Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 31, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
229091 6.8 警告 VirtueMart - VirtueMart におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2008-7204 2012-12-20 19:10 2009-09-11 Show GitHub Exploit DB Packet Storm
229092 5 警告 valve software - Valve Software Half-Life Counter-Strike におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2008-7203 2012-12-20 19:10 2009-09-11 Show GitHub Exploit DB Packet Storm
229093 6.8 警告 PHPKIT - PHPKIT におけるクロスサイトリクエストフォージェリ攻撃を実行される脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2008-7193 2012-12-20 19:10 2009-09-9 Show GitHub Exploit DB Packet Storm
229094 6.8 警告 woltlab - wBB の index.php におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2008-7192 2012-12-20 19:10 2009-09-9 Show GitHub Exploit DB Packet Storm
229095 5 警告 pps.jussieu - Polipo におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2008-7191 2012-12-20 19:10 2009-09-9 Show GitHub Exploit DB Packet Storm
229096 5 警告 rittwick banerjee - Telephone Directory 2008 の del_query1.php における任意の連絡先を削除される脆弱性 CWE-20
不適切な入力確認
CVE-2008-7180 2012-12-20 19:10 2009-09-8 Show GitHub Exploit DB Packet Storm
229097 7.5 危険 XOOPS - XOOPS 用の Uploader モジュールにおけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-7178 2012-12-20 19:10 2009-09-8 Show GitHub Exploit DB Packet Storm
229098 7.5 危険 yanick bourbeau - LNP における管理者権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-7172 2012-12-20 19:10 2009-09-8 Show GitHub Exploit DB Packet Storm
229099 4.3 警告 yanick bourbeau - LNP におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-7171 2012-12-20 19:10 2009-09-8 Show GitHub Exploit DB Packet Storm
229100 9.3 危険 uusee - UUSee UUUpgrade ActiveX コントロールにおける任意のファイルを強制的にダウンロードされる脆弱性 CWE-Other
その他
CVE-2008-7168 2012-12-20 19:10 2009-09-8 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 31, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
208421 8.1 HIGH
Network
monocms monocms MonoCMS Blog 1.0 is affected by: Arbitrary File Deletion. Any authenticated user can delete files on and off the webserver (php files can be unlinked and not deleted). CWE-22
Path Traversal
CVE-2020-25985 2024-11-21 14:19 2020-10-7 Show GitHub Exploit DB Packet Storm
208422 7.5 HIGH
Network
monocms monocms MonoCMS Blog 1.0 stores hard-coded admin hashes in the log.xml file in the source files for MonoCMS Blog. Hash type is bcrypt and hashcat mode 3200 can be used to crack the hash. CWE-532
 Inclusion of Sensitive Information in Log Files
CVE-2020-25987 2024-11-21 14:19 2020-10-6 Show GitHub Exploit DB Packet Storm
208423 6.5 MEDIUM
Network
monocms monocms A Cross Site Request Forgery (CSRF) vulnerability in MonoCMS Blog 1.0 allows attackers to change the password of a user. CWE-352
 Origin Validation Error
CVE-2020-25986 2024-11-21 14:19 2020-10-6 Show GitHub Exploit DB Packet Storm
208424 8.8 HIGH
Network
cuppacms cuppacms The file manager option in CuppaCMS before 2019-11-12 allows an authenticated attacker to upload a malicious file within an image extension and through a custom request using the rename function prov… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2020-26048 2024-11-21 14:19 2020-10-6 Show GitHub Exploit DB Packet Storm
208425 7.5 HIGH
Network
clickstudios passwordstate ClickStudios Passwordstate Password Reset Portal prior to build 8501 is affected by an authentication bypass vulnerability. The ResetPassword function does not validate whether the user has successfu… CWE-306
Missing Authentication for Critical Function
CVE-2020-26061 2024-11-21 14:19 2020-10-5 Show GitHub Exploit DB Packet Storm
208426 5.4 MEDIUM
Network
qdpm qdpm The file upload functionality in qdPM 9.1 doesn't check the file description, which allows remote authenticated attackers to inject web script or HTML via the attachments info parameter, aka XSS. Thi… CWE-79
Cross-site Scripting
CVE-2020-26166 2024-11-21 14:19 2020-10-5 Show GitHub Exploit DB Packet Storm
208427 6.1 MEDIUM
Network
livehelperchat live_helper_chat Live Helper Chat before 3.44v allows reflected XSS via the setsettingajax PATH_INFO. CWE-79
Cross-site Scripting
CVE-2020-26135 2024-11-21 14:19 2020-10-2 Show GitHub Exploit DB Packet Storm
208428 6.1 MEDIUM
Network
livehelperchat live_helper_chat Live Helper Chat before 3.44v allows stored XSS in chat messages with an operator via BBCode. CWE-79
Cross-site Scripting
CVE-2020-26134 2024-11-21 14:19 2020-10-2 Show GitHub Exploit DB Packet Storm
208429 8.8 HIGH
Network
openmediavault openmediavault openmediavault before 4.1.36 and 5.x before 5.5.12 allows authenticated PHP code injection attacks, via the sortfield POST parameter of rpc.php, because json_encode_safe is not used in config/databas… CWE-94
Code Injection
CVE-2020-26124 2024-11-21 14:19 2020-10-2 Show GitHub Exploit DB Packet Storm
208430 5.5 MEDIUM
Local
artifex
debian
fedoraproject
mupdf
debian_linux
fedora
Artifex MuPDF before 1.18.0 has a heap based buffer over-write when parsing JBIG2 files allowing attackers to cause a denial of service. CWE-787
 Out-of-bounds Write
CVE-2020-26519 2024-11-21 14:19 2020-10-2 Show GitHub Exploit DB Packet Storm