Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 29, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
229551 7.5 危険 v3chat - V3 Chat Live Support の admin/index.php における認証を回避される脆弱性 CWE-287
不適切な認証
CVE-2008-5783 2012-12-20 19:10 2008-12-31 Show GitHub Exploit DB Packet Storm
229552 7.5 危険 zeeways - ZeeMatri の bannerclick.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-5782 2012-12-20 19:10 2008-12-31 Show GitHub Exploit DB Packet Storm
229553 7.5 危険 phpweather - PHP Weather の test.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-5771 2012-12-20 19:10 2008-12-30 Show GitHub Exploit DB Packet Storm
229554 4.3 警告 phpweather - PHP Weather の config/make_config.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-5770 2012-12-20 19:10 2008-12-30 Show GitHub Exploit DB Packet Storm
229555 7.5 危険 sirium - XOOPS 用の AM Events モジュールにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-5768 2012-12-20 19:10 2008-12-30 Show GitHub Exploit DB Packet Storm
229556 6.8 警告 phparanoid - PHParanoid におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2008-5758 2012-12-20 19:10 2008-12-30 Show GitHub Exploit DB Packet Storm
229557 3.5 注意 Textpattern - Textpattern の textarea/index.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-5757 2012-12-20 19:10 2008-12-30 Show GitHub Exploit DB Packet Storm
229558 4.3 警告 WordPress.org - WordPress 用の Page Flip Image Gallery プラグインにおけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-5752 2012-12-20 19:10 2008-12-30 Show GitHub Exploit DB Packet Storm
229559 7.5 危険 Pligg - Pligg CMS の evb/check_url.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-5739 2012-12-20 19:10 2008-12-26 Show GitHub Exploit DB Packet Storm
229560 7.5 危険 PHP-Fusion - PHP-Fusion 用の Team Impact TI Blog System モジュールにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-5733 2012-12-20 19:10 2008-12-26 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 29, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
214971 6.5 MEDIUM
Network
intelliants subrion admin/blocks.php in Subrion CMS through 4.2.1 allows PHP Object Injection (with resultant file deletion) via serialized data in the subpages value within a block to blocks/edit. CWE-502
 Deserialization of Untrusted Data
CVE-2020-12469 2024-11-21 13:59 2020-04-30 Show GitHub Exploit DB Packet Storm
214972 7.8 HIGH
Local
intelliants subrion Subrion CMS 4.2.1 allows CSV injection via a phrase value within a language. This is related to phrases/add/ and languages/download/. NVD-CWE-Other
CVE-2020-12468 2024-11-21 13:59 2020-04-30 Show GitHub Exploit DB Packet Storm
214973 6.5 MEDIUM
Network
intelliants subrion Subrion CMS 4.2.1 allows session fixation via an alphanumeric value in a session cookie. CWE-384
 Session Fixation
CVE-2020-12467 2024-11-21 13:59 2020-04-30 Show GitHub Exploit DB Packet Storm
214974 7.2 HIGH
Network
mono monox MonoX through 5.1.40.5152 allows admins to execute arbitrary programs by reconfiguring the Converter Executable setting from ffmpeg.exe to a different program. NVD-CWE-noinfo
CVE-2020-12473 2024-11-21 13:59 2020-04-30 Show GitHub Exploit DB Packet Storm
214975 5.4 MEDIUM
Network
mono monox MonoX through 5.1.40.5152 allows stored XSS via User Status, Blog Comments, or Blog Description. CWE-79
Cross-site Scripting
CVE-2020-12472 2024-11-21 13:59 2020-04-30 Show GitHub Exploit DB Packet Storm
214976 6.7 MEDIUM
Local
linux
netapp
linux_kernel
cloud_backup
steelstore_cloud_integrated_storage
hci_storage_nodes
aff_a700s
active_iq_unified_manager
hci_compute_node
solidfire_\&_hci_storage_node
solidfir…
usb_sg_cancel in drivers/usb/core/message.c in the Linux kernel before 5.6.8 has a use-after-free because a transfer occurs without a reference, aka CID-056ad39ee925. CWE-416
 Use After Free
CVE-2020-12464 2024-11-21 13:59 2020-04-30 Show GitHub Exploit DB Packet Storm
214977 6.7 MEDIUM
Local
linux
netapp
linux_kernel
cloud_backup
steelstore_cloud_integrated_storage
solidfire_\&_hci_management_node
active_iq_unified_manager
hci_compute_node
solidfire_baseboard_management_controll…
An array overflow was discovered in mt76_add_fragment in drivers/net/wireless/mediatek/mt76/dma.c in the Linux kernel before 5.5.10, aka CID-b102f0c522cf. An oversized packet with too many rx fragmen… CWE-120
Classic Buffer Overflow
CVE-2020-12465 2024-11-21 13:59 2020-04-30 Show GitHub Exploit DB Packet Storm
214978 6.1 MEDIUM
Network
ninjaforms ninja_forms The ninja-forms plugin before 3.4.24.2 for WordPress allows CSRF with resultant XSS. CWE-352
 Origin Validation Error
CVE-2020-12462 2024-11-21 13:59 2020-04-30 Show GitHub Exploit DB Packet Storm
214979 8.8 HIGH
Network
php-fusion php-fusion PHP-Fusion 9.03.50 allows SQL Injection because maincore.php has an insufficient protection mechanism. An attacker can develop a crafted payload that can be inserted into the sort_order GET parameter… CWE-89
SQL Injection
CVE-2020-12461 2024-11-21 13:59 2020-04-30 Show GitHub Exploit DB Packet Storm
214980 5.3 MEDIUM
Network
gitlab gitlab GitLab 10.8 through 12.9 has a vulnerability that allows someone to mirror a repository even if the feature is not activated. CWE-276
Incorrect Default Permissions 
CVE-2020-12277 2024-11-21 13:59 2020-04-30 Show GitHub Exploit DB Packet Storm