Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 26, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
229941 7.5 危険 y-blog - yBlog における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2669 2012-12-20 18:52 2008-06-11 Show GitHub Exploit DB Packet Storm
229942 4.3 警告 y-blog - yBlog におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-2668 2012-12-20 18:52 2008-06-11 Show GitHub Exploit DB Packet Storm
229943 7.5 危険 smeweb - SMEWeb の catalog.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2652 2012-12-20 18:52 2008-06-10 Show GitHub Exploit DB Packet Storm
229944 4.3 警告 smeweb - SMEWeb における任意の Web スクリプトまたは HTML を挿入される脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-2644 2012-12-20 18:52 2008-06-10 Show GitHub Exploit DB Packet Storm
229945 7.5 危険 theflashblog - FlashBlog の php/leer_comentarios.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2572 2012-12-20 18:52 2008-06-6 Show GitHub Exploit DB Packet Storm
229946 4.3 警告 samtodo - SamTodo の dsp_main.php などにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-2563 2012-12-20 18:52 2008-06-6 Show GitHub Exploit DB Packet Storm
229947 6.5 警告 powerphlogger - PowerPhlogger の edCss.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2562 2012-12-20 18:52 2008-06-6 Show GitHub Exploit DB Packet Storm
229948 4.3 警告 slashcode.com - Slash におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-2553 2012-12-20 18:52 2008-06-5 Show GitHub Exploit DB Packet Storm
229949 9.3 危険 Skype Technologies S.A. - Skype における警告ダイアログを回避される脆弱性 CWE-20
不適切な入力確認
CVE-2008-2545 2012-12-20 18:52 2008-06-6 Show GitHub Exploit DB Packet Storm
229950 7.2 危険 サン・マイクロシステムズ - Sun Solaris 上の Sun Cluster における任意の削除されたファイルデータが読まれる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-2539 2012-12-20 18:52 2008-03-30 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 26, 2026, 4:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
214401 7.8 HIGH
Local
osisoft pi_buffer_subsystem
pi_api
pi_connector
pi_connector_relay
pi_interface_configuration_utility
pi_integrator
pi_data_collection_manager
pi_data_archive
pi_to_ocs
In OSIsoft PI System multiple products and versions, a local attacker can exploit incorrect permissions set by affected PI System software. This exploitation can result in unauthorized information di… CWE-276
Incorrect Default Permissions 
CVE-2020-10606 2024-11-21 13:55 2020-07-25 Show GitHub Exploit DB Packet Storm
214402 7.5 HIGH
Network
grundfos cim_500_firmware Grundfos CIM 500 before v06.16.00 responds to unauthenticated requests for password storage files. CWE-306
Missing Authentication for Critical Function
CVE-2020-10605 2024-11-21 13:55 2020-07-18 Show GitHub Exploit DB Packet Storm
214403 9.8 CRITICAL
Network
abb robotware IRC5 exposes an ftp server (port 21). Upon attempting to gain access you are challenged with a request of username and password, however you can input whatever you like. As long as the field isn't em… CWE-287
Improper Authentication
CVE-2020-10288 2024-11-21 13:55 2020-07-16 Show GitHub Exploit DB Packet Storm
214404 8.8 HIGH
Adjacent
ufactory xarm_5_lite_firmware
xarm_6_firmware
xarm_7_firmware
the main user account has restricted privileges but is in the sudoers group and there is not any mechanism in place to prevent sudo su or sudo -i to be run gaining unrestricted access to sensible fil… CWE-269
 Improper Privilege Management
CVE-2020-10286 2024-11-21 13:55 2020-07-16 Show GitHub Exploit DB Packet Storm
214405 9.8 CRITICAL
Network
ufactory xarm_5_lite_firmware The authentication implementation on the xArm controller has very low entropy, making it vulnerable to a brute-force attack. There is no mechanism in place to mitigate or lockout automated attempts t… CWE-331
 Insufficient Entropy
CVE-2020-10285 2024-11-21 13:55 2020-07-16 Show GitHub Exploit DB Packet Storm
214406 9.8 CRITICAL
Network
abb irb140_firmware
irc5_firmware
The IRC5 family with UAS service enabled comes by default with credentials that can be found on publicly available manuals. ABB considers this a well documented functionality that helps customer set … CWE-522
 Insufficiently Protected Credentials
CVE-2020-10287 2024-11-21 13:55 2020-07-16 Show GitHub Exploit DB Packet Storm
214407 9.1 CRITICAL
Network
ufactory xarm_studio No authentication is required to control the robot inside the network, moreso the latest available user manual shows an option that lets the user to add a password to the robot but as in xarm_studio … NVD-CWE-noinfo
CVE-2020-10284 2024-11-21 13:55 2020-07-16 Show GitHub Exploit DB Packet Storm
214408 7.5 HIGH
Network
samba
fedoraproject
opensuse
debian
samba
fedora
leap
debian_linux
A flaw was found in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4 in the way it processed NetBios over TCP/IP. This flaw allows a remote attacker could to cause the Samba server… CWE-400
 Uncontrolled Resource Consumption
CVE-2020-10745 2024-11-21 13:55 2020-07-7 Show GitHub Exploit DB Packet Storm
214409 6.5 MEDIUM
Network
samba
redhat
opensuse
fedoraproject
debian
samba
storage
leap
fedora
debian_linux
A NULL pointer dereference, or possible use-after-free flaw was found in Samba AD LDAP server in versions before 4.10.17, before 4.11.11 and before 4.12.4. Although some versions of Samba shipped wit… CWE-476
CWE-416
 NULL Pointer Dereference
 Use After Free
CVE-2020-10730 2024-11-21 13:55 2020-07-7 Show GitHub Exploit DB Packet Storm
214410 9.8 CRITICAL
Network
dronecode micro_air_vehicle_link The Micro Air Vehicle Link (MAVLink) protocol presents no authentication mechanism on its version 1.0 (nor authorization) whichs leads to a variety of attacks including identity spoofing, unauthorize… CWE-306
Missing Authentication for Critical Function
CVE-2020-10282 2024-11-21 13:55 2020-07-4 Show GitHub Exploit DB Packet Storm