Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 2, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
230221 7.5 危険 Wafer - Webmatic における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2925 2012-12-20 18:52 2008-06-30 Show GitHub Exploit DB Packet Storm
230222 4.3 警告 Wafer - Webmatic におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-2924 2012-12-20 18:52 2008-06-30 Show GitHub Exploit DB Packet Storm
230223 7.5 危険 t0pp8uzz - artegic Dana IRC クライアントにおけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-2922 2012-12-20 18:52 2008-06-30 Show GitHub Exploit DB Packet Storm
230224 7.5 危険 PreProject.com - E-SMART CART の productsofcat.asp における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2917 2012-12-20 18:52 2008-06-30 Show GitHub Exploit DB Packet Storm
230225 6.8 警告 PreProject.com - Pre ADS Portal における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2916 2012-12-20 18:52 2008-06-30 Show GitHub Exploit DB Packet Storm
230226 7.5 危険 PreProject.com - Pre Job Board の jobseekers/JobSearch.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2915 2012-12-20 18:52 2008-06-30 Show GitHub Exploit DB Packet Storm
230227 7.5 危険 PreProject.com - PHP JOBWEBSITE PRO の jobseekers/JobSearch3.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2914 2012-12-20 18:52 2008-06-30 Show GitHub Exploit DB Packet Storm
230228 6.8 警告 webchamado - WebChamado の admin/index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2907 2012-12-20 18:52 2008-06-30 Show GitHub Exploit DB Packet Storm
230229 6.8 警告 webchamado - WebChamado の lista_anexos.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2906 2012-12-20 18:52 2008-06-30 Show GitHub Exploit DB Packet Storm
230230 7.5 危険 phpmycart - Conkurent PHPMyCart の shop.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2904 2012-12-20 18:52 2008-06-30 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 2, 2026, 4:18 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
196151 5.4 MEDIUM
Network
gitlab gitlab Improper authorization in GitLab CE/EE affecting all versions since 12.6 allowed guest users to create issues for Sentry errors and track their status CWE-863
 Incorrect Authorization
CVE-2021-22256 2024-11-21 14:49 2021-08-26 Show GitHub Exploit DB Packet Storm
196152 5.4 MEDIUM
Network
gitlab gitlab Improper authorization in GitLab CE/EE affecting all versions since 13.3 allowed users to view and delete impersonation tokens that administrators created for their account NVD-CWE-Other
CVE-2021-22250 2024-11-21 14:49 2021-08-26 Show GitHub Exploit DB Packet Storm
196153 4.3 MEDIUM
Network
gitlab gitlab Improper authorization in GitLab CE/EE affecting all versions since 13.0 allows guests in private projects to view CI/CD analytics CWE-863
 Incorrect Authorization
CVE-2021-22247 2024-11-21 14:49 2021-08-26 Show GitHub Exploit DB Packet Storm
196154 2.7 LOW
Network
gitlab gitlab Improper validation of commit author in GitLab CE/EE affecting all versions allowed an attacker to make several pages in a project impossible to view CWE-20
 Improper Input Validation 
CVE-2021-22245 2024-11-21 14:49 2021-08-26 Show GitHub Exploit DB Packet Storm
196155 6.5 MEDIUM
Network
gitlab gitlab Improper authorization in the vulnerability report feature in GitLab EE affecting all versions since 13.1 allowed a reporter to access vulnerability data NVD-CWE-Other
CVE-2021-22244 2024-11-21 14:49 2021-08-26 Show GitHub Exploit DB Packet Storm
196156 4.3 MEDIUM
Network
gitlab gitlab Under specialized conditions, GitLab CE/EE versions starting 7.10 may allow existing GitLab users to use an invite URL meant for another email address to gain access into a group. CWE-863
 Incorrect Authorization
CVE-2021-22243 2024-11-21 14:49 2021-08-26 Show GitHub Exploit DB Packet Storm
196157 5.4 MEDIUM
Network
gitlab gitlab Insufficient input sanitization in Mermaid markdown in GitLab CE/EE version 11.4 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted markdown CWE-79
Cross-site Scripting
CVE-2021-22242 2024-11-21 14:49 2021-08-26 Show GitHub Exploit DB Packet Storm
196158 4.9 MEDIUM
Network
gitlab gitlab Under specialized conditions, GitLab may allow a user with an impersonation token to perform Git actions even if impersonation is disabled. This vulnerability is present in GitLab CE/EE versions befo… CWE-384
 Session Fixation
CVE-2021-22237 2024-11-21 14:49 2021-08-26 Show GitHub Exploit DB Packet Storm
196159 8.8 HIGH
Network
gitlab gitlab Due to improper handling of OAuth client IDs, new subscriptions generated OAuth tokens on an incorrect OAuth client application. This vulnerability is present in GitLab CE/EE since version 14.1. CWE-863
 Incorrect Authorization
CVE-2021-22236 2024-11-21 14:49 2021-08-26 Show GitHub Exploit DB Packet Storm
196160 7.8 HIGH
Local
codesys codesys An unsafe deserialization vulnerability exists in the Engine.plugin ProfileInformation ProfileData functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file… CWE-502
 Deserialization of Untrusted Data
CVE-2021-21869 2024-11-21 14:49 2021-08-26 Show GitHub Exploit DB Packet Storm