Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 28, 2026, 2:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
230301 6.9 警告 symark - Symark PowerBroker におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-1056 2012-12-20 18:34 2008-02-28 Show GitHub Exploit DB Packet Storm
230302 7.5 危険 PHPNUKE - PHP-Nuke 用の Kose_Yazilari モジュールにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-1053 2012-12-20 18:34 2008-02-27 Show GitHub Exploit DB Packet Storm
230303 6.8 警告 phpprofiles - phpProfiles の include/body_comm.inc.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2008-1051 2012-12-20 18:34 2008-02-27 Show GitHub Exploit DB Packet Storm
230304 7.5 危険 softbiz - Softbiz Jokes & Funny Pics Script の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-1050 2012-12-20 18:34 2008-02-27 Show GitHub Exploit DB Packet Storm
230305 10 危険 positive software - Parallels H-Sphere で使用される Parallels SiteStudio における脆弱性 CWE-noinfo
情報不足
CVE-2008-1049 2012-12-20 18:34 2008-02-26 Show GitHub Exploit DB Packet Storm
230306 4.3 警告 Plume CMS - Plume CMS の manager/xmedia.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-1048 2012-12-20 18:34 2008-02-27 Show GitHub Exploit DB Packet Storm
230307 4.3 警告 Tiki Software Community Association - TikiWiki の tiki-edit_article.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-1047 2012-12-20 18:34 2008-02-23 Show GitHub Exploit DB Packet Storm
230308 6.8 警告 quinsonnas - Quinsonnas Mail Checker の footer.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2008-1046 2012-12-20 18:34 2008-02-27 Show GitHub Exploit DB Packet Storm
230309 7.5 危険 porar - PORAR WEBBOARD の question.asp における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-1039 2012-12-20 18:34 2008-02-27 Show GitHub Exploit DB Packet Storm
230310 5.8 警告 spyce - Spyce - PSP における重要な情報を取得される脆弱性 CWE-20
不適切な入力確認
CVE-2008-0982 2012-12-20 18:34 2008-02-25 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 28, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
200971 6.5 MEDIUM
Network
sos-berlin jobscheduler An XML External Entity (XEE) vulnerability exists in the JOC Cockpit component of SOS JobScheduler 1.12 and 1.13.2 allows attackers to read files from the server via an entity declaration in any of t… CWE-776
XML Entity Expansion
CVE-2020-6856 2024-11-21 14:36 2020-02-7 Show GitHub Exploit DB Packet Storm
200972 6.5 MEDIUM
Network
sos-berlin jobscheduler A large or infinite loop vulnerability in the JOC Cockpit component of SOS JobScheduler 1.11 and 1.13.2 allows attackers to parameterize housekeeping jobs in a way that exhausts system resources and … CWE-835
 Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2020-6855 2024-11-21 14:36 2020-02-7 Show GitHub Exploit DB Packet Storm
200973 6.5 MEDIUM
Network
bosch video_management_system_viewer
video_management_system
A path traversal vulnerability in the Bosch Video Management System (BVMS) FileTransferService allows an authenticated remote attacker to read arbitrary files from the Central Server. This affects Bo… CWE-22
Path Traversal
CVE-2020-6767 2024-11-21 14:36 2020-02-7 Show GitHub Exploit DB Packet Storm
200974 5.4 MEDIUM
Network
sos-berlin jobscheduler A cross-site scripting (XSS) vulnerability in the JOC Cockpit component of SOS JobScheduler 1.11 and 1.13.2 allows attackers to inject arbitrary web script or HTML via JSON properties available from … CWE-79
Cross-site Scripting
CVE-2020-6854 2024-11-21 14:36 2020-02-6 Show GitHub Exploit DB Packet Storm
200975 7.5 HIGH
Network
gitlab gitlab An issue was discovered in GitLab EE 11.3 and later. A GitLab Workhorse bypass could lead to package and file disclosure via request smuggling. NVD-CWE-noinfo
CVE-2020-6833 2024-11-21 14:36 2020-02-6 Show GitHub Exploit DB Packet Storm
200976 9.8 CRITICAL
Network
dotcms dotcms dotCMS before 5.2.4 is vulnerable to directory traversal, leading to incorrect access control. It allows an attacker to read or execute files under $TOMCAT_HOME/webapps/ROOT/assets (which should be a… CWE-22
CWE-434
Path Traversal
 Unrestricted Upload of File with Dangerous Type 
CVE-2020-6754 2024-11-21 14:36 2020-02-6 Show GitHub Exploit DB Packet Storm
200977 9.8 CRITICAL
Network
automationdirect c-more_ea9-rhi_firmware
c-more_ea9-t6cl-r_firmware
c-more_ea9-t6cl_firmware
c-more_ea9-t7cl-r_firmware
c-more_ea9-t7cl_firmware
c-more_ea9-t8cl_firmware
c-more_ea9-t10cl_firmware
It is possible to unmask credentials and other sensitive information on “unprotected” project files, which may allow an attacker to remotely access the C-More Touch Panels EA9 series: firmware versio… CWE-522
 Insufficiently Protected Credentials
CVE-2020-6969 2024-11-21 14:36 2020-02-6 Show GitHub Exploit DB Packet Storm
200978 7.5 HIGH
Network
opensuse wicked
leap
An ni_dhcp4_parse_response memory leak in openSUSE wicked 0.6.55 and earlier allows network attackers to cause a denial of service by sending DHCP4 packets without a message type option. CWE-401
 Missing Release of Memory after Effective Lifetime
CVE-2020-7216 2024-11-21 14:36 2020-02-6 Show GitHub Exploit DB Packet Storm
200979 7.8 HIGH
Local
mariadb mariadb mysql_install_db in MariaDB 10.4.7 through 10.4.11 allows privilege escalation from the mysql user account to root because chown and chmod are performed unsafely, as demonstrated by a symlink attack … CWE-59
Link Following
CVE-2020-7221 2024-11-21 14:36 2020-02-5 Show GitHub Exploit DB Packet Storm
200980 7.5 HIGH
Network
hashicorp consul HashiCorp Consul and Consul Enterprise up to 1.6.2 HTTP/RPC services allowed unbounded resource usage, and were susceptible to unauthenticated denial of service. Fixed in 1.6.3. CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2020-7219 2024-11-21 14:36 2020-01-31 Show GitHub Exploit DB Packet Storm