Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 30, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
230031 9.3 危険 txtsql - txtSQL の examples/txtSQLAdmin/startup.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2008-3595 2012-12-20 18:52 2008-08-12 Show GitHub Exploit DB Packet Storm
230032 7.5 危険 syzygycms - SyzygyCMS の index.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-3593 2012-12-20 18:52 2008-08-11 Show GitHub Exploit DB Packet Storm
230033 7.5 危険 phsblog - phsBlog における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3588 2012-12-20 18:52 2008-08-11 Show GitHub Exploit DB Packet Storm
230034 7.5 危険 pozscripts - PozScripts GreenCart PHP Shopping Cart における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3585 2012-12-20 18:52 2008-08-11 Show GitHub Exploit DB Packet Storm
230035 4.3 警告 qsoft - Qsoft K-Links の index.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-3581 2012-12-20 18:52 2008-08-10 Show GitHub Exploit DB Packet Storm
230036 7.5 危険 qsoft - Qsoft K-Links における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3580 2012-12-20 18:52 2008-08-10 Show GitHub Exploit DB Packet Storm
230037 2.6 注意 Pluck CMS - Pluck におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-3574 2012-12-20 18:52 2008-08-10 Show GitHub Exploit DB Packet Storm
230038 5 警告 Pligg
PHPNUKE
- Pligg などの製品の CAPTCHA 実装における CAPTCHA テストを通過される脆弱性 CWE-189
CWE-264
CVE-2008-3573 2012-12-20 18:52 2008-08-10 Show GitHub Exploit DB Packet Storm
230039 4.3 警告 Pligg - Pligg の index.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-3572 2012-12-20 18:52 2008-08-10 Show GitHub Exploit DB Packet Storm
230040 7.8 危険 Xerox - Xerox Phaser におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2008-3571 2012-12-20 18:52 2008-08-10 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 30, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
201611 7.5 HIGH
Network
mozilla firefox_esr A malicious Android application could craft an Intent that would have been processed by Firefox for Android and potentially result in a file overwrite in the user's profile directory. One exploitatio… CWE-22
Path Traversal
CVE-2020-6828 2024-11-21 14:36 2020-04-25 Show GitHub Exploit DB Packet Storm
201612 9.8 CRITICAL
Network
mozilla firefox Mozilla developers Tyson Smith, Bob Clary, and Alexandru Michis reported memory safety bugs present in Firefox 74. Some of these bugs showed evidence of memory corruption and we presume that with eno… CWE-787
 Out-of-bounds Write
CVE-2020-6826 2024-11-21 14:36 2020-04-25 Show GitHub Exploit DB Packet Storm
201613 9.8 CRITICAL
Network
mozilla firefox
firefox_esr
thunderbird
Mozilla developers and community members Tyson Smith and Christian Holler reported memory safety bugs present in Firefox 74 and Firefox ESR 68.6. Some of these bugs showed evidence of memory corrupti… CWE-787
 Out-of-bounds Write
CVE-2020-6825 2024-11-21 14:36 2020-04-25 Show GitHub Exploit DB Packet Storm
201614 2.8 LOW
Local
mozilla firefox Initially, a user opens a Private Browsing Window and generates a password for a site, then closes the Private Browsing Window but leaves Firefox open. Subsequently, if the user had opened a new Priv… CWE-384
 Session Fixation
CVE-2020-6824 2024-11-21 14:36 2020-04-25 Show GitHub Exploit DB Packet Storm
201615 9.8 CRITICAL
Network
mozilla firefox A malicious extension could have called <code>browser.identity.launchWebAuthFlow</code>, controlling the redirect_uri, and through the Promise returned, obtain the Auth code and gain access to the us… CWE-862
 Missing Authorization
CVE-2020-6823 2024-11-21 14:36 2020-04-25 Show GitHub Exploit DB Packet Storm
201616 8.8 HIGH
Network
mozilla firefox
firefox_esr
thunderbird
On 32-bit builds, an out of bounds write could have occurred when processing an image larger than 4 GB in <code>GMPDecodeData</code>. It is possible that with enough effort this could have been explo… CWE-787
 Out-of-bounds Write
CVE-2020-6822 2024-11-21 14:36 2020-04-25 Show GitHub Exploit DB Packet Storm
201617 7.5 HIGH
Network
mozilla firefox
firefox_esr
thunderbird
When reading from areas partially or fully outside the source resource with WebGL's <code>copyTexSubImage</code> method, the specification requires the returned values be zero. Previously, this memor… CWE-908
 Use of Uninitialized Resource
CVE-2020-6821 2024-11-21 14:36 2020-04-25 Show GitHub Exploit DB Packet Storm
201618 8.1 HIGH
Network
mozilla thunderbird
firefox
firefox_esr
Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thund… CWE-362
Race Condition
CVE-2020-6820 2024-11-21 14:36 2020-04-25 Show GitHub Exploit DB Packet Storm
201619 8.1 HIGH
Network
mozilla thunderbird
firefox
firefox_esr
Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affec… CWE-362
CWE-416
Race Condition
 Use After Free
CVE-2020-6819 2024-11-21 14:36 2020-04-25 Show GitHub Exploit DB Packet Storm
201620 5.4 MEDIUM
Network
hp onboard_administrator A potential security vulnerability has been identified in HPE Onboard Administrator. The vulnerability could be remotely exploited to allow Reflected Cross Site Scripting. HPE has made the following … CWE-79
Cross-site Scripting
CVE-2020-7132 2024-11-21 14:36 2020-04-24 Show GitHub Exploit DB Packet Storm