Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 27, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
229971 10 危険 plusphp - plusPHP Short URL Multi-User Script の plus.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2008-2480 2012-12-20 18:52 2008-05-28 Show GitHub Exploit DB Packet Storm
229972 7.5 危険 vBulletin Solutions, Inc. - vBulletin Gold の faq.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2460 2012-12-20 18:52 2008-05-27 Show GitHub Exploit DB Packet Storm
229973 7.5 危険 phpclassifiedsscript - PHP Classifieds Script における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2453 2012-12-20 18:52 2008-05-27 Show GitHub Exploit DB Packet Storm
229974 4.3 警告 TYPO3 Association - TYPO3 用の Questionaire エクステンションにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-2452 2012-12-20 18:52 2008-05-27 Show GitHub Exploit DB Packet Storm
229975 7.5 危険 TYPO3 Association - TYPO3 用の Statistics エクステンションにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2451 2012-12-20 18:52 2008-05-27 Show GitHub Exploit DB Packet Storm
229976 4.3 警告 TYPO3 Association - TYPO3 用の Statistics エクステンションにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-2450 2012-12-20 18:52 2008-05-27 Show GitHub Exploit DB Packet Storm
229977 7.5 危険 wgcc - WGCC における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2446 2012-12-20 18:52 2008-05-27 Show GitHub Exploit DB Packet Storm
229978 4.3 警告 wgcc - WGCC の profile.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-2445 2012-12-20 18:52 2008-05-27 Show GitHub Exploit DB Packet Storm
229979 7.5 危険 therealestatescript - The Real Estate Script の dpage.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2443 2012-12-20 18:52 2008-05-27 Show GitHub Exploit DB Packet Storm
229980 5 警告 トレンドマイクロ - Trend Micro OfficeScan および Worry-Free Business Security クライアントの OfficeScanNT Listener サービスにおけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-2439 2012-12-20 18:52 2008-09-26 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 27, 2026, 4:52 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
196141 9.8 CRITICAL
Network
sonicwall sma_210_firmware
sma_410_firmware
sma_500v_firmware
sra_4600_firmware
sra_1600_firmware
sra_va_firmware
Improper neutralization of a SQL Command leading to SQL Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products, specifically the SRA appliances running all 8.x firmware and… CWE-89
SQL Injection
CVE-2021-20028 2024-11-21 14:45 2021-08-5 Show GitHub Exploit DB Packet Storm
196142 7.5 HIGH
Network
tecnick tcexam When installed following the default/recommended settings, TCExam <= 14.8.1 allowed unauthenticated users to access the /cache/backup/ directory, which included sensitive database backup files. CWE-425
 Direct Request ('Forced Browsing')
CVE-2021-20114 2024-11-21 14:45 2021-07-30 Show GitHub Exploit DB Packet Storm
196143 5.3 MEDIUM
Network
tecnick tcexam An exposure of sensitive information vulnerability exists in TCExam <= 14.8.1. If a password reset request was made for an email address that was not registered with a user then we would be presented… CWE-203
 Information Exposure Through Discrepancy
CVE-2021-20113 2024-11-21 14:45 2021-07-30 Show GitHub Exploit DB Packet Storm
196144 5.4 MEDIUM
Network
tecnick tcexam A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1. Valid files uploaded via tce_select_mediafile.php with a filename beggining with a period will be rendered as text/html. An att… CWE-79
Cross-site Scripting
CVE-2021-20112 2024-11-21 14:45 2021-07-30 Show GitHub Exploit DB Packet Storm
196145 5.4 MEDIUM
Network
tecnick tcexam A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1. Valid files uploaded via tce_filemanager.php with a filename beggining with a period will be rendered as text/html. An attacker… CWE-79
Cross-site Scripting
CVE-2021-20111 2024-11-21 14:45 2021-07-30 Show GitHub Exploit DB Packet Storm
196146 6.5 MEDIUM
Local
tenable nessus Nessus Agent versions 8.2.5 and earlier were found to contain a privilege escalation vulnerability which could allow a Nessus administrator user to upload a specially crafted file that could lead to … NVD-CWE-noinfo
CVE-2021-20106 2024-11-21 14:45 2021-07-22 Show GitHub Exploit DB Packet Storm
196147 9.8 CRITICAL
Network
zohocorp manageengine_assetexplorer Due to Manage Engine Asset Explorer Agent 1.0.34 not validating HTTPS certificates, an attacker on the network can statically configure their IP address to match the Asset Explorer's Server IP addres… CWE-190
 Integer Overflow or Wraparound
CVE-2021-20110 2024-11-21 14:45 2021-07-20 Show GitHub Exploit DB Packet Storm
196148 7.5 HIGH
Network
zohocorp manageengine_assetexplorer Due to the Asset Explorer agent not validating HTTPS certificates, an attacker on the network can statically configure their IP address to match the Asset Explorer's Server IP address. This will allo… CWE-787
 Out-of-bounds Write
CVE-2021-20109 2024-11-21 14:45 2021-07-20 Show GitHub Exploit DB Packet Storm
196149 7.5 HIGH
Network
zohocorp manageengine_assetexplorer Manage Engine Asset Explorer Agent 1.0.34 listens on port 9000 for incoming commands over HTTPS from Manage Engine Server. The HTTPS certificates are not verified which allows any arbitrary user on t… CWE-401
 Missing Release of Memory after Effective Lifetime
CVE-2021-20108 2024-11-21 14:45 2021-07-20 Show GitHub Exploit DB Packet Storm
196150 7.5 HIGH
Network
qualcomm apq8053_firmware
aqt1000_firmware
ar8031_firmware
ar8035_firmware
csra6620_firmware
csra6640_firmware
csrb31024_firmware
msm8953_firmware
qca6175a_firmware
qca6310_firmware…
Possible out of bound read due to lack of length check of FT sub-elements in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdrag… CWE-20
CWE-125
 Improper Input Validation 
Out-of-bounds Read
CVE-2021-1970 2024-11-21 14:45 2021-07-13 Show GitHub Exploit DB Packet Storm