Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 29, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
230161 6.5 警告 phpmotion - PHPmotion の update_profile.php における任意のコードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2008-3117 2012-12-20 18:52 2008-07-10 Show GitHub Exploit DB Packet Storm
230162 4.3 警告 v-webmail - V-webmail の redirect.php におけるオープンリダイレクトの脆弱性 CWE-Other
その他
CVE-2008-3061 2012-12-20 18:52 2008-10-7 Show GitHub Exploit DB Packet Storm
230163 5 警告 v-webmail - V-webmail における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2008-3060 2012-12-20 18:52 2008-10-7 Show GitHub Exploit DB Packet Storm
230164 7.5 危険 TYPO3 Association - TYPO3 用の Codeon Petition エクステンションにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3056 2012-12-20 18:52 2008-07-7 Show GitHub Exploit DB Packet Storm
230165 7.5 危険 TYPO3 Association - TYPO3 用の Support view エクステンションにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3055 2012-12-20 18:52 2008-07-7 Show GitHub Exploit DB Packet Storm
230166 7.5 危険 TYPO3 Association - TYPO3 用の Branchenbuch エクステンションにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3054 2012-12-20 18:52 2008-07-7 Show GitHub Exploit DB Packet Storm
230167 7.5 危険 TYPO3 Association - TYPO3 用の SQL Frontend エクステンションにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3053 2012-12-20 18:52 2008-07-7 Show GitHub Exploit DB Packet Storm
230168 7.5 危険 TYPO3 Association - TYPO3 用の SQL Frontend エクステンションにおけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2008-3052 2012-12-20 18:52 2008-07-7 Show GitHub Exploit DB Packet Storm
230169 7.5 危険 TYPO3 Association - TYPO3 用の Pinboard エクステンションにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3051 2012-12-20 18:52 2008-07-7 Show GitHub Exploit DB Packet Storm
230170 5 警告 TYPO3 Association - TYPO3 用の PDF Generator 2 エクステンションにおけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2008-3050 2012-12-20 18:52 2008-07-7 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 29, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
201391 6.1 MEDIUM
Network
cayintech smp-pro4_firmware An issue was discovered on Cayin SMP-PRO4 devices. They allow image_preview.html?filename= reflected XSS. CWE-79
Cross-site Scripting
CVE-2020-6955 2024-11-21 14:36 2020-01-14 Show GitHub Exploit DB Packet Storm
201392 6.5 MEDIUM
Network
cayintech smp-pro4_firmware An issue was discovered on Cayin SMP-PRO4 devices. A user can discover a saved password by viewing the URL after a Connection String Test. This password is shown in the webpass parameter of a media_f… CWE-200
Information Exposure
CVE-2020-6954 2024-11-21 14:36 2020-01-14 Show GitHub Exploit DB Packet Storm
201393 5.3 MEDIUM
Network
gitlab gitlab An issue was discovered in GitLab Enterprise Edition (EE) 8.9.0 through 12.6.1. Using the project import feature, it was possible for someone to obtain issues from private projects. NVD-CWE-noinfo
CVE-2020-6832 2024-11-21 14:36 2020-01-14 Show GitHub Exploit DB Packet Storm
201394 8.8 HIGH
Network
hashbrowncms hashbrown_cms A privilege escalation issue was discovered in the postUser function in HashBrown CMS through 1.3.3. An editor user can change the password hash of an admin user's account, or otherwise reconfigure t… CWE-269
 Improper Privilege Management
CVE-2020-6949 2024-11-21 14:36 2020-01-14 Show GitHub Exploit DB Packet Storm
201395 9.8 CRITICAL
Network
hashbrowncms hashbrown_cms A remote code execution issue was discovered in HashBrown CMS through 1.3.3. Server/Entity/Deployer/GitDeployer.js has a Service.AppService.exec call that mishandles the URL, repository, username, an… CWE-78
OS Command 
CVE-2020-6948 2024-11-21 14:36 2020-01-14 Show GitHub Exploit DB Packet Storm
201396 5.3 MEDIUM
Network
ultimatemember ultimate_member Multiple Insecure Direct Object Reference vulnerabilities in includes/core/class-files.php in the Ultimate Member plugin through 2.1.2 for WordPress allow remote attackers to change other users' prof… CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2020-6859 2024-11-21 14:36 2020-01-14 Show GitHub Exploit DB Packet Storm
201397 8.8 HIGH
Network
symonics
fedoraproject
libmysofa
fedora
libmysofa 0.9.1 has a stack-based buffer overflow in readDataVar in hdf/dataobject.c during the reading of a header message attribute. CWE-787
 Out-of-bounds Write
CVE-2020-6860 2024-11-21 14:36 2020-01-13 Show GitHub Exploit DB Packet Storm
201398 7.5 HIGH
Network
uclouvain
fedoraproject
debian
redhat
oracle
openjpeg
fedora
debian_linux
enterprise_linux_desktop
enterprise_linux_workstation
enterprise_linux_server
enterprise_linux
enterprise_linux_server_aus
enterprise_linux_server…
OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because of lack of opj_j2k_update_image_dimensions validation. CWE-787
 Out-of-bounds Write
CVE-2020-6851 2024-11-21 14:36 2020-01-13 Show GitHub Exploit DB Packet Storm
201399 6.1 MEDIUM
Network
axper vision_ii_firmware Axper Vision II 4 devices allow XSS via the DEVICE_NAME (aka Device Name) parameter to the configWebParams.cgi URI. CWE-79
Cross-site Scripting
CVE-2020-6848 2024-11-21 14:36 2020-01-13 Show GitHub Exploit DB Packet Storm
201400 5.4 MEDIUM
Network
opentrade_project opentrade OpenTrade through 0.2.0 has a DOM-based XSS vulnerability that is executed when an administrator attempts to delete a message that contains JavaScript. CWE-79
Cross-site Scripting
CVE-2020-6847 2024-11-21 14:36 2020-01-11 Show GitHub Exploit DB Packet Storm