Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 6, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
229451 5.1 警告 The Tor Project - Tor における送信元および送信先間の通信を特定される脆弱性 CWE-Other
その他
CVE-2009-0654 2012-12-20 19:10 2009-02-20 Show GitHub Exploit DB Packet Storm
229452 10 危険 tptest - TPTEST の GetStatsFromLine 関数におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-0650 2012-12-20 19:10 2009-02-20 Show GitHub Exploit DB Packet Storm
229453 5 警告 swannsecurity - Swann DVR4-SecuraNet の HTTP インターフェースにおける昇格したアクセス権を取得される脆弱性 CWE-255
証明書・パスワード管理
CVE-2009-0644 2012-12-20 19:10 2009-02-18 Show GitHub Exploit DB Packet Storm
229454 5 警告 swannsecurity - Swann DVR4-SecuraNet の管理 Web サーバにおけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2009-0640 2012-12-20 19:10 2009-02-20 Show GitHub Exploit DB Packet Storm
229455 7.5 危険 phpyabs - phpyabs の moduli/libri/index.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2009-0639 2012-12-20 19:10 2009-02-18 Show GitHub Exploit DB Packet Storm
229456 7.5 危険 wikkitikkitavi - WikkiTikkiTavi の upload.php における任意のコードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2009-0602 2012-12-20 19:10 2009-02-16 Show GitHub Exploit DB Packet Storm
229457 7.5 危険 phpmesfilms - PhpMesFilms の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-0598 2012-12-20 19:10 2009-02-16 Show GitHub Exploit DB Packet Storm
229458 6.8 警告 w3bcms - w3b>cms の admin/index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-0597 2012-12-20 19:10 2009-02-16 Show GitHub Exploit DB Packet Storm
229459 6.8 警告 phpskelsite - phpSkelSite の skysilver/login.tpl.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2009-0596 2012-12-20 19:10 2009-02-16 Show GitHub Exploit DB Packet Storm
229460 5.1 警告 phpskelsite - phpSkelSite の skysilver/login.tpl.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2009-0595 2012-12-20 19:10 2009-02-16 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 6, 2026, 4:18 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
202331 7.5 HIGH
Network
rubyonrails
debian
opensuse
rails
debian_linux
leap
backports_sle
A deserialization of untrusted data vulnerability exists in rails < 5.2.4.3, rails < 6.0.3.1 which can allow an attacker to supply information can be inadvertently leaked fromStrong Parameters. CWE-502
 Deserialization of Untrusted Data
CVE-2020-8164 2024-11-21 14:38 2020-06-20 Show GitHub Exploit DB Packet Storm
202332 7.5 HIGH
Network
rubyonrails
debian
rails
debian_linux
A client side enforcement of server side security vulnerability exists in rails < 5.2.4.2 and rails < 6.0.3.1 ActiveStorage's S3 adapter that allows the Content-Length of a direct file upload to be m… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2020-8162 2024-11-21 14:38 2020-06-20 Show GitHub Exploit DB Packet Storm
202333 5.7 MEDIUM
Network
openmicroscopy omero.web OMERO.web before 5.6.3 optionally allows sensitive data elements (e.g., a session key) to be passed as URL query parameters. If an attacker tricks a user into clicking a malicious link in OMERO.web, … CWE-200
Information Exposure
CVE-2020-7932 2024-11-21 14:38 2020-06-18 Show GitHub Exploit DB Packet Storm
202334 6.5 MEDIUM
Network
open-xchange open-xchange_appsuite OX App Suite through 7.10.3 allows XXE attacks. CWE-611
XXE
CVE-2020-8541 2024-11-21 14:38 2020-06-16 Show GitHub Exploit DB Packet Storm
202335 6.7 MEDIUM
Local
synaptics smart_audio_uwp An unquoted search path vulnerability was reported in versions prior to 1.0.83.0 of the Synaptics Smart Audio UWP app associated with the DCHU audio drivers on Lenovo platforms that could allow an ad… CWE-428
 Unquoted Search Path or Element
CVE-2020-8337 2024-11-21 14:38 2020-06-10 Show GitHub Exploit DB Packet Storm
202336 6.8 MEDIUM
Physics
lenovo thinkpad_e14_firmware
thinkpad_e15_firmware
thinkpad_r14_firmware
thinkpad_s3_gen_2_firmware
thinkpad_e490s_firmware
thinkpad_s3_firmware
thinkpad_e490_firmware
thinkpad_e590_fir…
Lenovo implemented Intel CSME Anti-rollback ARB protections on some ThinkPad models to prevent roll back of CSME Firmware in flash. NVD-CWE-noinfo
CVE-2020-8336 2024-11-21 14:38 2020-06-10 Show GitHub Exploit DB Packet Storm
202337 6.8 MEDIUM
Physics
lenovo thinkpad_t495s_firmware
thinkpad_x395_firmware
thinkpad_t495_firmware
thinkpad_a485_firmware
thinkpad_a285_firmware
thinkpad_a475_firmware
thinkpad_a275_firmware
The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T495s, X395, T495, A485, A285, A475, A275 which may allow for unauthorized access. CWE-754
 Improper Check for Unusual or Exceptional Conditions
CVE-2020-8334 2024-11-21 14:38 2020-06-10 Show GitHub Exploit DB Packet Storm
202338 6.7 MEDIUM
Local
lenovo 330-14ast_firmware
330-15ast_firmware
330-17ast_firmware
340c-15api_firmware
340c-15ast_firmware
720s_touch-15ikb_firmware
720s-15ikb_firmware
730s-13iwl_firmware
c640-iml_fir…
A potential vulnerability in the SMI callback function used in the Legacy SD driver in some Lenovo ThinkPad, ThinkStation, and Lenovo Notebook models may allow arbitrary code execution. NVD-CWE-noinfo
CVE-2020-8323 2024-11-21 14:38 2020-06-10 Show GitHub Exploit DB Packet Storm
202339 6.7 MEDIUM
Local
lenovo 330-14ast_firmware
330-15ast_firmware
330-17ast_firmware
340c-15api_firmware
340c-15ast_firmware
720s_touch-15ikb_firmware
720s-15ikb_firmware
730s-13iwl_firmware
c640-iml_fir…
A potential vulnerability in the SMI callback function used in the Legacy USB driver in some Lenovo Notebook and ThinkStation models may allow arbitrary code execution. NVD-CWE-noinfo
CVE-2020-8322 2024-11-21 14:38 2020-06-10 Show GitHub Exploit DB Packet Storm
202340 6.7 MEDIUM
Local
lenovo 130-14ast_firmware
130-14ikb_firmware
130-15ast_firmware
130-15ikb_firmware
320c-15ikb_firmware
330-14igm_firmware
330-14ikb_firmware
330-14ikbr_firmware
330-15arr_firmware
A potential vulnerability in the SMI callback function used in the System Lock Preinstallation driver in some Lenovo Notebook and ThinkStation models may allow arbitrary code execution. NVD-CWE-noinfo
CVE-2020-8321 2024-11-21 14:38 2020-06-10 Show GitHub Exploit DB Packet Storm