Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 5, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
230501 7.5 危険 pozscripts - PozScripts GreenCart PHP Shopping Cart における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3585 2012-12-20 18:52 2008-08-11 Show GitHub Exploit DB Packet Storm
230502 4.3 警告 qsoft - Qsoft K-Links の index.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-3581 2012-12-20 18:52 2008-08-10 Show GitHub Exploit DB Packet Storm
230503 7.5 危険 qsoft - Qsoft K-Links における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3580 2012-12-20 18:52 2008-08-10 Show GitHub Exploit DB Packet Storm
230504 2.6 注意 Pluck CMS - Pluck におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-3574 2012-12-20 18:52 2008-08-10 Show GitHub Exploit DB Packet Storm
230505 5 警告 Pligg
PHPNUKE
- Pligg などの製品の CAPTCHA 実装における CAPTCHA テストを通過される脆弱性 CWE-189
CWE-264
CVE-2008-3573 2012-12-20 18:52 2008-08-10 Show GitHub Exploit DB Packet Storm
230506 4.3 警告 Pligg - Pligg の index.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-3572 2012-12-20 18:52 2008-08-10 Show GitHub Exploit DB Packet Storm
230507 7.8 危険 Xerox - Xerox Phaser におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2008-3571 2012-12-20 18:52 2008-08-10 Show GitHub Exploit DB Packet Storm
230508 7.5 危険 unak - UNAK-CMS の fckeditor/editor/filemanager/browser/default/connectors/php/connector.php における絶対パストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-3568 2012-12-20 18:52 2008-08-10 Show GitHub Exploit DB Packet Storm
230509 4.3 警告 ZoneO-soft - ZoneO-soft freeForum におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-3566 2012-12-20 18:52 2008-08-10 Show GitHub Exploit DB Packet Storm
230510 7.5 危険 Plogger Project - Plogger における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3563 2012-12-20 18:52 2008-07-29 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 5, 2026, 4:11 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
201361 7.8 HIGH
Local
huawei oxfordp-an10b_firmware Huawei smartphones OxfordP-AN10B with versions earlier than 10.0.1.169(C00E166R4P1) have an improper authentication vulnerability. The Application doesn't perform proper authentication when user perf… CWE-287
Improper Authentication
CVE-2020-9066 2024-11-21 14:39 2020-03-27 Show GitHub Exploit DB Packet Storm
201362 5.5 MEDIUM
Local
huawei taurus-al00b_firmware Huawei smart phone Taurus-AL00B with versions earlier than 10.0.0.203(C00E201R7P2) have a use-after-free (UAF) vulnerability. An authenticated, local attacker may perform specific operations to explo… CWE-416
 Use After Free
CVE-2020-9065 2024-11-21 14:39 2020-03-27 Show GitHub Exploit DB Packet Storm
201363 6.5 MEDIUM
Network
google closure_library A URL parsing issue in goog.uri of the Google Closure Library versions up to and including v20200224 allows an attacker to send malicious URLs to be parsed by the library and return the wrong authori… NVD-CWE-noinfo
CVE-2020-8910 2024-11-21 14:39 2020-03-26 Show GitHub Exploit DB Packet Storm
201364 6.1 MEDIUM
Network
dart dart_software_development_kit An improper HTML sanitization in Dart versions up to and including 2.7.1 and dev versions 2.8.0-dev.16.0, allows an attacker leveraging DOM Clobbering techniques to skip the sanitization and inject c… CWE-79
Cross-site Scripting
CVE-2020-8923 2024-11-21 14:39 2020-03-26 Show GitHub Exploit DB Packet Storm
201365 9.8 CRITICAL
Network
zend zendto lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta failed to properly check for equality when validating the session cookie, allowing an attacker to gain administrative access with a large number of r… CWE-754
 Improper Check for Unusual or Exceptional Conditions
CVE-2020-8986 2024-11-21 14:39 2020-03-25 Show GitHub Exploit DB Packet Storm
201366 8.8 HIGH
Network
zend zendto ZendTo prior to 5.22-2 Beta allowed reflected XSS and CSRF via the unlock.tpl unlock user functionality. CWE-352
CWE-79
 Origin Validation Error
Cross-site Scripting
CVE-2020-8985 2024-11-21 14:39 2020-03-25 Show GitHub Exploit DB Packet Storm
201367 7.5 HIGH
Network
zend zendto lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta allowed IP address spoofing via the X-Forwarded-For header. CWE-346
 Origin Validation Error
CVE-2020-8984 2024-11-21 14:39 2020-03-25 Show GitHub Exploit DB Packet Storm
201368 9.8 CRITICAL
Network
quest foglight_evolve This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest Foglight Evolve 9.0.0. Authentication is not required to exploit this vulnerability. The specif… CWE-798
 Use of Hard-coded Credentials
CVE-2020-8868 2024-11-21 14:39 2020-03-24 Show GitHub Exploit DB Packet Storm
201369 6.5 MEDIUM
Network
horde
debian
groupware
horde_form
debian_linux
This vulnerability allows remote attackers to create arbitrary files on affected installations of Horde Groupware Webmail Edition 5.2.22. Authentication is required to exploit this vulnerability. The… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2020-8866 2024-11-21 14:39 2020-03-24 Show GitHub Exploit DB Packet Storm
201370 6.3 MEDIUM
Network
horde
debian
groupware
debian_linux
This vulnerability allows remote attackers to execute local PHP files on affected installations of Horde Groupware Webmail Edition 5.2.22. Authentication is required to exploit this vulnerability. Th… CWE-22
Path Traversal
CVE-2020-8865 2024-11-21 14:39 2020-03-24 Show GitHub Exploit DB Packet Storm