Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 1, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
229091 2.1 注意 RivetCode Software - RivetTracker におけるパスワードを特定される脆弱性 CWE-310
暗号の問題
CVE-2008-7207 2012-12-20 19:10 2009-09-11 Show GitHub Exploit DB Packet Storm
229092 4.3 警告 stefan ritt - ELOG における脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-7206 2012-12-20 19:10 2009-09-11 Show GitHub Exploit DB Packet Storm
229093 4.3 警告 VirtueMart - VirtueMart の製品ビュー機能における任意のファイルを読み取られる脆弱性 CWE-20
不適切な入力確認
CVE-2008-7205 2012-12-20 19:10 2009-09-11 Show GitHub Exploit DB Packet Storm
229094 6.8 警告 VirtueMart - VirtueMart におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2008-7204 2012-12-20 19:10 2009-09-11 Show GitHub Exploit DB Packet Storm
229095 5 警告 valve software - Valve Software Half-Life Counter-Strike におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2008-7203 2012-12-20 19:10 2009-09-11 Show GitHub Exploit DB Packet Storm
229096 6.8 警告 PHPKIT - PHPKIT におけるクロスサイトリクエストフォージェリ攻撃を実行される脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2008-7193 2012-12-20 19:10 2009-09-9 Show GitHub Exploit DB Packet Storm
229097 6.8 警告 woltlab - wBB の index.php におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2008-7192 2012-12-20 19:10 2009-09-9 Show GitHub Exploit DB Packet Storm
229098 5 警告 pps.jussieu - Polipo におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2008-7191 2012-12-20 19:10 2009-09-9 Show GitHub Exploit DB Packet Storm
229099 5 警告 rittwick banerjee - Telephone Directory 2008 の del_query1.php における任意の連絡先を削除される脆弱性 CWE-20
不適切な入力確認
CVE-2008-7180 2012-12-20 19:10 2009-09-8 Show GitHub Exploit DB Packet Storm
229100 7.5 危険 XOOPS - XOOPS 用の Uploader モジュールにおけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-7178 2012-12-20 19:10 2009-09-8 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 2, 2026, 4:18 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
195141 7.5 HIGH
Network
convert-svg-core_project convert-svg-core This affects all versions of package convert-svg-core; all versions of package convert-svg-to-png; all versions of package convert-svg-to-jpeg. Using a specially crafted SVG file, an attacker could r… CWE-22
Path Traversal
CVE-2021-23631 2024-11-21 14:51 2022-01-22 Show GitHub Exploit DB Packet Storm
195142 9.8 CRITICAL
Network
cached-path-relative_project
debian
cached-path-relative
debian_linux
The package cached-path-relative before 1.1.0 are vulnerable to Prototype Pollution via the cache variable that is set as {} instead of Object.create(null) in the cachedPathRelative function, which a… CWE-1321
 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVE-2021-23518 2024-11-21 14:51 2022-01-22 Show GitHub Exploit DB Packet Storm
195143 7.5 HIGH
Network
camunda min-dash The package min-dash before 3.8.1 are vulnerable to Prototype Pollution via the set method due to missing enforcement of key types. CWE-1321
 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVE-2021-23460 2024-11-21 14:51 2022-01-22 Show GitHub Exploit DB Packet Storm
195144 7.5 HIGH
Network
fresenius-kabi vigilant_centerium
vigilant_mastermed
vigilant_insight
agilia_partner_maintenance_software
agilia_connect_firmware
link\+_agilia_firmware
Requests may be used to interrupt the normal operation of the device. When exploited, Fresenius Kabi Agilia Link+ version 3.0 must be rebooted via a hard reset triggered by pressing a button on the r… CWE-400
 Uncontrolled Resource Consumption
CVE-2021-23236 2024-11-21 14:51 2022-01-22 Show GitHub Exploit DB Packet Storm
195145 9.8 CRITICAL
Network
fresenius-kabi vigilant_centerium
vigilant_mastermed
vigilant_insight
agilia_partner_maintenance_software
agilia_connect_firmware
link\+_agilia_firmware
Sensitive endpoints in Fresenius Kabi Agilia Link+ v3.0 and prior can be accessed without any authentication information such as the session cookie. An attacker can send requests to sensitive endpoin… CWE-798
 Use of Hard-coded Credentials
CVE-2021-23233 2024-11-21 14:51 2022-01-22 Show GitHub Exploit DB Packet Storm
195146 5.5 MEDIUM
Local
fresenius-kabi agilia_connect
vigilant_centerium
vigilant_mastermed
vigilant_insight
agilia_partner_maintenance_software
link\+_agilia_firmware
An attacker with physical access to the host can extract the secrets from the registry and create valid JWT tokens for the Fresenius Kabi Vigilant MasterMed version 2.0.1.3 application and impersonat… CWE-522
 Insufficiently Protected Credentials
CVE-2021-23207 2024-11-21 14:51 2022-01-22 Show GitHub Exploit DB Packet Storm
195147 9.8 CRITICAL
Network
fresenius-kabi agilia_connect_firmware
vigilant_centerium
vigilant_mastermed
vigilant_insight
agilia_partner_maintenance_software
link\+_agilia_firmware
The web application on Agilia Link+ version 3.0 implements authentication and session management mechanisms exclusively on the client-side and does not protect authentication attributes sufficiently. CWE-287
Improper Authentication
CVE-2021-23196 2024-11-21 14:51 2022-01-22 Show GitHub Exploit DB Packet Storm
195148 5.3 MEDIUM
Network
fresenius-kabi agilia_connect_firmware
vigilant_centerium
vigilant_mastermed
vigilant_insight
agilia_partner_maintenance_software
link\+_agilia_firmware
Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 has the option for automated indexing (directory listing) activated. When accessing a directory, a web server delivers its… CWE-200
Information Exposure
CVE-2021-23195 2024-11-21 14:51 2022-01-22 Show GitHub Exploit DB Packet Storm
195149 7.8 HIGH
Local
bosch amc2_firmware
access_management_system
access_professional_edition
building_integration_system
The Bosch software tools AccessIPConfig.exe and AmcIpConfig.exe are used to configure certains settings in AMC2 devices. The tool allows putting a password protection on configured devices to restric… CWE-306
Missing Authentication for Critical Function
CVE-2021-23843 2024-11-21 14:51 2022-01-20 Show GitHub Exploit DB Packet Storm
195150 7.1 HIGH
Local
bosch amc2_firmware
access_management_system
access_professional_edition
building_integration_system
Communication to the AMC2 uses a state-of-the-art cryptographic algorithm for symmetric encryption called Blowfish. An attacker could retrieve the key from the firmware to decrypt network traffic bet… CWE-798
 Use of Hard-coded Credentials
CVE-2021-23842 2024-11-21 14:51 2022-01-20 Show GitHub Exploit DB Packet Storm