Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 19, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
229731 10 危険 tutos - TUTOS における任意のシェルコマンドを実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-0148 2012-12-20 18:34 2008-01-8 Show GitHub Exploit DB Packet Storm
229732 6.8 警告 smallnuke - SmallNuke の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0147 2012-12-20 18:34 2008-01-8 Show GitHub Exploit DB Packet Storm
229733 7.5 危険 phprisk - NetRisk の index.php における PHP リモートファイルインクルージョンの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0144 2012-12-20 18:34 2008-01-8 Show GitHub Exploit DB Packet Storm
229734 7.5 危険 spacial audio solutions - samPHPweb の common/db.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2008-0143 2012-12-20 18:34 2008-01-8 Show GitHub Exploit DB Packet Storm
229735 9.3 危険 ZyXEL - ZyXEL P-330W ルータの Web 管理インターフェースにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2007-6730 2012-12-20 18:34 2009-09-10 Show GitHub Exploit DB Packet Storm
229736 4.3 警告 ZyXEL - ZyXEL P-330W ルータの Web 管理インターフェースにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-6729 2012-12-20 18:34 2009-09-10 Show GitHub Exploit DB Packet Storm
229737 6.8 警告 webportal - WebPortal CMS における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0142 2012-12-20 18:34 2008-01-8 Show GitHub Exploit DB Packet Storm
229738 7.5 危険 webportal - WebPortal CMS の actions.php における任意のアカウントへのアクセス権を取得される脆弱性 CWE-255
証明書・パスワード管理
CVE-2008-0141 2012-12-20 18:34 2008-01-8 Show GitHub Exploit DB Packet Storm
229739 6.4 警告 uebimiau - Uebimiau Webmail の error.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-0140 2012-12-20 18:34 2008-01-8 Show GitHub Exploit DB Packet Storm
229740 7.5 危険 snetworks - SNETWORKS PHP CLASSIFIEDS の config.inc.php における PHP リモートファイルインクルージョンの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0137 2012-12-20 18:34 2008-01-8 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 19, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
200921 7.0 HIGH
Local
ibm mq_for_hpe_nonstop IBM MQ on HPE NonStop 8.0.4 and 8.1.0 is vulnerable to a privilege escalation attack when running in restricted mode. IBM X-Force ID: 178427. NVD-CWE-noinfo
CVE-2020-4352 2024-11-21 14:32 2020-05-29 Show GitHub Exploit DB Packet Storm
200922 5.4 MEDIUM
Network
ibm planning_analytics_local IBM Planning Analytics Local 2.0.0 through 2.0.9 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended fun… CWE-79
Cross-site Scripting
CVE-2020-4306 2024-11-21 14:32 2020-05-29 Show GitHub Exploit DB Packet Storm
200923 2.7 LOW
Network
ibm security_identity_governance_and_intelligence IBM Security Identity Governance and Intelligence 5.2.6 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This informat… CWE-209
Information Exposure Through an Error Message
CVE-2020-4248 2024-11-21 14:32 2020-05-29 Show GitHub Exploit DB Packet Storm
200924 5.4 MEDIUM
Network
ibm jazz_reporting_service IBM Jazz Reporting Service 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended f… CWE-79
Cross-site Scripting
CVE-2020-4419 2024-11-21 14:32 2020-05-29 Show GitHub Exploit DB Packet Storm
200925 6.5 MEDIUM
Network
ibm security_identity_governance_and_intelligence IBM Security Identity Governance and Intelligence 5.2.6 could disclose highly sensitive information to other authenticated users on the sytem due to incorrect authorization. IBM X-Force ID: 175485. CWE-863
 Incorrect Authorization
CVE-2020-4249 2024-11-21 14:32 2020-05-29 Show GitHub Exploit DB Packet Storm
200926 7.1 HIGH
Network
ibm security_identity_governance_and_intelligence IBM Security Identity Governance and Intelligence 5.2.6 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to … CWE-611
XXE
CVE-2020-4246 2024-11-21 14:32 2020-05-29 Show GitHub Exploit DB Packet Storm
200927 7.5 HIGH
Network
ibm security_identity_governance_and_intelligence IBM Security Identity Governance and Intelligence 5.2.6 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-For… CWE-521
Weak Password Requirements 
CVE-2020-4245 2024-11-21 14:32 2020-05-29 Show GitHub Exploit DB Packet Storm
200928 5.3 MEDIUM
Network
ibm security_identity_governance_and_intelligence IBM Security Identity Governance and Intelligence 5.2.6 could allow an unauthorized user to obtain sensitive information through user enumeration. IBM X-Force ID: 175422. NVD-CWE-noinfo
CVE-2020-4244 2024-11-21 14:32 2020-05-29 Show GitHub Exploit DB Packet Storm
200929 5.3 MEDIUM
Network
ibm security_identity_governance_and_intelligence IBM Security Identity Governance and Intelligence 5.2.6 could allow a remote attacker to obtain sensitive information, caused by the failure to set the secure flag for the session cookie in SSL mode.… CWE-311
Missing Encryption of Sensitive Data
CVE-2020-4233 2024-11-21 14:32 2020-05-29 Show GitHub Exploit DB Packet Storm
200930 7.5 HIGH
Network
ibm security_identity_governance_and_intelligence IBM Security Identity Governance and Intelligence 5.2.6 could allow an attacker to enumerate usernames to find valid login credentials which could be used to attempt further attacks against the syste… CWE-307
mproper Restriction of Excessive Authentication Attempts
CVE-2020-4232 2024-11-21 14:32 2020-05-29 Show GitHub Exploit DB Packet Storm