Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 27, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
229771 3.5 注意 tuxplanet - BilboBlog におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-3301 2012-12-20 18:52 2008-07-25 Show GitHub Exploit DB Packet Storm
229772 6 警告 socialengine - SE における任意の PHP コードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2008-3298 2012-12-20 18:52 2008-07-25 Show GitHub Exploit DB Packet Storm
229773 7.5 危険 socialengine - SE における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3297 2012-12-20 18:52 2008-07-25 Show GitHub Exploit DB Packet Storm
229774 5 警告 sierra - SWAT におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2008-3286 2012-12-20 18:52 2008-07-24 Show GitHub Exploit DB Packet Storm
229775 5 警告 レッドハット - Red Hat Enterprise IPA および FreeIPA のデフォルト設定における Kerberos マスターキーを取得される脆弱性 CWE-200
情報漏えい
CVE-2008-3274 2012-12-20 18:52 2008-09-10 Show GitHub Exploit DB Packet Storm
229776 5 警告 winsoftmagic - WinSoftMagic WRPC Lite におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2008-3269 2012-12-20 18:52 2008-07-24 Show GitHub Exploit DB Packet Storm
229777 7.5 危険 softacid - SoftAcid HRS Multi の picture_pic_bv.asp における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3266 2012-12-20 18:52 2008-07-24 Show GitHub Exploit DB Packet Storm
229778 7.5 危険 Zoph - Zoph における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3258 2012-12-20 18:52 2008-07-22 Show GitHub Exploit DB Packet Storm
229779 7.5 危険 siteframe - Siteframe CMS の folder.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3256 2012-12-20 18:52 2008-07-22 Show GitHub Exploit DB Packet Storm
229780 6.8 警告 precoc - preCMS の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3254 2012-12-20 18:52 2008-07-22 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 28, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
195921 9.8 CRITICAL
Network
weidmueller uc20-wl2000-ac_firmware
uc20-wl2000-iot_firmware
iot-gw30_firmware
iot-gw30-4g-eu_firmware
In Weidmüller u-controls and IoT-Gateways in versions up to 1.12.1 a network port intended only for device-internal usage is accidentally accessible via external network interfaces. By exploiting thi… NVD-CWE-Other
CVE-2021-20999 2024-11-21 14:47 2021-05-13 Show GitHub Exploit DB Packet Storm
195922 9.8 CRITICAL
Network
wago 0852-0303_firmware
0852-1305_firmware
0852-1505_firmware
0852-1305\/000-001_firmware
0852-1505\/000-001_firmware
In multiple managed switches by WAGO in different versions without authorization and with specially crafted packets it is possible to create users. CWE-306
Missing Authentication for Critical Function
CVE-2021-20998 2024-11-21 14:47 2021-05-13 Show GitHub Exploit DB Packet Storm
195923 7.5 HIGH
Network
wago 0852-0303_firmware
0852-1305_firmware
0852-1505_firmware
0852-1305\/000-001_firmware
0852-1505\/000-001_firmware
In multiple managed switches by WAGO in different versions it is possible to read out the password hashes of all Web-based Management users. CWE-522
 Insufficiently Protected Credentials
CVE-2021-20997 2024-11-21 14:47 2021-05-13 Show GitHub Exploit DB Packet Storm
195924 5.3 MEDIUM
Network
wago 0852-0303_firmware
0852-1305_firmware
0852-1505_firmware
0852-1305\/000-001_firmware
0852-1505\/000-001_firmware
In multiple managed switches by WAGO in different versions special crafted requests can lead to cookies being transferred to third parties. CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2021-20996 2024-11-21 14:47 2021-05-13 Show GitHub Exploit DB Packet Storm
195925 7.5 HIGH
Network
wago 0852-0303_firmware
0852-1305_firmware
0852-1505_firmware
0852-1305\/000-001_firmware
0852-1505\/000-001_firmware
In multiple managed switches by WAGO in different versions the webserver cookies of the web based UI contain user credentials. CWE-312
 Cleartext Storage of Sensitive Information
CVE-2021-20995 2024-11-21 14:47 2021-05-13 Show GitHub Exploit DB Packet Storm
195926 6.1 MEDIUM
Network
wago 0852-0303_firmware
0852-1305_firmware
0852-1505_firmware
0852-1305\/000-001_firmware
0852-1505\/000-001_firmware
In multiple managed switches by WAGO in different versions an attacker may trick a legitimate user to click a link to inject possible malicious code into the Web-Based Management. CWE-79
Cross-site Scripting
CVE-2021-20994 2024-11-21 14:47 2021-05-13 Show GitHub Exploit DB Packet Storm
195927 5.3 MEDIUM
Network
wago 0852-0303_firmware
0852-1305_firmware
0852-1505_firmware
0852-1305\/000-001_firmware
0852-1505\/000-001_firmware
In multiple managed switches by WAGO in different versions the activated directory listing provides an attacker with the index of the resources located inside the directory. CWE-200
Information Exposure
CVE-2021-20993 2024-11-21 14:47 2021-05-13 Show GitHub Exploit DB Packet Storm
195928 7.5 HIGH
Network
hilscher
pepperl-fuchs
rcx_rtos
ice1-16di-g60l-v1d_firmware
ice1-16dio-g60l-c1-v1d_firmware
ice1-16dio-g60l-v1d_firmware
ice1-8di8do-g60l-c1-v1d_firmware
ice1-8di8do-g60l-v1d_firmware
ice1-8iol-g30l-v1d_f…
In Hilscher rcX RTOS versions prios to V2.1.14.1 the actual UDP packet length is not verified against the length indicated by the packet. This may lead to a denial of service of the affected device. CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2021-20988 2024-11-21 14:47 2021-05-13 Show GitHub Exploit DB Packet Storm
195929 6.1 MEDIUM
Network
ec-cube ec-cube Cross-site scripting vulnerability in EC-CUBE 4.0.0 to 4.0.5 allows a remote attacker to inject a specially crafted script in the specific input field of the EC web site which is created using EC-CUB… CWE-79
Cross-site Scripting
CVE-2021-20717 2024-11-21 14:47 2021-05-10 Show GitHub Exploit DB Packet Storm
195930 5.2 MEDIUM
Local
octobercms october October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. A bypass of CVE-2020-26231 (fixed in 1.0.470/471 and 1.1.1) was discovered that has the same impact as CVE… NVD-CWE-Other
CVE-2021-21264 2024-11-21 14:47 2021-05-4 Show GitHub Exploit DB Packet Storm