Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 28, 2026, noon

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
230301 7.5 危険 PHPNUKE - PHP-Nuke 用の Kose_Yazilari モジュールにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-1053 2012-12-20 18:34 2008-02-27 Show GitHub Exploit DB Packet Storm
230302 6.8 警告 phpprofiles - phpProfiles の include/body_comm.inc.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2008-1051 2012-12-20 18:34 2008-02-27 Show GitHub Exploit DB Packet Storm
230303 7.5 危険 softbiz - Softbiz Jokes & Funny Pics Script の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-1050 2012-12-20 18:34 2008-02-27 Show GitHub Exploit DB Packet Storm
230304 10 危険 positive software - Parallels H-Sphere で使用される Parallels SiteStudio における脆弱性 CWE-noinfo
情報不足
CVE-2008-1049 2012-12-20 18:34 2008-02-26 Show GitHub Exploit DB Packet Storm
230305 4.3 警告 Plume CMS - Plume CMS の manager/xmedia.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-1048 2012-12-20 18:34 2008-02-27 Show GitHub Exploit DB Packet Storm
230306 4.3 警告 Tiki Software Community Association - TikiWiki の tiki-edit_article.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-1047 2012-12-20 18:34 2008-02-23 Show GitHub Exploit DB Packet Storm
230307 6.8 警告 quinsonnas - Quinsonnas Mail Checker の footer.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2008-1046 2012-12-20 18:34 2008-02-27 Show GitHub Exploit DB Packet Storm
230308 7.5 危険 porar - PORAR WEBBOARD の question.asp における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-1039 2012-12-20 18:34 2008-02-27 Show GitHub Exploit DB Packet Storm
230309 5.8 警告 spyce - Spyce - PSP における重要な情報を取得される脆弱性 CWE-20
不適切な入力確認
CVE-2008-0982 2012-12-20 18:34 2008-02-25 Show GitHub Exploit DB Packet Storm
230310 6.4 警告 spyce - Spyce - PSP の spyce/examples/redirect.spy におけるオープンリダイレクトの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-0981 2012-12-20 18:34 2008-02-25 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 28, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
209481 9.8 CRITICAL
Network
crmeb crmeb CRMEB 3.1.0+ is vulnerable to File Upload Getshell via /crmeb/crmeb/services/UploadService.php. CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2020-21787 2024-11-21 14:12 2021-06-25 Show GitHub Exploit DB Packet Storm
209482 9.8 CRITICAL
Network
txjia imcat SQL Injection vulnerability in imcat v5.2 via the fm[auser] parameters in coms/add_coms.php. CWE-89
SQL Injection
CVE-2020-20392 2024-11-21 14:12 2021-06-24 Show GitHub Exploit DB Packet Storm
209483 5.4 MEDIUM
Network
get-simple getsimplecms Cross Site Scripting vulnerability in GetSimpleCMS 3.4.0a in admin/snippets.php via (1) Add Snippet and (2) Save snippets. CWE-79
Cross-site Scripting
CVE-2020-20391 2024-11-21 14:12 2021-06-24 Show GitHub Exploit DB Packet Storm
209484 4.8 MEDIUM
Network
get-simple getsimplecms Cross Site Scripting (XSS) vulnerability in GetSimpleCMS 3.4.0a in admin/edit.php. CWE-79
Cross-site Scripting
CVE-2020-20389 2024-11-21 14:12 2021-06-24 Show GitHub Exploit DB Packet Storm
209485 6.1 MEDIUM
Network
hisiphp hisiphp Cross Site Scripting (XSS) vulnerability in HisiPHP 2.0.8 via the group name in addgroup.html. CWE-79
Cross-site Scripting
CVE-2020-21130 2024-11-21 14:12 2021-06-22 Show GitHub Exploit DB Packet Storm
209486 6.1 MEDIUM
Network
metinfo metinfo Cross Site Scripting (XSS) vulnerability in MetInfo 7.0.0 via the gourl parameter in login.php. CWE-79
Cross-site Scripting
CVE-2020-21517 2024-11-21 14:12 2021-06-22 Show GitHub Exploit DB Packet Storm
209487 7.5 HIGH
Network
white_shark_systems_project white_shark_systems White Shark System (WSS) 1.3.2 has a SQL injection vulnerability. The vulnerability stems from the default_task_edituser.php files failing to filter the csa_to_user parameter. Remote attackers can ex… CWE-89
SQL Injection
CVE-2020-20474 2024-11-21 14:12 2021-06-21 Show GitHub Exploit DB Packet Storm
209488 7.5 HIGH
Network
white_shark_systems_project white_shark_systems White Shark System (WSS) 1.3.2 has a SQL injection vulnerability. The vulnerability stems from the control_task.php, control_project.php, default_user.php files failing to filter the sort parameter. … CWE-89
SQL Injection
CVE-2020-20473 2024-11-21 14:12 2021-06-21 Show GitHub Exploit DB Packet Storm
209489 5.3 MEDIUM
Network
white_shark_systems_project white_shark_systems White Shark System (WSS) 1.3.2 has a sensitive information disclosure vulnerability. The if_get_addbook.php file does not have an authentication operation. Remote attackers can obtain username inform… CWE-306
Missing Authentication for Critical Function
CVE-2020-20472 2024-11-21 14:12 2021-06-21 Show GitHub Exploit DB Packet Storm
209490 8.8 HIGH
Network
white_shark_systems_project white_shark_systems White Shark System (WSS) 1.3.2 has an unauthorized access vulnerability in default_user_edit.php, remote attackers can exploit this vulnerability to escalate to admin privileges. CWE-863
 Incorrect Authorization
CVE-2020-20471 2024-11-21 14:12 2021-06-21 Show GitHub Exploit DB Packet Storm