Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 24, 2026, noon

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
230021 7.5 危険 phpBB - phpBB 用の XS-Mod におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-1512 2012-12-20 18:52 2008-03-25 Show GitHub Exploit DB Packet Storm
230022 7.5 危険 xlportal - XLPortal の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-1509 2012-12-20 18:52 2008-03-25 Show GitHub Exploit DB Packet Storm
230023 7.5 危険 sstreamtv - Joomla! 用の SSTREAMTV custompages コンポーネントにおける PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2008-1505 2012-12-20 18:52 2008-03-25 Show GitHub Exploit DB Packet Storm
230024 4.3 警告 php heaven - phpHeaven phpMyChat の setup.php3 におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-1504 2012-12-20 18:52 2008-03-25 Show GitHub Exploit DB Packet Storm
230025 4.3 警告 tinyportal - TinyPortal の index.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-1500 2012-12-20 18:52 2008-03-25 Show GitHub Exploit DB Packet Storm
230026 6.8 警告 VideoLAN - VLC 用の libmp4.c における整数オーバーフローの脆弱性 CWE-189
数値処理の問題
CVE-2008-1489 2012-12-20 18:52 2008-03-24 Show GitHub Exploit DB Packet Storm
230027 4.3 警告 PunBB - PunBB におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-1485 2012-12-20 18:52 2008-03-24 Show GitHub Exploit DB Packet Storm
230028 3.5 注意 PunBB - PunBB のパスワードリセット機能における新規パスワードを特定される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-1484 2012-12-20 18:52 2008-02-20 Show GitHub Exploit DB Packet Storm
230029 6.8 警告 Xine - xine-lib における整数オーバーフローの脆弱性 CWE-119
CWE-189
CVE-2008-1482 2012-12-20 18:52 2008-03-24 Show GitHub Exploit DB Packet Storm
230030 4.3 警告 webSPELL - webSPELL の index.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-1481 2012-12-20 18:52 2008-03-24 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 24, 2026, 4:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
209631 9.8 CRITICAL
Network
abloy key_manager An issue in the SeChangeNotifyPrivilege component of Abloy Key Manager Version 7.14301.0.0 allows attackers to escalate privileges via a change in permissions. NVD-CWE-Other
CVE-2020-18170 2024-11-21 14:08 2021-07-27 Show GitHub Exploit DB Packet Storm
209632 7.8 HIGH
Local
techsmith snagit A vulnerability in the Windows installer XML (WiX) toolset of TechSmith Snagit 19.1.1.2860 allows attackers to escalate privileges. NOTE: Exploit of the Snagit installer would require the end user to… CWE-269
 Improper Privilege Management
CVE-2020-18169 2024-11-21 14:08 2021-07-27 Show GitHub Exploit DB Packet Storm
209633 9.8 CRITICAL
Network
twothink_project twothink A remote code execution (RCE) vulnerability in /library/think/App.php of Twothink v2.0 allows attackers to execute arbitrary PHP code. NVD-CWE-noinfo
CVE-2020-17952 2024-11-21 14:08 2021-07-27 Show GitHub Exploit DB Packet Storm
209634 9.8 CRITICAL
Network
intelliants subrion SQL Injection vulnerability in Subrion CMS v4.2.1 in the search page if a website uses a PDO connection. CWE-89
SQL Injection
CVE-2020-18155 2024-11-21 14:08 2021-07-15 Show GitHub Exploit DB Packet Storm
209635 6.5 MEDIUM
Network
thinkcmf thinkcmf Cross Site Request Forgery (CSRF) vulnerability in ThinkCMF v5.1.0, which can add an admin account. CWE-352
 Origin Validation Error
CVE-2020-18151 2024-11-21 14:08 2021-07-15 Show GitHub Exploit DB Packet Storm
209636 6.1 MEDIUM
Network
baidu umeditor Cross Site Scripting (XSS) vulnerability in umeditor v1.2.3 via /public/common/umeditor/php/getcontent.php. CWE-79
Cross-site Scripting
CVE-2020-18145 2024-11-21 14:08 2021-07-15 Show GitHub Exploit DB Packet Storm
209637 9.8 CRITICAL
Network
ectouch ectouch SQL Injection Vulnerability in ECTouch v2 via the integral_min parameter in index.php. CWE-89
SQL Injection
CVE-2020-18144 2024-11-21 14:08 2021-07-15 Show GitHub Exploit DB Packet Storm
209638 9.8 CRITICAL
Network
wms_project wms SQL Injection in WMS v1.0 allows remote attackers to execute arbitrary code via the "username" parameter in the component "chkuser.php". CWE-89
SQL Injection
CVE-2020-18544 2024-11-21 14:08 2021-07-13 Show GitHub Exploit DB Packet Storm
209639 9.1 CRITICAL
Network
halo halo File Deletion vulnerability in Halo 0.4.3 via delBackup. CWE-862
 Missing Authorization
CVE-2020-19038 2024-11-21 14:08 2021-07-13 Show GitHub Exploit DB Packet Storm
209640 5.3 MEDIUM
Network
halo halo Incorrect Access Control vulnearbility in Halo 0.4.3, which allows a malicious user to bypass encrption to view encrpted articles via cookies. CWE-287
Improper Authentication
CVE-2020-19037 2024-11-21 14:08 2021-07-13 Show GitHub Exploit DB Packet Storm