Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 24, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
229531 4.3 警告 softbiz - Softbiz Photo Gallery におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-3511 2012-12-20 18:52 2008-08-7 Show GitHub Exploit DB Packet Storm
229532 5 警告 wogan may - LiteNews における認証を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-3508 2012-12-20 18:52 2008-08-7 Show GitHub Exploit DB Packet Storm
229533 7.5 危険 wogan may - LiteNews の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3507 2012-12-20 18:52 2008-08-7 Show GitHub Exploit DB Packet Storm
229534 7.5 危険 polypager - PolyPager における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3506 2012-12-20 18:52 2008-08-6 Show GitHub Exploit DB Packet Storm
229535 4.3 警告 polypager - PolyPager におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-3505 2012-12-20 18:52 2008-08-6 Show GitHub Exploit DB Packet Storm
229536 5 警告 webgui - Plain Black WebGUI の RSSFromParent における重要な情報を取得される脆弱性 CWE-287
不適切な認証
CVE-2008-3503 2012-12-20 18:52 2008-06-20 Show GitHub Exploit DB Packet Storm
229537 5 警告 RealVNC - RealVNC Windows Client の vncviewer.exe におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2008-3493 2012-12-20 18:52 2008-08-6 Show GitHub Exploit DB Packet Storm
229538 7.5 危険 scripts24 - Scripts24 iPost および iTGP の go.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3491 2012-12-20 18:52 2008-08-6 Show GitHub Exploit DB Packet Storm
229539 7.5 危険 phpx - PHPX の includes/functions.inc.php の checkCookie 関数における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3489 2012-12-20 18:52 2008-08-6 Show GitHub Exploit DB Packet Storm
229540 7.5 危険 phpauctions - PHPAuction GPL の profile.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3487 2012-12-20 18:52 2008-08-6 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 24, 2026, 4:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
214711 4.8 MEDIUM
Network
chadhaajay phpkb The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/add-field.php by adding a question mark (… CWE-79
Cross-site Scripting
CVE-2020-10393 2024-11-21 13:55 2020-03-12 Show GitHub Exploit DB Packet Storm
214712 4.8 MEDIUM
Network
chadhaajay phpkb The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/add-category.php by adding a question mar… CWE-79
Cross-site Scripting
CVE-2020-10392 2024-11-21 13:55 2020-03-12 Show GitHub Exploit DB Packet Storm
214713 4.8 MEDIUM
Network
chadhaajay phpkb The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/add-article.php by adding a question mark… CWE-79
Cross-site Scripting
CVE-2020-10391 2024-11-21 13:55 2020-03-12 Show GitHub Exploit DB Packet Storm
214714 7.2 HIGH
Network
chadhaajay phpkb OS Command Injection in export.php (vulnerable function called from include/functions-article.php) in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code Execution by savin… CWE-78
OS Command 
CVE-2020-10390 2024-11-21 13:55 2020-03-12 Show GitHub Exploit DB Packet Storm
214715 7.2 HIGH
Network
chadhaajay phpkb admin/save-settings.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code Execution by injecting PHP code into any POST parameter when saving global settings. CWE-94
Code Injection
CVE-2020-10389 2024-11-21 13:55 2020-03-12 Show GitHub Exploit DB Packet Storm
214716 5.4 MEDIUM
Network
chadhaajay phpkb The way the Referer header in article.php is handled in Chadha PHPKB Standard Multi-Language 9 allows attackers to execute Stored (Blind) XSS (injecting arbitrary web script or HTML) in admin/report-… CWE-79
Cross-site Scripting
CVE-2020-10388 2024-11-21 13:55 2020-03-12 Show GitHub Exploit DB Packet Storm
214717 4.9 MEDIUM
Network
chadhaajay phpkb Path Traversal in admin/download.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to download files from the server using a dot-dot-slash sequence (../) via the GET parameter fil… CWE-22
Path Traversal
CVE-2020-10387 2024-11-21 13:55 2020-03-12 Show GitHub Exploit DB Packet Storm
214718 7.2 HIGH
Network
chadhaajay phpkb admin/imagepaster/image-upload.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code Execution by uploading a .php file in the admin/js/ directory. CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2020-10386 2024-11-21 13:55 2020-03-12 Show GitHub Exploit DB Packet Storm
214719 9.8 CRITICAL
Network
technicolor tc7337net_firmware Technicolor TC7337NET 08.89.17.23.03 devices allow remote attackers to discover passwords by sniffing the network for an "Authorization: Basic" HTTP header. CWE-319
Cleartext Transmission of Sensitive Information
CVE-2020-10376 2024-11-21 13:55 2020-03-11 Show GitHub Exploit DB Packet Storm
214720 5.4 MEDIUM
Network
ramp altimeter Ramp AltitudeCDN Altimeter before 2.4.0 allows authenticated Stored XSS via the vdms/ipmapping.jsp location field to the dms/rest/services/datastore/createOrEditValueForKey URI. CWE-79
Cross-site Scripting
CVE-2020-10372 2024-11-21 13:55 2020-03-11 Show GitHub Exploit DB Packet Storm