Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 28, 2026, noon

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
230461 4.3 警告 サン・マイクロシステムズ - Sun Java System Identity Manager におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-0239 2012-12-20 18:34 2008-01-9 Show GitHub Exploit DB Packet Storm
230462 7.5 危険 Xine - xine-lib の input/libreal/rmff.c におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-0238 2012-12-20 18:34 2008-01-11 Show GitHub Exploit DB Packet Storm
230463 7.5 危険 zero cms - Zero CMS における意図したアクセス制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-0233 2012-12-20 18:34 2008-01-10 Show GitHub Exploit DB Packet Storm
230464 7.5 危険 zero cms - Zero CMS における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0232 2012-12-20 18:34 2008-01-10 Show GitHub Exploit DB Packet Storm
230465 7.5 危険 tuned studios - Tuned Studios Subwoofer などの Web ページテンプレートにおけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-0231 2012-12-20 18:34 2008-01-10 Show GitHub Exploit DB Packet Storm
230466 6.4 警告 Xine - xine-lib の input/libreal/rmff.c におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-0225 2012-12-20 18:34 2008-01-10 Show GitHub Exploit DB Packet Storm
230467 7.5 危険 runcms - RunCMS の Newbb_plus モジュールにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0224 2012-12-20 18:34 2008-01-10 Show GitHub Exploit DB Packet Storm
230468 7.5 危険 WordPress.org - WordPress 用の Wp-FileManager プラグインにおける任意の PHP コードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2008-0222 2012-12-20 18:34 2008-01-10 Show GitHub Exploit DB Packet Storm
230469 6.4 警告 uebimiau - Uebimiau Webmail における認証を回避される脆弱性 CWE-287
不適切な認証
CVE-2008-0210 2012-12-20 18:34 2008-01-9 Show GitHub Exploit DB Packet Storm
230470 5.8 警告 snitz forums 2000 - Snitz Forums 2000 の Forums/login.asp におけるオープンリダイレクトの脆弱性 CWE-20
不適切な入力確認
CVE-2008-0209 2012-12-20 18:34 2008-01-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 28, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
196711 8.8 HIGH
Local
qualcomm aqt1000_firmware
ar8031_firmware
ar8035_firmware
csra6620_firmware
csra6640_firmware
fsm10055_firmware
fsm10056_firmware
mdm9150_firmware
qca6390_firmware
qca6391_firmware<…
Improper handling of permissions of a shared memory region can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industria… CWE-787
 Out-of-bounds Write
CVE-2021-1942 2024-11-21 14:45 2022-04-1 Show GitHub Exploit DB Packet Storm
196712 9.8 CRITICAL
Network
skolelinux
debian
debian-edu-config
debian_linux
It was discovered, that debian-edu-config, a set of configuration files used for the Debian Edu blend, before 2.12.16 configured insecure permissions for the user web shares (~/public_html), which co… CWE-276
Incorrect Default Permissions 
CVE-2021-20001 2024-11-21 14:45 2022-02-12 Show GitHub Exploit DB Packet Storm
196713 8.8 HIGH
Network
sonicwall sonicos A Stack-based buffer overflow in the SonicOS SessionID HTTP response header allows a remote authenticated attacker to cause Denial of Service (DoS) and potentially results in code execution in the fi… CWE-787
 Out-of-bounds Write
CVE-2021-20048 2024-11-21 14:45 2022-01-10 Show GitHub Exploit DB Packet Storm
196714 8.8 HIGH
Network
sonicwall sonicos A Stack-based buffer overflow in the SonicOS HTTP Content-Length response header allows a remote authenticated attacker to cause Denial of Service (DoS) and potentially results in code execution in t… CWE-787
 Out-of-bounds Write
CVE-2021-20046 2024-11-21 14:45 2022-01-10 Show GitHub Exploit DB Packet Storm
196715 6.5 MEDIUM
Local
qualcomm qca6391_firmware
qcm6490_firmware
qcs6490_firmware
qrb5165_firmware
qrb5165n_firmware
sd690_5g_firmware
sd750g_firmware
sd765_firmware
sd765g_firmware
sd768g_firmware
sd…
Improper handling of resource allocation in virtual machines can lead to information exposure in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile CWE-668
 Exposure of Resource to Wrong Sphere
CVE-2021-1918 2024-11-21 14:45 2022-01-3 Show GitHub Exploit DB Packet Storm
196716 7.8 HIGH
Local
qualcomm ar8031_firmware
ar8035_firmware
csra6620_firmware
csra6640_firmware
csrb31024_firmware
fsm10055_firmware
fsm10056_firmware
mdm9150_firmware
mdm9205_firmware
mdm9628_firmwar…
Improper access control in TrustZone due to improper error handling while handling the signing key in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon… CWE-755
 Improper Handling of Exceptional Conditions
CVE-2021-1894 2024-11-21 14:45 2022-01-3 Show GitHub Exploit DB Packet Storm
196717 8.8 HIGH
Adjacent
dlink dir-2640-us_firmware Quagga Services on D-Link DIR-2640 less than or equal to version 1.11B02 use default hard-coded credentials, which can allow a remote attacker to gain administrative access to the zebra or ripd those… CWE-798
 Use of Hard-coded Credentials
CVE-2021-20132 2024-11-21 14:45 2021-12-31 Show GitHub Exploit DB Packet Storm
196718 8.4 HIGH
Adjacent
dlink dir-2640-us_firmware Quagga Services on D-Link DIR-2640 less than or equal to version 1.11B02 are affected by an absolute path traversal vulnerability that allows a remote, authenticated attacker to set an arbitrary file… CWE-22
Path Traversal
CVE-2021-20134 2024-11-21 14:45 2021-12-31 Show GitHub Exploit DB Packet Storm
196719 6.1 MEDIUM
Adjacent
dlink dir-2640-us_firmware Quagga Services on D-Link DIR-2640 less than or equal to version 1.11B02 are affected by an absolute path traversal vulnerability that allows a remote, authenticated attacker to set the "message of t… CWE-22
Path Traversal
CVE-2021-20133 2024-11-21 14:45 2021-12-31 Show GitHub Exploit DB Packet Storm
196720 7.5 HIGH
Network
sonicwall sma_100_firmware
sma_200_firmware
sma_210_firmware
sma_400_firmware
sma_410_firmware
sma_500v_firmware
An Improper Access Control Vulnerability in the SMA100 series leads to multiple restricted management APIs being accessible without a user login, potentially exposing configuration meta-data. NVD-CWE-Other
CVE-2021-20050 2024-11-21 14:45 2021-12-23 Show GitHub Exploit DB Packet Storm