Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 4, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
229941 4.3 警告 scripts4you - Werner Hilversum Clean CMS の full_txt.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-5290 2012-12-20 18:52 2008-12-1 Show GitHub Exploit DB Packet Storm
229942 7.5 危険 scripts4you - Werner Hilversum Clean CMS の full_txt.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-5289 2012-12-20 18:52 2008-12-1 Show GitHub Exploit DB Packet Storm
229943 6.8 警告 scripts4you - Werner Hilversum FAQ Manager の include/header.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2008-5288 2012-12-20 18:52 2008-12-1 Show GitHub Exploit DB Packet Storm
229944 7.5 危険 scripts4you - Werner Hilversum FAQ Manager の catagorie.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-5287 2012-12-20 18:52 2008-12-1 Show GitHub Exploit DB Packet Storm
229945 10 危険 W3C - W3C Amaya Web Browser におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-5282 2012-12-20 18:52 2008-11-28 Show GitHub Exploit DB Packet Storm
229946 10 危険 south river technologies - Titan FTP Server におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-5281 2012-12-20 18:52 2008-11-28 Show GitHub Exploit DB Packet Storm
229947 5 警告 zilab - ZIM Server の Local ZIM Server におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2008-5280 2012-12-20 18:52 2008-11-28 Show GitHub Exploit DB Packet Storm
229948 10 危険 zilab - ZIP Server の Local ZIM Server における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2008-5279 2012-12-20 18:52 2008-11-28 Show GitHub Exploit DB Packet Storm
229949 4.3 警告 PowerDNS - PowerDNS におけるサービス運用妨害 (DoS) の脆弱性 CWE-16
環境設定
CVE-2008-5277 2012-12-20 18:52 2008-11-18 Show GitHub Exploit DB Packet Storm
229950 5 警告 toddwoolums - Todd Woolums ASP News Management におけるニュース項目を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-5274 2012-12-20 18:52 2008-11-28 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 4, 2026, 4:17 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
224961 6.8 MEDIUM
Physics
tk-star q90_junior_gps_horloge_firmware An issue was discovered on TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. Any SIM card used with the device cannot have a PIN configured. If a PIN is configured, the device simply produces a "… NVD-CWE-noinfo
CVE-2019-20473 2024-11-21 13:38 2021-02-2 Show GitHub Exploit DB Packet Storm
224962 7.8 HIGH
Local
tk-star q90_junior_gps_horloge_firmware An issue was discovered on TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. When using the device at initial setup, a default password is used (123456) for administrative purposes. There is no p… CWE-798
 Use of Hard-coded Credentials
CVE-2019-20471 2024-11-21 13:38 2021-02-2 Show GitHub Exploit DB Packet Storm
224963 7.5 HIGH
Network
tk-star q90_junior_gps_horloge_firmware An issue was discovered on TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. It performs actions based on certain SMS commands. This can be used to set up a voice communication channel from the w… CWE-1188
 Insecure Default Initialization of Resource
CVE-2019-20470 2024-11-21 13:38 2021-02-2 Show GitHub Exploit DB Packet Storm
224964 9.8 CRITICAL
Network
tk-star q90_junior_gps_horloge_firmware An issue was discovered in SeTracker2 for TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. It has unnecessary permissions such as READ_EXTERNAL_STORAGE, WRITE_EXTERNAL_STORAGE, and READ_CONTACTS. CWE-276
Incorrect Default Permissions 
CVE-2019-20468 2024-11-21 13:38 2021-02-2 Show GitHub Exploit DB Packet Storm
224965 8.1 HIGH
Network
vikisolutions vera An issue was discovered in Viki Vera 4.9.1.26180. A user without access to a project could download or upload project files by opening the Project URL directly in the browser after logging in. CWE-425
 Direct Request ('Forced Browsing')
CVE-2019-20484 2024-11-21 13:38 2021-01-6 Show GitHub Exploit DB Packet Storm
224966 5.4 MEDIUM
Network
vikisolutions vera An issue was discovered in Viki Vera 4.9.1.26180. An attacker could set a user's last name to an XSS Payload, and read another user's cookie and use that to login to the application. CWE-79
Cross-site Scripting
CVE-2019-20483 2024-11-21 13:38 2021-01-6 Show GitHub Exploit DB Packet Storm
224967 6.1 MEDIUM
Network
treasuryxpress treasuryxpress An XSS issue was discovered in TreasuryXpress 19191105. Due to the lack of filtering and sanitization of user input, malicious JavaScript can be executed throughout the application. A malicious paylo… CWE-79
Cross-site Scripting
CVE-2019-20152 2024-11-21 13:38 2020-08-20 Show GitHub Exploit DB Packet Storm
224968 6.1 MEDIUM
Network
treasuryxpress treasuryxpress An XSS issue was discovered in TreasuryXpress 19191105. Due to the lack of filtering and sanitization of user input, malicious JavaScript can be executed by the application's administrator(s). A mali… CWE-79
Cross-site Scripting
CVE-2019-20151 2024-11-21 13:38 2020-08-20 Show GitHub Exploit DB Packet Storm
224969 6.5 MEDIUM
Network
treasuryxpress treasuryxpress In TreasuryXpress 19191105, a logged-in user can discover saved credentials, even though the UI hides them. Using functionality within the application and a malicious host, it is possible to force th… NVD-CWE-noinfo
CVE-2019-20150 2024-11-21 13:38 2020-08-20 Show GitHub Exploit DB Packet Storm
224970 7.8 HIGH
Local
abbyy finereader ABBYY network license server in ABBYY FineReader 15 before Release 4 (aka 15.0.112.2130) allows escalation of privileges by local users via manipulations involving files and using symbolic links. CWE-59
Link Following
CVE-2019-20383 2024-11-21 13:38 2020-08-14 Show GitHub Exploit DB Packet Storm