Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 31, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
229131 7.5 危険 Pligg - Pligg における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-7091 2012-12-20 19:10 2009-08-26 Show GitHub Exploit DB Packet Storm
229132 7.8 危険 Pligg - Pligg におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-7090 2012-12-20 19:10 2009-08-26 Show GitHub Exploit DB Packet Storm
229133 4.3 警告 Pligg - Pligg におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-7089 2012-12-20 19:10 2009-08-26 Show GitHub Exploit DB Packet Storm
229134 7.5 危険 thehockeystop - TheHockeyStop HockeySTATS Online における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-7085 2012-12-20 19:10 2009-08-26 Show GitHub Exploit DB Packet Storm
229135 7.5 危険 revou - ReVou Micro Blogging Twitter クローンにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-7083 2012-12-20 19:10 2009-08-25 Show GitHub Exploit DB Packet Storm
229136 4.3 警告 Simple Machines
phpraider
- Simple Machines phpRaider の不特定のコンポーネントにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-7035 2012-12-20 19:10 2009-08-24 Show GitHub Exploit DB Packet Storm
229137 7.5 危険 tigran abrahamyan - PHPEcho CMS の kernel/smarty/Smarty.class.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2008-7034 2012-12-20 19:10 2009-08-24 Show GitHub Exploit DB Packet Storm
229138 7.5 危険 site2nite - Site2Nite Real Estate Web における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-7030 2012-12-20 19:10 2009-08-24 Show GitHub Exploit DB Packet Storm
229139 10 危険 skalinks - Skalfa Software SkaLinks Exchange Script における管理者を追加される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-7010 2012-12-20 19:10 2009-08-19 Show GitHub Exploit DB Packet Storm
229140 7.5 危険 phpversion - Free PHP VX Guestbook における管理者アクセス権を取得される脆弱性 CWE-287
不適切な認証
CVE-2008-7007 2012-12-20 19:10 2009-08-19 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 1, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
208431 8.8 HIGH
Network
xstream_project
debian
netapp
apache
oracle
xstream
debian_linux
snapmanager
activemq
banking_platform
communications_policy_management
banking_virtual_account_management
business_activity_monitoring
retail_xstore_point…
XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Onl… - CVE-2020-26217 2024-11-21 14:19 2020-11-17 Show GitHub Exploit DB Packet Storm
208432 6.5 MEDIUM
Network
jetbrains ktor In JetBrains Ktor before 1.4.1, HTTP request smuggling was possible. CWE-444
HTTP Request Smuggling
CVE-2020-26129 2024-11-21 14:19 2020-11-17 Show GitHub Exploit DB Packet Storm
208433 9.8 CRITICAL
Network
user_registration_\&_login_and_user_management_system_project user_registration_\&_login_and_user_management_system SQL injection vulnerability in PHPGurukul User Registration & Login and User Management System With admin panel 2.1 allows remote attackers to execute arbitrary SQL commands and bypass authentication. CWE-89
SQL Injection
CVE-2020-25952 2024-11-21 14:19 2020-11-17 Show GitHub Exploit DB Packet Storm
208434 6.5 MEDIUM
Network
spreecommerce spree Spree is a complete open source e-commerce solution built with Ruby on Rails. In Spree from version 3.7 and before versions 3.7.13, 4.0.5, and 4.1.12, there is an authorization bypass vulnerability. … - CVE-2020-26223 2024-11-21 14:19 2020-11-14 Show GitHub Exploit DB Packet Storm
208435 5.3 MEDIUM
Network
radarcovid radar-covid-backend-dp3t-server
radarcovid
Radar COVID is the official COVID-19 exposure notification app for Spain. In affected versions of Radar COVID, identification and de-anonymization of COVID-19 positive users that upload Radar COVID T… - CVE-2020-26230 2024-11-21 14:19 2020-11-14 Show GitHub Exploit DB Packet Storm
208436 8.8 HIGH
Network
dependabot_project dependabot Dependabot is a set of packages for automated dependency management for Ruby, JavaScript, Python, PHP, Elixir, Rust, Java, .NET, Elm and Go. In Dependabot-Core from version 0.119.0.beta1 before versi… - CVE-2020-26222 2024-11-21 14:19 2020-11-14 Show GitHub Exploit DB Packet Storm
208437 6.1 MEDIUM
Network
touchbase.ai_project touchbase.ai touchbase.ai before version 2.0 is vulnerable to Cross-Site Scripting (XSS). The vulnerability allows an attacker to send malicious JavaScript code which could result in hijacking of the user's cooki… - CVE-2020-26221 2024-11-21 14:19 2020-11-12 Show GitHub Exploit DB Packet Storm
208438 3.5 LOW
Network
touchbase.ai_project touchbase.ai toucbase.ai before version 2.0 leaks information by not stripping exif data from images. Anyone with access to the uploaded image of other users could obtain its geolocation, device, and software ver… - CVE-2020-26220 2024-11-21 14:19 2020-11-12 Show GitHub Exploit DB Packet Storm
208439 6.1 MEDIUM
Network
touchbase.ai_project touchbase.ai touchbase.ai before version 2.0 is vulnerable to Open Redirect. Impacts can be many, and vary from theft of information and credentials, to the redirection to malicious websites containing attacker-c… - CVE-2020-26219 2024-11-21 14:19 2020-11-12 Show GitHub Exploit DB Packet Storm
208440 6.1 MEDIUM
Network
touchbase.ai_project touchbase.ai touchbase.ai before version 2.0 is vulnerable to Cross-Site Scripting. The vulnerability allows an attacker to inject HTML payloads which could result in defacement, user redirection to a malicious w… - CVE-2020-26218 2024-11-21 14:19 2020-11-12 Show GitHub Exploit DB Packet Storm