Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 8, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
230021 7.5 危険 thehockeystop - TheHockeyStop HockeySTATS Online における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-7085 2012-12-20 19:10 2009-08-26 Show GitHub Exploit DB Packet Storm
230022 7.5 危険 revou - ReVou Micro Blogging Twitter クローンにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-7083 2012-12-20 19:10 2009-08-25 Show GitHub Exploit DB Packet Storm
230023 4.3 警告 Simple Machines
phpraider
- Simple Machines phpRaider の不特定のコンポーネントにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-7035 2012-12-20 19:10 2009-08-24 Show GitHub Exploit DB Packet Storm
230024 7.5 危険 tigran abrahamyan - PHPEcho CMS の kernel/smarty/Smarty.class.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2008-7034 2012-12-20 19:10 2009-08-24 Show GitHub Exploit DB Packet Storm
230025 7.5 危険 site2nite - Site2Nite Real Estate Web における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-7030 2012-12-20 19:10 2009-08-24 Show GitHub Exploit DB Packet Storm
230026 10 危険 skalinks - Skalfa Software SkaLinks Exchange Script における管理者を追加される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-7010 2012-12-20 19:10 2009-08-19 Show GitHub Exploit DB Packet Storm
230027 7.5 危険 phpversion - Free PHP VX Guestbook における管理者アクセス権を取得される脆弱性 CWE-287
不適切な認証
CVE-2008-7007 2012-12-20 19:10 2009-08-19 Show GitHub Exploit DB Packet Storm
230028 5 警告 phpversion - Free PHP VX Guestbook におけるデータベースのバックアップをダウンロードされる脆弱性 CWE-287
不適切な認証
CVE-2008-7006 2012-12-20 19:10 2009-08-19 Show GitHub Exploit DB Packet Storm
230029 7.5 危険 the-rat-cms - The Rat CMS の login.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-7003 2012-12-20 19:10 2009-08-19 Show GitHub Exploit DB Packet Storm
230030 7.5 危険 phpauction - PHPAuction の index.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2008-7000 2012-12-20 19:10 2009-08-19 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 8, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
208641 6.1 MEDIUM
Network
coremail_xt_project coremail_xt jsp/upload.jsp in Coremail XT 5.0 allows XSS via an uploaded personal signature, as demonstrated by a .jpg.html filename in the signImgFile parameter. CWE-79
Cross-site Scripting
CVE-2020-29133 2024-11-21 14:23 2020-11-27 Show GitHub Exploit DB Packet Storm
208642 5.4 MEDIUM
Network
ericsson bscs_ix_r18_billing_\&_rating_mx
bscs_ix_r18_billing_\&_rating_admx
In Ericsson BSCS iX R18 Billing & Rating iX R18, ADMX is a web base module in BSCS iX that is vulnerable to stored XSS via the name or description field to a solutionUnitServlet?SuName=UserReferenceD… CWE-79
Cross-site Scripting
CVE-2020-29145 2024-11-21 14:23 2020-11-27 Show GitHub Exploit DB Packet Storm
208643 4.3 MEDIUM
Network
libslirp_project
debian
fedoraproject
libslirp
debian_linux
fedora
slirp.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length. CWE-125
Out-of-bounds Read
CVE-2020-29130 2024-11-21 14:23 2020-11-27 Show GitHub Exploit DB Packet Storm
208644 4.3 MEDIUM
Network
libslirp_project
fedoraproject
debian
libslirp
fedora
debian_linux
ncsi.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length. CWE-125
Out-of-bounds Read
CVE-2020-29129 2024-11-21 14:23 2020-11-27 Show GitHub Exploit DB Packet Storm
208645 7.5 HIGH
Network
bigbluebutton bigbluebutton An issue was discovered in BigBlueButton through 2.2.29. When at attacker is able to view an account_activations/edit?token= URI, the attacker can create an approved user account associated with an e… CWE-200
Information Exposure
CVE-2020-29043 2024-11-21 14:23 2020-11-27 Show GitHub Exploit DB Packet Storm
208646 3.7 LOW
Network
bigbluebutton bigbluebutton An issue was discovered in BigBlueButton through 2.2.29. A brute-force attack may occur because an unlimited number of codes can be entered for a meeting that is protected by an access code. CWE-307
mproper Restriction of Excessive Authentication Attempts
CVE-2020-29042 2024-11-21 14:23 2020-11-27 Show GitHub Exploit DB Packet Storm
208647 9.8 CRITICAL
Network
petl_project petl petl before 1.68, in some configurations, allows resolution of entities in an XML document. CWE-91
Blind XPath Injection
CVE-2020-29128 2024-11-21 14:23 2020-11-26 Show GitHub Exploit DB Packet Storm
208648 8.8 HIGH
Network
x11vnc_project
fedoraproject
debian
x11vnc
fedora
debian_linux
scan.c in x11vnc 0.9.16 uses IPC_CREAT|0777 in shmget calls, which allows access by actors other than the current user. CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2020-29074 2024-11-21 14:23 2020-11-26 Show GitHub Exploit DB Packet Storm
208649 4.8 MEDIUM
Network
oscommerce oscommerce osCommerce 2.3.4.1 has XSS vulnerability via the authenticated user entering the XSS payload into the title section of newsletters. CWE-79
Cross-site Scripting
CVE-2020-29070 2024-11-21 14:23 2020-11-26 Show GitHub Exploit DB Packet Storm
208650 6.1 MEDIUM
Network
liquidfiles liquidfiles A Cross-Site Script Inclusion vulnerability was found on LiquidFiles before 3.3.19. This client-side attack requires user interaction (opening a link) and successful exploitation could lead to encryp… CWE-829
 Inclusion of Functionality from Untrusted Control Sphere
CVE-2020-29072 2024-11-21 14:23 2020-11-25 Show GitHub Exploit DB Packet Storm