Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 19, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
229171 4.3 警告 phpinv - phpInv の search.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-2694 2012-12-20 18:52 2008-06-13 Show GitHub Exploit DB Packet Storm
229172 7.5 危険 PilotCart - ASPilot Pilot Cart の pilot.asp における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2688 2012-12-20 18:52 2008-06-13 Show GitHub Exploit DB Packet Storm
229173 7.5 危険 promanager - ProManager の inc/config.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-2687 2012-12-20 18:52 2008-06-13 Show GitHub Exploit DB Packet Storm
229174 7.5 危険 realm project - Realm CMS の _RealmAdmin/login.asp における 認証を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-2682 2012-12-20 18:52 2008-06-12 Show GitHub Exploit DB Packet Storm
229175 5 警告 realm project - Realm CMS における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2008-2681 2012-12-20 18:52 2008-06-12 Show GitHub Exploit DB Packet Storm
229176 4.3 警告 realm project - Realm CMS の _db/compact.asp におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-2680 2012-12-20 18:52 2008-06-12 Show GitHub Exploit DB Packet Storm
229177 7.5 危険 realm project - Realm CMS の _includes/inc_routines.asp における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2679 2012-12-20 18:52 2008-06-12 Show GitHub Exploit DB Packet Storm
229178 7.5 危険 telephone - Telephone Directory 2008 における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2678 2012-12-20 18:52 2008-06-12 Show GitHub Exploit DB Packet Storm
229179 4.3 警告 telephone - Telephone Directory 2008 の edit1.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-2677 2012-12-20 18:52 2008-06-12 Show GitHub Exploit DB Packet Storm
229180 4.3 警告 softcomplex - PHP Image Gallery の index.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-2675 2012-12-20 18:52 2008-06-12 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 19, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
209131 9.1 CRITICAL
Network
get-simple getsimplecms GetSimpleCMS-3.3.15 is affected by directory traversal. Remote attackers are able to delete arbitrary files via /GetSimpleCMS-3.3.15/admin/log.php CWE-22
Path Traversal
CVE-2020-18191 2024-11-21 14:08 2020-10-2 Show GitHub Exploit DB Packet Storm
209132 9.1 CRITICAL
Network
bludit bludit Bludit v3.8.1 is affected by directory traversal. Remote attackers are able to delete arbitrary files via /admin/ajax/upload-profile-picture. CWE-22
Path Traversal
CVE-2020-18190 2024-11-21 14:08 2020-10-2 Show GitHub Exploit DB Packet Storm
209133 9.8 CRITICAL
Network
pluxml pluxml class.plx.admin.php in PluXml 5.7 allows attackers to execute arbitrary PHP code by modify the configuration file in a linux environment. CWE-94
Code Injection
CVE-2020-18185 2024-11-21 14:08 2020-10-2 Show GitHub Exploit DB Packet Storm
209134 7.2 HIGH
Network
pluxxml pluxxml In PluxXml V5.7,the theme edit function /PluXml/core/admin/parametres_edittpl.php allows remote attackers to execute arbitrary PHP code by placing this code into a template. NVD-CWE-noinfo
CVE-2020-18184 2024-11-21 14:08 2020-10-2 Show GitHub Exploit DB Packet Storm
209135 4.3 MEDIUM
Network
powerdns authoritative An issue has been found in PowerDNS Authoritative Server before 4.3.1 where an authorized user with the ability to insert crafted records into a zone might be able to leak the content of uninitialize… CWE-908
 Use of Uninitialized Resource
CVE-2020-17482 2024-11-21 14:08 2020-10-2 Show GitHub Exploit DB Packet Storm
209136 7.5 HIGH
Network
nec expresscluster_x This vulnerability allows remote attackers to disclose sensitive information on affected installations of NEC ExpressCluster 4.1. Authentication is not required to exploit this vulnerability. The spe… - CVE-2020-17408 2024-11-21 14:08 2020-09-11 Show GitHub Exploit DB Packet Storm
209137 5.4 MEDIUM
Network
fabbricadigitale multiux A post-authenticated stored XSS was found in MultiUx v.3.1.12.0 via the /multiux/SaveMailbox LastName field. CWE-79
Cross-site Scripting
CVE-2020-17458 2024-11-21 14:08 2020-09-2 Show GitHub Exploit DB Packet Storm
209138 8.8 HIGH
Adjacent
senstar symphony This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Senstar Symphony 7.3.2.2. Authentication is not required to exploit this vulnerability. The… - CVE-2020-17405 2024-11-21 14:08 2020-09-2 Show GitHub Exploit DB Packet Storm
209139 6.1 MEDIUM
Network
forgerock identity_manager Dashboards and progressiveProfileForms in ForgeRock Identity Manager before 7.0.0 are vulnerable to stored XSS. The vulnerability affects versions 6.5.0.4, 6.0.0.6. CWE-79
Cross-site Scripting
CVE-2020-17465 2024-11-21 14:08 2020-09-1 Show GitHub Exploit DB Packet Storm
209140 5.4 MEDIUM
Network
halo halo Halo blog 1.2.0 allows users to submit comments on blog posts via /api/content/posts/comments. The javascript code supplied by the attacker will then execute in the victim user's browser. CWE-79
Cross-site Scripting
CVE-2020-19007 2024-11-21 14:08 2020-08-26 Show GitHub Exploit DB Packet Storm