Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 26, 2026, 4:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
229911 4.3 警告 xigla - Xigla Absolute Image Gallery XE におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-2766 2012-12-20 18:52 2008-06-18 Show GitHub Exploit DB Packet Storm
229912 7.5 危険 xigla - Xigla Absolute Image Gallery XE の gallery.asp における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2765 2012-12-20 18:52 2008-06-18 Show GitHub Exploit DB Packet Storm
229913 3.5 注意 xigla - Xigla Absolute Live Support XE の admin/search.asp におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-2764 2012-12-20 18:52 2008-06-18 Show GitHub Exploit DB Packet Storm
229914 6.5 警告 xigla - Xigla Absolute Live Support XE の search.asp における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2763 2012-12-20 18:52 2008-06-18 Show GitHub Exploit DB Packet Storm
229915 6.5 警告 xigla - Xigla Absolute Form Processor XE の search.asp における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2762 2012-12-20 18:52 2008-06-18 Show GitHub Exploit DB Packet Storm
229916 3.5 注意 xigla - Xigla Absolute Banner Manager XE におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-2761 2012-12-20 18:52 2008-06-18 Show GitHub Exploit DB Packet Storm
229917 6.5 警告 xigla - Xigla Absolute Banner Manager XE の searchbanners.asp における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2760 2012-12-20 18:52 2008-06-18 Show GitHub Exploit DB Packet Storm
229918 4.3 警告 xigla - Xigla Absolute Form Processor XE におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-2759 2012-12-20 18:52 2008-06-18 Show GitHub Exploit DB Packet Storm
229919 3.5 注意 xigla - Xigla Absolute News Manager XE におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-2758 2012-12-20 18:52 2008-06-18 Show GitHub Exploit DB Packet Storm
229920 6.5 警告 xigla - Xigla Absolute News Manager XE の search.asp における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2757 2012-12-20 18:52 2008-06-18 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 26, 2026, 4:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
222331 9.8 CRITICAL
Network
nec sv8100_firmware
sv9100_firmware
sl1100_firmware
sl2100_firmware
Aspire-derived NEC PBXes, including the SV8100, SV9100, SL1100 and SL2100 with software releases 7.0 or higher contain the possibility if incorrectly configured to allow a blank username and password… CWE-287
Improper Authentication
CVE-2019-20027 2024-11-21 13:37 2020-07-30 Show GitHub Exploit DB Packet Storm
222332 7.5 HIGH
Network
nec sv9100_firmware The WebPro interface in NEC SV9100 software releases 7.0 or higher allows unauthenticated remote attackers to reset all existing usernames and passwords to default values via a crafted request. NVD-CWE-noinfo
CVE-2019-20026 2024-11-21 13:37 2020-07-30 Show GitHub Exploit DB Packet Storm
222333 9.8 CRITICAL
Network
nec sv9100_firmware Certain builds of NEC SV9100 software could allow an unauthenticated, remote attacker to log into a device running an affected release with a hardcoded username and password, aka a Static Credential … CWE-798
 Use of Hard-coded Credentials
CVE-2019-20025 2024-11-21 13:37 2020-07-30 Show GitHub Exploit DB Packet Storm
222334 7.8 HIGH
Local
solarwinds webhelpdesk Formula Injection exists in the export feature in SolarWinds WebHelpDesk 12.7.1 via a value (provided by a low-privileged user in the Subject field of a help request form) that is mishandled in a Tic… CWE-1236
 Improper Neutralization of Formula Elements in a CSV File
CVE-2019-20002 2024-11-21 13:37 2020-04-28 Show GitHub Exploit DB Packet Storm
222335 3.7 LOW
Network
cisco webex_business_suite_39 Cisco Webex Business Suite before 39.1.0 contains a vulnerability that could allow an unauthenticated, remote attacker to affect the integrity of the application. The vulnerability is due to improper… CWE-345
 Insufficient Verification of Data Authenticity
CVE-2019-1866 2024-11-21 13:37 2020-04-14 Show GitHub Exploit DB Packet Storm
222336 7.8 HIGH
Local
zsh
fedoraproject
debian
apple
zsh
fedora
debian_linux
mac_os_x
iphone_os
watchos
tvos
ipados
In Zsh before 5.8, attackers able to execute commands can regain privileges dropped by the --no-PRIVILEGED option. Zsh fails to overwrite the saved uid, so the original privileges can be restored by … CWE-273
 Improper Check for Dropped Privileges
CVE-2019-20044 2024-11-21 13:37 2020-02-24 Show GitHub Exploit DB Packet Storm
222337 8.4 HIGH
Local
cisco ios_xe A vulnerability in Cisco IOS XE SD-WAN Software could allow an unauthenticated, local attacker to gain unauthorized access to an affected device. The vulnerability is due to the existence of default … CWE-1188
 Insecure Default Initialization of Resource
CVE-2019-1950 2024-11-21 13:37 2020-02-20 Show GitHub Exploit DB Packet Storm
222338 9.8 CRITICAL
Network
s3india husky_rtu_6049-e70_firmware The Synergy Systems & Solutions PLC & RTU system has a vulnerability in HUSKY RTU 6049-E70 firmware versions 5.0 and prior. The affected product does not require adequate authentication, which may al… CWE-287
Improper Authentication
CVE-2019-20046 2024-11-21 13:37 2020-02-15 Show GitHub Exploit DB Packet Storm
222339 7.5 HIGH
Network
s3india husky_rtu_6049-e70_firmware The Synergy Systems & Solutions PLC & RTU system has a vulnerability in HUSKY RTU 6049-E70 firmware versions 5.0 and prior. Specially crafted malicious packets could cause disconnection of active aut… CWE-20
 Improper Input Validation 
CVE-2019-20045 2024-11-21 13:37 2020-02-15 Show GitHub Exploit DB Packet Storm
222340 9.8 CRITICAL
Network
mfscripts yetishare MFScripts YetiShare v3.5.2 through v4.5.4 might allow an attacker to reset a password by using a leaked hash (the hash never expires until used). CWE-287
Improper Authentication
CVE-2019-20062 2024-11-21 13:37 2020-02-10 Show GitHub Exploit DB Packet Storm