Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 21, 2026, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
229931 9.3 危険 rising antivirus international - Rising Antivirus Online Scanner の Web Scan Object ActiveX コントロール における任意のコードを強制的にダウンロードされる脆弱性 CWE-DesignError
CVE-2008-1116 2012-12-20 18:34 2008-03-3 Show GitHub Exploit DB Packet Storm
229932 7.8 危険 Vocera - Cisco Unified Wireless IP Phone 7921 におけるハッシュされたパスワードを盗まれる脆弱性 CWE-200
情報漏えい
CVE-2008-1113 2012-12-20 18:34 2008-03-3 Show GitHub Exploit DB Packet Storm
229933 6.8 警告 Xine - xine-lib の xineplug_dmx_asf.so プラグイン におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-1110 2012-12-20 18:34 2008-02-29 Show GitHub Exploit DB Packet Storm
229934 6.8 警告 quantum game library - Quantum Game Library における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2008-1069 2012-12-20 18:34 2008-02-28 Show GitHub Exploit DB Packet Storm
229935 6.8 警告 portail web php - Portail Web Php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2008-1068 2012-12-20 18:34 2008-02-28 Show GitHub Exploit DB Packet Storm
229936 6.8 警告 phpqladmin - phpQLAdmin における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2008-1067 2012-12-20 18:34 2008-02-28 Show GitHub Exploit DB Packet Storm
229937 7.5 危険 Smarty - S9Y などの製品で使用される Smarty における任意の PHP 関数を呼び出される脆弱性 CWE-20
不適切な入力確認
CVE-2008-1066 2012-12-20 18:34 2008-02-28 Show GitHub Exploit DB Packet Storm
229938 4.3 警告 WordPress.org - WordPress 用の Sniplets プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-1061 2012-12-20 18:34 2008-02-28 Show GitHub Exploit DB Packet Storm
229939 7.5 危険 WordPress.org - WordPress 用の Sniplets プラグインにおける任意の PHP コードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2008-1060 2012-12-20 18:34 2008-02-28 Show GitHub Exploit DB Packet Storm
229940 7.5 危険 WordPress.org - WordPress 用の Sniplets プラグインにおける PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2008-1059 2012-12-20 18:34 2008-02-28 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 21, 2026, 4:10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
209531 9.8 CRITICAL
Network
zkteco zkbiosecurity_server
facedepot_7b_firmware
A token-reuse vulnerability in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.0_20190723 allows an attacker to create arbitrary new users, elevate users to administrators, delete users, and… CWE-613
 Insufficient Session Expiration
CVE-2020-17474 2024-11-21 14:08 2020-08-15 Show GitHub Exploit DB Packet Storm
209532 5.9 MEDIUM
Network
zkteco zkbiosecurity_server
facedepot_7b_firmware
Lack of mutual authentication in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.0_20190723 allows an attacker to obtain a long-lasting token by impersonating the server. CWE-613
 Insufficient Session Expiration
CVE-2020-17473 2024-11-21 14:08 2020-08-15 Show GitHub Exploit DB Packet Storm
209533 7.8 HIGH
Local
cmsmadesimple cms_made_simple CMS Made Simple 2.2.14 allows Authenticated Arbitrary File Upload because the File Manager does not block .ptar files, a related issue to CVE-2017-16798. CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2020-17462 2024-11-21 14:08 2020-08-15 Show GitHub Exploit DB Packet Storm
209534 6.5 MEDIUM
Network
wireshark
fedoraproject
opensuse
oracle
wireshark
fedora
leap
zfs_storage_appliance_kit
In Wireshark 3.2.0 to 3.2.5, the Kafka protocol dissector could crash. This was addressed in epan/dissectors/packet-kafka.c by avoiding a double free during LZ4 decompression. CWE-415
 Double Free
CVE-2020-17498 2024-11-21 14:08 2020-08-14 Show GitHub Exploit DB Packet Storm
209535 5.5 MEDIUM
Local
artifex
debian
canonical
ghostscript
debian_linux
ubuntu_linux
A buffer overflow vulnerability in GetNumSameData() in contrib/lips4/gdevlips.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. Thi… CWE-787
 Out-of-bounds Write
CVE-2020-17538 2024-11-21 14:08 2020-08-13 Show GitHub Exploit DB Packet Storm
209536 6.1 MEDIUM
Network
php-fusion php-fusion PHP-Fusion 9.03 allows XSS on the preview page. CWE-79
Cross-site Scripting
CVE-2020-17450 2024-11-21 14:08 2020-08-13 Show GitHub Exploit DB Packet Storm
209537 5.4 MEDIUM
Network
php-fusion php-fusion PHP-Fusion 9.03 allows XSS via the error_log file. CWE-79
Cross-site Scripting
CVE-2020-17449 2024-11-21 14:08 2020-08-13 Show GitHub Exploit DB Packet Storm
209538 5.3 MEDIUM
Network
qt
debian
fedoraproject
qt
debian_linux
fedora
An issue was discovered in Qt through 5.12.9, and 5.13.x through 5.15.x before 5.15.1. read_xbm_body in gui/image/qxbmhandler.cpp has a buffer over-read. CWE-125
Out-of-bounds Read
CVE-2020-17507 2024-11-21 14:08 2020-08-13 Show GitHub Exploit DB Packet Storm
209539 9.8 CRITICAL
Network
articatech web_proxy Artica Web Proxy 4.30.00000000 allows remote attacker to bypass privilege detection and gain web backend administrator privileges through SQL injection of the apikey parameter in fw.login.php. CWE-89
SQL Injection
CVE-2020-17506 2024-11-21 14:08 2020-08-13 Show GitHub Exploit DB Packet Storm
209540 8.8 HIGH
Network
articatech web_proxy Artica Web Proxy 4.30.000000 allows an authenticated remote attacker to inject commands via the service-cmds parameter in cyrus.php. These commands are executed with root privileges via service_cmds_… CWE-78
OS Command 
CVE-2020-17505 2024-11-21 14:08 2020-08-13 Show GitHub Exploit DB Packet Storm