Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 10, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
230471 7.8 危険 Pligg - Pligg におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-7090 2012-12-20 19:10 2009-08-26 Show GitHub Exploit DB Packet Storm
230472 4.3 警告 Pligg - Pligg におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-7089 2012-12-20 19:10 2009-08-26 Show GitHub Exploit DB Packet Storm
230473 7.5 危険 thehockeystop - TheHockeyStop HockeySTATS Online における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-7085 2012-12-20 19:10 2009-08-26 Show GitHub Exploit DB Packet Storm
230474 7.5 危険 revou - ReVou Micro Blogging Twitter クローンにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-7083 2012-12-20 19:10 2009-08-25 Show GitHub Exploit DB Packet Storm
230475 4.3 警告 Simple Machines
phpraider
- Simple Machines phpRaider の不特定のコンポーネントにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-7035 2012-12-20 19:10 2009-08-24 Show GitHub Exploit DB Packet Storm
230476 7.5 危険 tigran abrahamyan - PHPEcho CMS の kernel/smarty/Smarty.class.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2008-7034 2012-12-20 19:10 2009-08-24 Show GitHub Exploit DB Packet Storm
230477 7.5 危険 site2nite - Site2Nite Real Estate Web における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-7030 2012-12-20 19:10 2009-08-24 Show GitHub Exploit DB Packet Storm
230478 10 危険 skalinks - Skalfa Software SkaLinks Exchange Script における管理者を追加される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-7010 2012-12-20 19:10 2009-08-19 Show GitHub Exploit DB Packet Storm
230479 7.5 危険 phpversion - Free PHP VX Guestbook における管理者アクセス権を取得される脆弱性 CWE-287
不適切な認証
CVE-2008-7007 2012-12-20 19:10 2009-08-19 Show GitHub Exploit DB Packet Storm
230480 5 警告 phpversion - Free PHP VX Guestbook におけるデータベースのバックアップをダウンロードされる脆弱性 CWE-287
不適切な認証
CVE-2008-7006 2012-12-20 19:10 2009-08-19 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 11, 2026, 5:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
196601 7.8 HIGH
Local
samsung notes Using unsafe PendingIntent in Samsung Notes prior to version 4.2.00.22 allows local attackers unauthorized action without permission via hijacking the PendingIntent. CWE-276
Incorrect Default Permissions 
CVE-2021-25355 2024-11-21 14:54 2021-03-26 Show GitHub Exploit DB Packet Storm
196602 5.3 MEDIUM
Local
samsung internet Improper input check in Samsung Internet prior to version 13.2.1.46 allows attackers to launch non-exported activity in Samsung Browser via malicious deeplink. NVD-CWE-Other
CVE-2021-25354 2024-11-21 14:54 2021-03-26 Show GitHub Exploit DB Packet Storm
196603 7.1 HIGH
Local
samsung galaxy_themes Using empty PendingIntent in Galaxy Themes prior to version 5.2.00.1215 allows local attackers to read/write private file directories of Galaxy Themes application without permission via hijacking the… NVD-CWE-noinfo
CVE-2021-25353 2024-11-21 14:54 2021-03-26 Show GitHub Exploit DB Packet Storm
196604 7.8 HIGH
Local
samsung bixby_voice Using PendingIntent with implicit intent in Bixby Voice prior to version 3.0.52.14 allows attackers to execute privileged action by hijacking and modifying the intent. CWE-668
 Exposure of Resource to Wrong Sphere
CVE-2021-25352 2024-11-21 14:54 2021-03-26 Show GitHub Exploit DB Packet Storm
196605 2.4 LOW
Physics
samsung account Improper Access Control in EmailValidationView in Samsung Account prior to version 10.7.0.7 and 12.1.1.3 allows physically proximate attackers to log out user account on device without user password. NVD-CWE-Other
CVE-2021-25351 2024-11-21 14:54 2021-03-26 Show GitHub Exploit DB Packet Storm
196606 3.9 LOW
Physics
samsung account Information Exposure vulnerability in Samsung Account prior to version 12.1.1.3 allows physically proximate attackers to access user information via log. CWE-532
 Inclusion of Sensitive Information in Log Files
CVE-2021-25350 2024-11-21 14:54 2021-03-26 Show GitHub Exploit DB Packet Storm
196607 7.8 HIGH
Local
samsung slow_motion_editor Using unsafe PendingIntent in Slow Motion Editor prior to version 3.5.18.5 allows local attackers unauthorized action without permission via hijacking the PendingIntent. NVD-CWE-Other
CVE-2021-25349 2024-11-21 14:54 2021-03-26 Show GitHub Exploit DB Packet Storm
196608 8.8 HIGH
Network
sophos connect A malicious website could execute code remotely in Sophos Connect Client before version 2.1. NVD-CWE-noinfo
CVE-2021-25265 2024-11-21 14:54 2021-03-23 Show GitHub Exploit DB Packet Storm
196609 4.8 MEDIUM
Network
ftapi ftapi FTAPI 4.0 through 4.10 allows XSS via an SVG document to the Background Image upload feature in the Submit Box Template Editor. CWE-79
Cross-site Scripting
CVE-2021-25278 2024-11-21 14:54 2021-03-20 Show GitHub Exploit DB Packet Storm
196610 6.1 MEDIUM
Network
ftapi ftapi FTAPI 4.0 - 4.10 allows XSS via a crafted filename to the alternative text hover box in the file submission component. CWE-79
Cross-site Scripting
CVE-2021-25277 2024-11-21 14:54 2021-03-20 Show GitHub Exploit DB Packet Storm