Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 1, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
229791 5.1 警告 tinycms - TinyCMS 内の ZZ_Templater モジュール内におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-4740 2012-12-20 18:52 2008-10-27 Show GitHub Exploit DB Packet Storm
229792 6.8 警告 plugspace - PlugSpace の index.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-4739 2012-12-20 18:52 2008-10-24 Show GitHub Exploit DB Packet Storm
229793 7.5 危険 tufat - MyCard の gallery.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-4738 2012-12-20 18:52 2008-10-24 Show GitHub Exploit DB Packet Storm
229794 7.5 危険 pressography - WordPress 用の WP Comment Remix プラグインにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2008-4734 2012-12-20 18:52 2008-10-24 Show GitHub Exploit DB Packet Storm
229795 4.3 警告 pressography - WordPress 用の WP Comment Remix プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-4733 2012-12-20 18:52 2008-10-24 Show GitHub Exploit DB Packet Storm
229796 7.5 危険 pressography - WordPress 用の WP Comment Remix プラグインにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-4732 2012-12-20 18:52 2008-10-24 Show GitHub Exploit DB Packet Storm
229797 4.3 警告 CJ Niemira - phpMyID の MyID.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-4730 2012-12-20 18:52 2008-10-24 Show GitHub Exploit DB Packet Storm
229798 4.3 警告 sungard - SunGard Banner Student のコンタクトアップデートページにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-4727 2012-12-20 18:52 2008-10-23 Show GitHub Exploit DB Packet Storm
229799 7.5 危険 X7 Group - X7 Chat の help/mini.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-4718 2012-12-20 18:52 2008-10-23 Show GitHub Exploit DB Packet Storm
229800 7.5 危険 zeeways - ZEELYRICS の bannerclick.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-4717 2012-12-20 18:52 2008-10-23 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 1, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
208771 7.5 HIGH
Network
mediawiki
fedoraproject
mediawiki
fedora
An issue was discovered in the OATHAuth extension in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. For Wikis using OATHAuth on a farm/cluster (such as via CentralAuth), rate limit… CWE-307
mproper Restriction of Excessive Authentication Attempts
CVE-2020-25827 2024-11-21 14:18 2020-09-28 Show GitHub Exploit DB Packet Storm
208772 6.1 MEDIUM
Network
mediawiki
fedoraproject
mediawiki
fedora
An issue was discovered in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. The non-jqueryMsg version of mw.message().parse() doesn't escape HTML. This affects both message contents … CWE-79
Cross-site Scripting
CVE-2020-25828 2024-11-21 14:18 2020-09-28 Show GitHub Exploit DB Packet Storm
208773 6.1 MEDIUM
Network
mediawiki
fedoraproject
mediawiki
fedora
An issue was discovered in MediaWiki 1.32.x through 1.34.x before 1.34.4. LogEventList::getFiltersDesc is insecurely using message text to build options names for an HTML multi-select field. The rele… CWE-79
Cross-site Scripting
CVE-2020-25815 2024-11-21 14:18 2020-09-28 Show GitHub Exploit DB Packet Storm
208774 6.1 MEDIUM
Network
mediawiki
fedoraproject
mediawiki
fedora
In MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4, XSS related to jQuery can occur. The attacker creates a message with [javascript:payload xss] and turns it into a jQuery object wi… CWE-79
Cross-site Scripting
CVE-2020-25814 2024-11-21 14:18 2020-09-28 Show GitHub Exploit DB Packet Storm
208775 5.3 MEDIUM
Network
mediawiki
fedoraproject
mediawiki
fedora
In MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4, Special:UserRights exposes the existence of hidden users. NVD-CWE-noinfo
CVE-2020-25813 2024-11-21 14:18 2020-09-28 Show GitHub Exploit DB Packet Storm
208776 6.1 MEDIUM
Network
mediawiki
fedoraproject
mediawiki
fedora
An issue was discovered in MediaWiki 1.34.x before 1.34.4. On Special:Contributions, the NS filter uses unescaped messages as keys in the option key for an HTMLForm specifier. This is vulnerable to a… CWE-79
Cross-site Scripting
CVE-2020-25812 2024-11-21 14:18 2020-09-28 Show GitHub Exploit DB Packet Storm
208777 5.3 MEDIUM
Local
qemu
debian
qemu
debian_linux
hw/usb/hcd-ohci.c in QEMU 5.0.0 has an infinite loop when a TD list has a loop. CWE-835
 Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2020-25625 2024-11-21 14:18 2020-09-25 Show GitHub Exploit DB Packet Storm
208778 9.8 CRITICAL
Network
rubetek rv-3406_firmware
rv-3409_firmware
rv-3411_firmware
The Telnet service of Rubetek cameras RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339) could allow an remote attacker to take full control of the device with a high-privileged acc… CWE-798
 Use of Hard-coded Credentials
CVE-2020-25749 2024-11-21 14:18 2020-09-25 Show GitHub Exploit DB Packet Storm
208779 8.1 HIGH
Network
rubetek rv-3406_firmware
rv-3409_firmware
rv-3411_firmware
A Cleartext Transmission issue was discovered on Rubetek RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339). Someone in the middle can intercept and modify the video data from the c… CWE-319
Cleartext Transmission of Sensitive Information
CVE-2020-25748 2024-11-21 14:18 2020-09-25 Show GitHub Exploit DB Packet Storm
208780 9.4 CRITICAL
Network
rubetek rv-3406_firmware
rv-3409_firmware
rv-3411_firmware
The Telnet service of Rubetek RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339) can allow a remote attacker to gain access to RTSP and ONFIV services without authentication. Thus, … CWE-306
Missing Authentication for Critical Function
CVE-2020-25747 2024-11-21 14:18 2020-09-25 Show GitHub Exploit DB Packet Storm