Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 29, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
230461 7.5 危険 pixel motion - Blog Pixel Motion の admin/sauvBase.php における重要な情報を含む blogPM.sql ファイルの結果を取得される脆弱性 CWE-287
不適切な認証
CVE-2008-1868 2012-12-20 18:52 2008-04-17 Show GitHub Exploit DB Packet Storm
230462 7.5 危険 pixel motion - Blog Pixel Motion における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-1867 2012-12-20 18:52 2008-04-17 Show GitHub Exploit DB Packet Storm
230463 9 危険 pixel motion - Blog Pixel Motion の admin/modif_config.php における任意の PHP スクリプトをアップロードされる脆弱性 CWE-94
コード・インジェクション
CVE-2008-1866 2012-12-20 18:52 2008-04-17 Show GitHub Exploit DB Packet Storm
230464 7.5 危険 prozilla - Prozilla Freelancers の project.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-1864 2012-12-20 18:52 2008-04-17 Show GitHub Exploit DB Packet Storm
230465 7.5 危険 prozilla - Prozilla Cheat Script の view_reviews.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-1863 2012-12-20 18:52 2008-04-17 Show GitHub Exploit DB Packet Storm
230466 5 警告 SmarterTools Inc. - SmarterMail の SmarterMail Web Server におけるサービス運用妨害 (DoS) の脆弱性 CWE-DesignError
CVE-2008-1854 2012-12-20 18:52 2008-04-16 Show GitHub Exploit DB Packet Storm
230467 4.3 警告 SAP - SAP NetWeaver のデフォルト設定におけるクロスサイトスクリプティング攻撃を実行される脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-1846 2012-12-20 18:52 2008-04-16 Show GitHub Exploit DB Packet Storm
230468 7.5 危険 w2b - W2B phpHotResources の cat.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-1844 2012-12-20 18:52 2008-04-16 Show GitHub Exploit DB Packet Storm
230469 7.5 危険 w2b - W2B DatingClub の browse.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-1843 2012-12-20 18:52 2008-04-16 Show GitHub Exploit DB Packet Storm
230470 4.3 警告 work system e-commerce - WORK system e-commerce の module/main.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-1839 2012-12-20 18:52 2008-04-16 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 29, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
209551 5.4 MEDIUM
Network
naviwebs navigatecms NavigateCMS 2.9 is affected by Cross Site Scripting (XSS) on module "Configuration." CWE-79
Cross-site Scripting
CVE-2020-23655 2024-11-21 14:13 2020-08-27 Show GitHub Exploit DB Packet Storm
209552 5.4 MEDIUM
Network
naviwebs navigatecms NavigateCMS 2.9 is affected by Cross Site Scripting (XSS) via the module "Shop." CWE-79
Cross-site Scripting
CVE-2020-23654 2024-11-21 14:13 2020-08-27 Show GitHub Exploit DB Packet Storm
209553 6.5 MEDIUM
Network
sysax multi_server When uploading a file in Sysax Multi Server 6.90, an authenticated user can modify the filename="" parameter in the uploadfile_name1.htm form to a length of 368 or more bytes. This will create a buff… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2020-23574 2024-11-21 14:13 2020-08-20 Show GitHub Exploit DB Packet Storm
209554 7.8 HIGH
Local
pnotes.net_project pnotes.net A File Upload Vulnerability in PNotes - Andrey Gruber PNotes.NET v3.8.1.2 allows a local attacker to execute arbitrary code via the Miscellaneous " External Programs by uploading the malicious .exe f… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2020-22721 2024-11-21 14:13 2020-08-15 Show GitHub Exploit DB Packet Storm
209555 7.8 HIGH
Local
rapidscada rapid_scada Rapid Software LLC Rapid SCADA 5.8.0 is affected by a local privilege escalation vulnerability in the ScadaAgentSvc.exe executable file. An attacker can obtain admin privileges by placing a malicious… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2020-22722 2024-11-21 14:13 2020-08-15 Show GitHub Exploit DB Packet Storm
209556 7.8 HIGH
Local
ogg_video_tools_project ogg_video_tools Buffer Overflow vulnerability in ExtractorInformation function in streamExtractor.cpp in oggvideotools 0.9.1 allows remaote attackers to run arbitrary code via opening of crafted ogg file. CWE-787
 Out-of-bounds Write
CVE-2020-21724 2024-11-21 14:12 2023-08-23 Show GitHub Exploit DB Packet Storm
209557 7.8 HIGH
Local
freeimage_project freeimage Buffer Overflow vulnerability in function LoadPixelDataRLE8 in PluginBMP.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary code and cause other impacts via crafted image file. CWE-120
Classic Buffer Overflow
CVE-2020-21427 2024-11-21 14:12 2023-08-23 Show GitHub Exploit DB Packet Storm
209558 7.5 HIGH
Network
openvpn openvpn Control Channel in OpenVPN 2.4.7 and earlier allows remote attackers to cause a denial of service via crafted reset packet. NVD-CWE-noinfo
CVE-2020-20813 2024-11-21 14:12 2023-08-23 Show GitHub Exploit DB Packet Storm
209559 7.5 HIGH
Network
phpok phpok SQL injection vulnerability in PHPOK v.5.4. allows a remote attacker to obtain sensitive information via the _userlist function in framerwork/phpok_call.php file. CWE-89
SQL Injection
CVE-2020-21486 2024-11-21 14:12 2023-06-21 Show GitHub Exploit DB Packet Storm
209560 6.1 MEDIUM
Network
taogogo taocms Cross Site Scripting vulnerability in taogogo taoCMS v.2.5 beta5.1 allows remote attacker to execute arbitrary code via the name field in admin.php. CWE-79
Cross-site Scripting
CVE-2020-20725 2024-11-21 14:12 2023-06-21 Show GitHub Exploit DB Packet Storm