news function. CWE-79
Cross-site Scripting
CVE-2020-21246 2024-11-21 14:12 2023-06-21 Show GitHub Exploit DB Packet Storm
208505 9.8 CRITICAL
Network
feehi feehicms File Upload vulenrability in liufee CMS v.2.0.7.1 allows a remote attacker to execute arbitrary code via the image suffix function. CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2020-21174 2024-11-21 14:12 2023-06-21 Show GitHub Exploit DB Packet Storm
208506 6.1 MEDIUM
Network
typora typora Cross Site Scripting vulnerability in Typora v.0.9.79 allows a remote attacker to execute arbitrary code via the mermaid sytax. CWE-79
Cross-site Scripting
CVE-2020-21058 2024-11-21 14:12 2023-06-21 Show GitHub Exploit DB Packet Storm
208507 6.1 MEDIUM
Network
zrlog zrlog Cross Site Scripting vulnerability in zrlog zrlog v.2.1.3 allows a remote attacker to execute arbitrary code via the nickame parameter of the /post/addComment function. CWE-79
Cross-site Scripting
CVE-2020-21052 2024-11-21 14:12 2023-06-21 Show GitHub Exploit DB Packet Storm
208508 7.2 HIGH
Network
pluck-cms pluck File Upload vulnerability in PluckCMS v.4.7.10 allows a remote attacker to execute arbitrary code via the trashcan_restoreitem.php file. CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2020-20969 2024-11-21 14:12 2023-06-21 Show GitHub Exploit DB Packet Storm
208509 7.2 HIGH
Network
pluck-cms pluck File upload vulnerability in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary code and access sensitive information via the theme.php file. CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2020-20919 2024-11-21 14:12 2023-06-21 Show GitHub Exploit DB Packet Storm
208510 7.2 HIGH
Network
pluck-cms pluck An issue discovered in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary php code via the hidden parameter to admin.php when editing a page. CWE-94
Code Injection
CVE-2020-20918 2024-11-21 14:12 2023-06-21 Show GitHub Exploit DB Packet Storm