Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 10, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
230701 8.5 危険 socialgroupie - Social Groupie の Photos/create_album.php における任意のコードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2008-6367 2012-12-20 19:10 2009-03-2 Show GitHub Exploit DB Packet Storm
230702 4.3 警告 phpf1 - Max's Guestbook の index.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-6359 2012-12-20 19:10 2009-03-2 Show GitHub Exploit DB Packet Storm
230703 7.5 危険 socialgroupie - Social Groupie の group_index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6358 2012-12-20 19:10 2009-03-2 Show GitHub Exploit DB Packet Storm
230704 5 警告 the net guys - The Net Guys ASPired2Protect におけるユーザ名などを含むデータベースをダウンロードされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-6355 2012-12-20 19:10 2009-03-2 Show GitHub Exploit DB Packet Storm
230705 5 警告 the net guys - The Net Guys ASPired2poll におけるユーザ名などを含むデータベースをダウンロードされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-6354 2012-12-20 19:10 2009-03-2 Show GitHub Exploit DB Packet Storm
230706 7.5 危険 xpoze - Xpoze Pro の home.html における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6352 2012-12-20 19:10 2009-03-2 Show GitHub Exploit DB Packet Storm
230707 4.3 警告 turnkeyforms - TurnkeyForms Local Classifieds の listtest.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-6351 2012-12-20 19:10 2009-03-2 Show GitHub Exploit DB Packet Storm
230708 7.5 危険 turnkeyforms - TurnkeyForms Local Classifieds の listtest.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6350 2012-12-20 19:10 2009-03-2 Show GitHub Exploit DB Packet Storm
230709 7.5 危険 turnkeyforms - TurnkeyForms Business Survey Pro の survey_results_text.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6349 2012-12-20 19:10 2009-03-2 Show GitHub Exploit DB Packet Storm
230710 4.3 警告 ticklespace - Drupal 用の Answers モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-6413 2012-12-20 19:10 2008-09-18 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 10, 2026, 5 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
199721 7.5 HIGH
Network
gryphonconnect gryphon_tower_firmware Gryphon Tower routers contain an unprotected openvpn configuration file which can grant attackers access to the Gryphon homebound VPN network which exposes the LAN interfaces of other users' devices … CWE-287
Improper Authentication
CVE-2021-20145 2024-11-21 14:46 2021-12-10 Show GitHub Exploit DB Packet Storm
199722 8.8 HIGH
Adjacent
gryphonconnect gryphon_tower_firmware An unauthenticated command injection vulnerability exists in the parameters of operation 49 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same n… CWE-78
OS Command 
CVE-2021-20144 2024-11-21 14:46 2021-12-10 Show GitHub Exploit DB Packet Storm
199723 8.8 HIGH
Adjacent
gryphonconnect gryphon_tower_firmware An unauthenticated command injection vulnerability exists in the parameters of operation 48 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same n… CWE-78
OS Command 
CVE-2021-20143 2024-11-21 14:46 2021-12-10 Show GitHub Exploit DB Packet Storm
199724 8.8 HIGH
Adjacent
gryphonconnect gryphon_tower_firmware An unauthenticated command injection vulnerability exists in the parameters of operation 41 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same n… CWE-78
OS Command 
CVE-2021-20142 2024-11-21 14:46 2021-12-10 Show GitHub Exploit DB Packet Storm
199725 8.8 HIGH
Adjacent
gryphonconnect gryphon_tower_firmware An unauthenticated command injection vulnerability exists in the parameters of operation 32 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same n… CWE-78
OS Command 
CVE-2021-20141 2024-11-21 14:46 2021-12-10 Show GitHub Exploit DB Packet Storm
199726 8.8 HIGH
Adjacent
gryphonconnect gryphon_tower_firmware An unauthenticated command injection vulnerability exists in the parameters of operation 10 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same n… CWE-78
OS Command 
CVE-2021-20140 2024-11-21 14:46 2021-12-10 Show GitHub Exploit DB Packet Storm
199727 6.1 MEDIUM
Network
ibm
netapp
cognos_analytics
oncommand_insight
IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality… CWE-79
Cross-site Scripting
CVE-2021-20493 2024-11-21 14:46 2021-12-4 Show GitHub Exploit DB Packet Storm
199728 7.5 HIGH
Network
ibm
netapp
cognos_analytics
oncommand_insight
IBM Cognos Analytics 11.1.7 and 11.2.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 196339. CWE-521
Weak Password Requirements 
CVE-2021-20470 2024-11-21 14:46 2021-12-4 Show GitHub Exploit DB Packet Storm
199729 7.5 HIGH
Network
ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.3 and 7.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 196074. CWE-326
Inadequate Encryption Strength
CVE-2021-20400 2024-11-21 14:46 2021-12-2 Show GitHub Exploit DB Packet Storm
199730 7.5 HIGH
Network
mitsubishi melsec_iq-r_r00_cpu_firmware
melsec_iq-r_r01_cpu_firmware
melsec_iq-r_r02_cpu_firmware
melsec_iq-r_r04_cpu_firmware
melsec_iq-r_r08_cpu_firmware
melsec_iq-r_r120_cpu_firmware
melsec…
Improper Input Validation vulnerability in Mitsubishi Electric MELSEC iQ-R Series R00/01/02CPU, MELSEC iQ-R Series R04/08/16/32/120(EN)CPU, MELSEC iQ-R Series R08/16/32/120SFCPU, MELSEC iQ-R Series R… CWE-20
 Improper Input Validation 
CVE-2021-20611 2024-11-21 14:46 2021-12-2 Show GitHub Exploit DB Packet Storm