Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 30, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
230631 6.8 警告 quantum game library - Quantum Game Library における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2008-1069 2012-12-20 18:34 2008-02-28 Show GitHub Exploit DB Packet Storm
230632 6.8 警告 portail web php - Portail Web Php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2008-1068 2012-12-20 18:34 2008-02-28 Show GitHub Exploit DB Packet Storm
230633 6.8 警告 phpqladmin - phpQLAdmin における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2008-1067 2012-12-20 18:34 2008-02-28 Show GitHub Exploit DB Packet Storm
230634 7.5 危険 Smarty - S9Y などの製品で使用される Smarty における任意の PHP 関数を呼び出される脆弱性 CWE-20
不適切な入力確認
CVE-2008-1066 2012-12-20 18:34 2008-02-28 Show GitHub Exploit DB Packet Storm
230635 4.3 警告 WordPress.org - WordPress 用の Sniplets プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-1061 2012-12-20 18:34 2008-02-28 Show GitHub Exploit DB Packet Storm
230636 7.5 危険 WordPress.org - WordPress 用の Sniplets プラグインにおける任意の PHP コードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2008-1060 2012-12-20 18:34 2008-02-28 Show GitHub Exploit DB Packet Storm
230637 7.5 危険 WordPress.org - WordPress 用の Sniplets プラグインにおける PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2008-1059 2012-12-20 18:34 2008-02-28 Show GitHub Exploit DB Packet Storm
230638 6.9 警告 symark - Symark PowerBroker におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-1056 2012-12-20 18:34 2008-02-28 Show GitHub Exploit DB Packet Storm
230639 7.5 危険 PHPNUKE - PHP-Nuke 用の Kose_Yazilari モジュールにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-1053 2012-12-20 18:34 2008-02-27 Show GitHub Exploit DB Packet Storm
230640 6.8 警告 phpprofiles - phpProfiles の include/body_comm.inc.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2008-1051 2012-12-20 18:34 2008-02-27 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 31, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
200781 7.5 HIGH
Network
rubyonrails
debian
rails
debian_linux
A client side enforcement of server side security vulnerability exists in rails < 5.2.4.2 and rails < 6.0.3.1 ActiveStorage's S3 adapter that allows the Content-Length of a direct file upload to be m… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2020-8162 2024-11-21 14:38 2020-06-20 Show GitHub Exploit DB Packet Storm
200782 5.7 MEDIUM
Network
openmicroscopy omero.web OMERO.web before 5.6.3 optionally allows sensitive data elements (e.g., a session key) to be passed as URL query parameters. If an attacker tricks a user into clicking a malicious link in OMERO.web, … CWE-200
Information Exposure
CVE-2020-7932 2024-11-21 14:38 2020-06-18 Show GitHub Exploit DB Packet Storm
200783 6.5 MEDIUM
Network
open-xchange open-xchange_appsuite OX App Suite through 7.10.3 allows XXE attacks. CWE-611
XXE
CVE-2020-8541 2024-11-21 14:38 2020-06-16 Show GitHub Exploit DB Packet Storm
200784 6.7 MEDIUM
Local
synaptics smart_audio_uwp An unquoted search path vulnerability was reported in versions prior to 1.0.83.0 of the Synaptics Smart Audio UWP app associated with the DCHU audio drivers on Lenovo platforms that could allow an ad… CWE-428
 Unquoted Search Path or Element
CVE-2020-8337 2024-11-21 14:38 2020-06-10 Show GitHub Exploit DB Packet Storm
200785 6.8 MEDIUM
Physics
lenovo thinkpad_e14_firmware
thinkpad_e15_firmware
thinkpad_r14_firmware
thinkpad_s3_gen_2_firmware
thinkpad_e490s_firmware
thinkpad_s3_firmware
thinkpad_e490_firmware
thinkpad_e590_fir…
Lenovo implemented Intel CSME Anti-rollback ARB protections on some ThinkPad models to prevent roll back of CSME Firmware in flash. NVD-CWE-noinfo
CVE-2020-8336 2024-11-21 14:38 2020-06-10 Show GitHub Exploit DB Packet Storm
200786 6.8 MEDIUM
Physics
lenovo thinkpad_t495s_firmware
thinkpad_x395_firmware
thinkpad_t495_firmware
thinkpad_a485_firmware
thinkpad_a285_firmware
thinkpad_a475_firmware
thinkpad_a275_firmware
The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T495s, X395, T495, A485, A285, A475, A275 which may allow for unauthorized access. CWE-754
 Improper Check for Unusual or Exceptional Conditions
CVE-2020-8334 2024-11-21 14:38 2020-06-10 Show GitHub Exploit DB Packet Storm
200787 6.7 MEDIUM
Local
lenovo 330-14ast_firmware
330-15ast_firmware
330-17ast_firmware
340c-15api_firmware
340c-15ast_firmware
720s_touch-15ikb_firmware
720s-15ikb_firmware
730s-13iwl_firmware
c640-iml_fir…
A potential vulnerability in the SMI callback function used in the Legacy SD driver in some Lenovo ThinkPad, ThinkStation, and Lenovo Notebook models may allow arbitrary code execution. NVD-CWE-noinfo
CVE-2020-8323 2024-11-21 14:38 2020-06-10 Show GitHub Exploit DB Packet Storm
200788 6.7 MEDIUM
Local
lenovo 330-14ast_firmware
330-15ast_firmware
330-17ast_firmware
340c-15api_firmware
340c-15ast_firmware
720s_touch-15ikb_firmware
720s-15ikb_firmware
730s-13iwl_firmware
c640-iml_fir…
A potential vulnerability in the SMI callback function used in the Legacy USB driver in some Lenovo Notebook and ThinkStation models may allow arbitrary code execution. NVD-CWE-noinfo
CVE-2020-8322 2024-11-21 14:38 2020-06-10 Show GitHub Exploit DB Packet Storm
200789 6.7 MEDIUM
Local
lenovo 130-14ast_firmware
130-14ikb_firmware
130-15ast_firmware
130-15ikb_firmware
320c-15ikb_firmware
330-14igm_firmware
330-14ikb_firmware
330-14ikbr_firmware
330-15arr_firmware
A potential vulnerability in the SMI callback function used in the System Lock Preinstallation driver in some Lenovo Notebook and ThinkStation models may allow arbitrary code execution. NVD-CWE-noinfo
CVE-2020-8321 2024-11-21 14:38 2020-06-10 Show GitHub Exploit DB Packet Storm
200790 6.8 MEDIUM
Physics
lenovo thinkpad_11e_yoga_gen_6_firmware
thinkpad_11e_firmware
thinkpad_yoga_11e_3rd_gen_firmware
thinkpad_yoga_11e_4th_gen_firmware
thinkpad_yoga_11e_5th_gen_firmware
thinkpad_13_2nd_gen_firm…
An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege. CWE-269
 Improper Privilege Management
CVE-2020-8320 2024-11-21 14:38 2020-06-10 Show GitHub Exploit DB Packet Storm