Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 9, 2026, noon

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
229071 6.8 警告 phpshop - PhpShop におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2009-4572 2012-12-20 19:28 2010-01-5 Show GitHub Exploit DB Packet Storm
229072 7.5 危険 phpshop - PhpShop の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-4571 2012-12-20 19:28 2010-01-5 Show GitHub Exploit DB Packet Storm
229073 4.3 警告 phpshop - PhpShop におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4570 2012-12-20 19:28 2010-01-5 Show GitHub Exploit DB Packet Storm
229074 3.5 注意 Viscacha - Viscacha の editprofile.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4567 2012-12-20 19:28 2010-01-5 Show GitHub Exploit DB Packet Storm
229075 7.5 危険 Zenphoto - Zenphoto の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-4566 2012-12-20 19:28 2010-01-4 Show GitHub Exploit DB Packet Storm
229076 6.8 警告 Zenphoto - Zenphoto の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-4564 2012-12-20 19:28 2010-01-4 Show GitHub Exploit DB Packet Storm
229077 4.3 警告 Zenphoto - Zenphoto の zp-core/admin-options.php におけるクロスサイトリクエストフォージェリの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4563 2012-12-20 19:28 2010-01-4 Show GitHub Exploit DB Packet Storm
229078 4.3 警告 Zenphoto - Zenphoto の zp-core/admin.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4562 2012-12-20 19:28 2010-01-4 Show GitHub Exploit DB Packet Storm
229079 6.8 警告 worms-league - WebLeague の Admin/index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-4561 2012-12-20 19:28 2010-01-4 Show GitHub Exploit DB Packet Storm
229080 7.5 危険 worms-league - WebLeague の profile.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-4560 2012-12-20 19:28 2010-01-4 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 9, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
225841 7.5 HIGH
Network
mattermost mattermost_server An issue was discovered in Mattermost Server before 5.11.0. Invite IDs were improperly generated. CWE-20
 Improper Input Validation 
CVE-2019-20868 2024-11-21 13:39 2020-06-20 Show GitHub Exploit DB Packet Storm
225842 5.3 MEDIUM
Network
mattermost mattermost_server An issue was discovered in Mattermost Server before 5.11.0. An attacker can interfere with a channel's post loading via one crafted post. NVD-CWE-noinfo
CVE-2019-20867 2024-11-21 13:39 2020-06-20 Show GitHub Exploit DB Packet Storm
225843 5.3 MEDIUM
Network
mattermost mattermost_server An issue was discovered in Mattermost Server before 5.12.0. Use of a Proxy HTTP header, rather than the source address in an IP packet header, for obtaining IP address information was mishandled. CWE-444
HTTP Request Smuggling
CVE-2019-20866 2024-11-21 13:39 2020-06-20 Show GitHub Exploit DB Packet Storm
225844 8.8 HIGH
Network
mattermost mattermost_server An issue was discovered in Mattermost Server before 5.12.0, 5.11.1, 5.10.2, 5.9.2, and 4.10.10. The login page allows CSRF. CWE-352
 Origin Validation Error
CVE-2019-20865 2024-11-21 13:39 2020-06-20 Show GitHub Exploit DB Packet Storm
225845 7.5 HIGH
Network
mattermost mattermost_plugins An issue was discovered in Mattermost Plugins before 5.13.0. The GitHub plugin allows an attacker to attach his Mattermost account to a different person's GitHub account. NVD-CWE-noinfo
CVE-2019-20864 2024-11-21 13:39 2020-06-20 Show GitHub Exploit DB Packet Storm
225846 7.5 HIGH
Network
mattermost mattermost_server An issue was discovered in Mattermost Server before 5.13.0. Incoming webhook creation is not properly restricted. NVD-CWE-noinfo
CVE-2019-20863 2024-11-21 13:39 2020-06-20 Show GitHub Exploit DB Packet Storm
225847 7.5 HIGH
Network
mattermost mattermost_server An issue was discovered in Mattermost Server before 5.13.0. Non-members may fetch a team's slash commands. NVD-CWE-noinfo
CVE-2019-20862 2024-11-21 13:39 2020-06-20 Show GitHub Exploit DB Packet Storm
225848 8.8 HIGH
Network
mattermost mattermost_desktop An issue was discovered in Mattermost Desktop App before 4.2.2. It allows attackers to execute arbitrary code via a crafted link. NVD-CWE-noinfo
CVE-2019-20861 2024-11-21 13:39 2020-06-20 Show GitHub Exploit DB Packet Storm
225849 5.5 MEDIUM
Local
mattermost mattermost_server An issue was discovered in Mattermost Server before 5.14.0, 5.13.3, 5.12.6, and 5.9.4. It allows remote attackers to cause a denial of service (application hang) via a crafted SVG document. NVD-CWE-noinfo
CVE-2019-20860 2024-11-21 13:39 2020-06-20 Show GitHub Exploit DB Packet Storm
225850 7.5 HIGH
Network
mattermost mattermost_server An issue was discovered in Mattermost Server before 5.15.0. Login access control can be bypassed via crafted input. NVD-CWE-noinfo
CVE-2019-20859 2024-11-21 13:39 2020-06-20 Show GitHub Exploit DB Packet Storm