Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 27, 2026, noon

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
229941 7.5 危険 y-blog - yBlog における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2669 2012-12-20 18:52 2008-06-11 Show GitHub Exploit DB Packet Storm
229942 4.3 警告 y-blog - yBlog におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-2668 2012-12-20 18:52 2008-06-11 Show GitHub Exploit DB Packet Storm
229943 7.5 危険 smeweb - SMEWeb の catalog.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2652 2012-12-20 18:52 2008-06-10 Show GitHub Exploit DB Packet Storm
229944 4.3 警告 smeweb - SMEWeb における任意の Web スクリプトまたは HTML を挿入される脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-2644 2012-12-20 18:52 2008-06-10 Show GitHub Exploit DB Packet Storm
229945 7.5 危険 theflashblog - FlashBlog の php/leer_comentarios.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2572 2012-12-20 18:52 2008-06-6 Show GitHub Exploit DB Packet Storm
229946 4.3 警告 samtodo - SamTodo の dsp_main.php などにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-2563 2012-12-20 18:52 2008-06-6 Show GitHub Exploit DB Packet Storm
229947 6.5 警告 powerphlogger - PowerPhlogger の edCss.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2562 2012-12-20 18:52 2008-06-6 Show GitHub Exploit DB Packet Storm
229948 4.3 警告 slashcode.com - Slash におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-2553 2012-12-20 18:52 2008-06-5 Show GitHub Exploit DB Packet Storm
229949 9.3 危険 Skype Technologies S.A. - Skype における警告ダイアログを回避される脆弱性 CWE-20
不適切な入力確認
CVE-2008-2545 2012-12-20 18:52 2008-06-6 Show GitHub Exploit DB Packet Storm
229950 7.2 危険 サン・マイクロシステムズ - Sun Solaris 上の Sun Cluster における任意の削除されたファイルデータが読まれる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-2539 2012-12-20 18:52 2008-03-30 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 27, 2026, 4:52 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
209161 9.8 CRITICAL
Network
pyyaml
fedoraproject
opensuse
oracle
pyyaml
fedora
leap
communications_cloud_native_core_network_function_cloud_native_environment
A vulnerability was discovered in the PyYAML library in versions before 5.3.1, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method … - CVE-2020-1747 2024-11-21 14:11 2020-03-25 Show GitHub Exploit DB Packet Storm
209162 5.6 MEDIUM
Network
redhat keycloak A flaw was found in keycloak before version 9.0.1. When configuring an Conditional OTP Authentication Flow as a post login flow of an IDP, the failure login events for OTP are not being sent to the b… CWE-755
 Improper Handling of Exceptional Conditions
CVE-2020-1744 2024-11-21 14:11 2020-03-24 Show GitHub Exploit DB Packet Storm
209163 9.8 CRITICAL
Network
apache
debian
traffic_server
debian_linux
There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and Transfer-Encoding and Content length headers. Upgrade to versions 7.1.… CWE-444
HTTP Request Smuggling
CVE-2020-1944 2024-11-21 14:11 2020-03-24 Show GitHub Exploit DB Packet Storm
209164 5.5 MEDIUM
Local
apache
oracle
debian
canonical
tika
flexcube_private_banking
debian_linux
business_process_management_suite
ubuntu_linux
communications_messaging_server
A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23. CWE-835
 Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2020-1951 2024-11-21 14:11 2020-03-23 Show GitHub Exploit DB Packet Storm
209165 5.5 MEDIUM
Local
apache
oracle
debian
canonical
tika
flexcube_private_banking
debian_linux
business_process_management_suite
ubuntu_linux
communications_messaging_server
A carefully crafted or corrupt PSD file can cause excessive memory usage in Apache Tika's PSDParser in versions 1.0-1.23. CWE-400
 Uncontrolled Resource Consumption
CVE-2020-1950 2024-11-21 14:11 2020-03-23 Show GitHub Exploit DB Packet Storm
209166 5.5 MEDIUM
Local
huawei oxfords-an00a_firmware Huawei smartphone OxfordS-AN00A with versions earlier than 10.0.1.152D(C735E152R3P3),versions earlier than 10.0.1.160(C00E160R4P1) have an improper authentication vulnerability. Authentication to tar… CWE-287
Improper Authentication
CVE-2020-1878 2024-11-21 14:11 2020-03-21 Show GitHub Exploit DB Packet Storm
209167 3.9 LOW
Physics
huawei hege-560_firmware
hege-570_firmware
osca-550_firmware
osca-550a_firmware
osca-550ax_firmware
osca-550x_firmware
There is an improper integrity checking vulnerability on some huawei products. The software of the affected product has an improper integrity check which may allow an attacker with high privilege to … CWE-354
 Improper Validation of Integrity Check Value
CVE-2020-1879 2024-11-21 14:11 2020-03-21 Show GitHub Exploit DB Packet Storm
209168 8.1 HIGH
Network
huawei secospace_antiddos8000_firmware Some Huawei products have a security vulnerability due to improper authentication. A remote attacker needs to obtain some information and forge the peer device to send specific packets to the affecte… CWE-287
Improper Authentication
CVE-2020-1864 2024-11-21 14:11 2020-03-21 Show GitHub Exploit DB Packet Storm
209169 3.3 LOW
Local
huawei campusinsight
manageone
There is a double free vulnerability in some Huawei products. A local attacker with low privilege may perform some operations to exploit the vulnerability. Due to doubly freeing memory, successful ex… CWE-415
 Double Free
CVE-2020-1862 2024-11-21 14:11 2020-03-21 Show GitHub Exploit DB Packet Storm
209170 6.6 MEDIUM
Physics
huawei mate_20_firmware
mate_30_pro_firmware
There is an improper authorization vulnerability in several smartphones. The software incorrectly performs an authorization to certain user, successful exploit could allow a low privilege user to do … CWE-863
 Incorrect Authorization
CVE-2020-1796 2024-11-21 14:11 2020-03-21 Show GitHub Exploit DB Packet Storm