Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 7, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
229821 7.5 危険 socialsitegenerator - Social Site Generator における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6419 2012-12-20 19:10 2009-03-6 Show GitHub Exploit DB Packet Storm
229822 7.5 危険 torrenttrader - TorrentTrader の scrape.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6418 2012-12-20 19:10 2009-03-6 Show GitHub Exploit DB Packet Storm
229823 10 危険 Youngzsoft - YoungZSoft CCProxy におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-6415 2012-12-20 19:10 2009-03-6 Show GitHub Exploit DB Packet Storm
229824 7.5 危険 vignette - Vignette Content Management における管理者権限を取得される脆弱性 CWE-noinfo
情報不足
CVE-2008-6412 2012-12-20 19:10 2009-03-6 Show GitHub Exploit DB Packet Storm
229825 4.3 警告 refbase - refbase におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-6400 2012-12-20 19:10 2009-03-5 Show GitHub Exploit DB Packet Storm
229826 10 危険 psi-im - PSI Jabber クライアントにおける整数オーバーフローの脆弱性 CWE-189
数値処理の問題
CVE-2008-6393 2012-12-20 19:10 2009-03-3 Show GitHub Exploit DB Packet Storm
229827 4.3 警告 w3matter - W3matter RevSense の index.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-6385 2012-12-20 19:10 2009-03-2 Show GitHub Exploit DB Packet Storm
229828 7.5 危険 phpbb-seo - Multi SEO phpBB の include/global.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2008-6377 2012-12-20 19:10 2009-03-2 Show GitHub Exploit DB Packet Storm
229829 8.5 危険 socialgroupie - Social Groupie の Photos/create_album.php における任意のコードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2008-6367 2012-12-20 19:10 2009-03-2 Show GitHub Exploit DB Packet Storm
229830 4.3 警告 phpf1 - Max's Guestbook の index.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-6359 2012-12-20 19:10 2009-03-2 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 7, 2026, 4:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
202321 8.8 HIGH
Adjacent
lenovo thinkpad_stack_wireless_router_firmware An authentication bypass vulnerability was reported in Lenovo ThinkPad Stack Wireless Router firmware version 1.1.3.4 that could allow escalation of privilege. CWE-287
Improper Authentication
CVE-2020-8350 2024-11-21 14:38 2020-10-15 Show GitHub Exploit DB Packet Storm
202322 7.8 HIGH
Local
lenovo hardware_scan A DLL search path vulnerability was reported in the Lenovo HardwareScan Plugin for the Lenovo Vantage hardware scan feature prior to version 1.0.46.11 that could allow escalation of privilege. CWE-427
 Uncontrolled Search Path Element
CVE-2020-8345 2024-11-21 14:38 2020-10-15 Show GitHub Exploit DB Packet Storm
202323 7.8 HIGH
Local
lenovo diagnostics A DLL search path vulnerability was reported in Lenovo Diagnostics prior to version 4.35.4 that could allow a user with local access to execute code on the system. CWE-426
 Untrusted Search Path
CVE-2020-8338 2024-11-21 14:38 2020-10-15 Show GitHub Exploit DB Packet Storm
202324 9.8 CRITICAL
Network
lenovo cloud_networking_operating_system An internal security review has identified an unauthenticated remote code execution vulnerability in Cloud Networking Operating System (CNOS)’ optional REST API management interface. This interface i… CWE-94
Code Injection
CVE-2020-8349 2024-11-21 14:38 2020-10-15 Show GitHub Exploit DB Packet Storm
202325 6.4 MEDIUM
Local
lenovo bladecenter_hs23_firmware
bladecenter_hs23e_firmware
compute_node-x440_firmware
flex_system_x220_firmware
flex_system_x240_firmware
flex_system_x440_firmware
nextscale_nx360_m4_firm…
A potential vulnerability in the SMI callback function used in the legacy BIOS mode USB drivers in some legacy Lenovo and IBM System x servers may allow arbitrary code execution. Servers operating in… CWE-367
 Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2020-8332 2024-11-21 14:38 2020-10-15 Show GitHub Exploit DB Packet Storm
202326 4.3 MEDIUM
Network
nextcloud deck Missing access control in Nextcloud Deck 1.0.4 caused an insecure direct object reference allowing an attacker to view all attachments. CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2020-8235 2024-11-21 14:38 2020-10-5 Show GitHub Exploit DB Packet Storm
202327 5.3 MEDIUM
Network
nextcloud
opensuse
preferred_providers
leap
backports_sle
A missing rate limit in the Preferred Providers app 1.7.0 allowed an attacker to set the password an uncontrolled amount of times. CWE-307
mproper Restriction of Excessive Authentication Attempts
CVE-2020-8228 2024-11-21 14:38 2020-10-5 Show GitHub Exploit DB Packet Storm
202328 6.5 MEDIUM
Network
nextcloud
fedoraproject
nextcloud_server
fedora
A logic error in Nextcloud Server 19.0.0 caused a privilege escalation allowing malicious users to reshare with higher permissions than they got assigned themselves. CWE-269
 Improper Privilege Management
CVE-2020-8223 2024-11-21 14:38 2020-10-5 Show GitHub Exploit DB Packet Storm
202329 8.0 HIGH
Network
nextcloud deck Improper access control in Nextcloud Deck 0.8.0 allowed an attacker to reshare boards shared with them with more permissions than they had themselves. CWE-281
 Improper Preservation of Permissions
CVE-2020-8182 2024-11-21 14:38 2020-10-5 Show GitHub Exploit DB Packet Storm
202330 7.5 HIGH
Network
bitdefender engines A vulnerability has been discovered in the ceva_emu.cvd module that results from a lack of proper validation of user-supplied data, which can result in a pointer that is fetched from uninitialized me… CWE-824
 Access of Uninitialized Pointer
CVE-2020-8110 2024-11-21 14:38 2020-10-2 Show GitHub Exploit DB Packet Storm