Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 31, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
230761 5 警告 seagullproject.org - Seagull の optimizer.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-0465 2012-12-20 18:34 2008-01-25 Show GitHub Exploit DB Packet Storm
230762 6.8 警告 slaed - SLAED CMS の function/sources.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-0458 2012-12-20 18:34 2008-01-25 Show GitHub Exploit DB Packet Storm
230763 10 危険 シマンテック - Symantec Backup Exec System Recovery Manager で使用される Symantec LiveState Apache Tomcat サーバで稼動している FileUpload クラスにおける任意の JSP ファイルをアップロードされる脆弱性 CWE-20
不適切な入力確認
CVE-2008-0457 2012-12-20 18:34 2008-02-4 Show GitHub Exploit DB Packet Storm
230764 5 警告 siteman - Siteman の articles.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-0452 2012-12-20 18:34 2008-01-24 Show GitHub Exploit DB Packet Storm
230765 7.5 危険 rocksalt international - VP-ASP Shopping Cart の paypalresult.asp における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0449 2012-12-20 18:34 2008-01-24 Show GitHub Exploit DB Packet Storm
230766 7.5 危険 small axe solutions - Small Axe Weblog の inc/linkbar.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2008-0442 2012-12-20 18:34 2008-01-24 Show GitHub Exploit DB Packet Storm
230767 6.8 警告 東芝 - Toshiba Surveillance RecordSend ActiveX コントロールにおけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-0399 2012-12-20 18:34 2008-01-23 Show GitHub Exploit DB Packet Storm
230768 6.8 警告 WordPress.org - WordPress 用の WP-Forum プラグインにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0388 2012-12-20 18:34 2008-01-22 Show GitHub Exploit DB Packet Storm
230769 7.5 危険 urulu - Urulu の server/widgetallocator.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0385 2012-12-20 18:34 2008-02-29 Show GitHub Exploit DB Packet Storm
230770 6.8 警告 softpedia - Small Axe Weblog の inc/linkbar.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2008-0376 2012-12-20 18:34 2008-01-22 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 31, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
214091 5.5 MEDIUM
Local
mi miui The application in the mobile phone can unauthorized access to the list of running processes in the mobile phone, Xiaomi Mobile Phone MIUI < 2021.01.26. CWE-863
 Incorrect Authorization
CVE-2020-14106 2024-11-21 14:02 2021-04-9 Show GitHub Exploit DB Packet Storm
214092 5.5 MEDIUM
Local
mi miui The application in the mobile phone can read the SNO information of the device, Xiaomi 10 MIUI < 2020.01.15. NVD-CWE-noinfo
CVE-2020-14103 2024-11-21 14:02 2021-04-9 Show GitHub Exploit DB Packet Storm
214093 8.1 HIGH
Network
mi ax3600_firmware A RACE CONDITION on XQBACKUP causes a decompression path error on Xiaomi router AX3600 with ROM version =1.0.50. CWE-362
Race Condition
CVE-2020-14104 2024-11-21 14:02 2021-04-9 Show GitHub Exploit DB Packet Storm
214094 7.5 HIGH
Network
mi ax1800_firmware
rm1800_firmware
On Xiaomi router AX1800 rom version < 1.0.336 and RM1800 root version < 1.0.26, the encryption scheme for a user's backup files uses hard-coded keys, which can expose sensitive information such as a … CWE-798
 Use of Hard-coded Credentials
CVE-2020-14099 2024-11-21 14:02 2021-04-9 Show GitHub Exploit DB Packet Storm
214095 9.8 CRITICAL
Network
soplanning soplanning SOPlanning before 1.47 has Incorrect Access Control because certain secret key information, and the related authentication algorithm, is public. The key for admin is hardcoded in the installation cod… CWE-798
 Use of Hard-coded Credentials
CVE-2020-13963 2024-11-21 14:02 2021-03-22 Show GitHub Exploit DB Packet Storm
214096 7.5 HIGH
Network
apache ambari In Apache Ambari versions 2.6.2.2 and earlier, malicious users can construct file names for directory traversal and traverse to other directories to download files. CWE-22
Path Traversal
CVE-2020-13924 2024-11-21 14:02 2021-03-17 Show GitHub Exploit DB Packet Storm
214097 6.1 MEDIUM
Network
apache
debian
velocity_tools
debian_linux
The default error page for VelocityView in Apache Velocity Tools prior to 3.1 reflects back the vm file that was entered as part of the URL. An attacker can set an XSS payload file as this vm file in… CWE-79
Cross-site Scripting
CVE-2020-13959 2024-11-21 14:02 2021-03-10 Show GitHub Exploit DB Packet Storm
214098 8.8 HIGH
Network
apache
debian
oracle
velocity_engine
wss4j
debian_linux
retail_order_broker
banking_platform
communications_network_integrity
banking_enterprise_default_management
banking_party_management
utiliti…
An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This appl… NVD-CWE-noinfo
CVE-2020-13936 2024-11-21 14:02 2021-03-10 Show GitHub Exploit DB Packet Storm
214099 7.5 HIGH
Network
apache
oracle
thrift
hive
communications_cloud_native_core_network_slice_selection_function
communications_cloud_native_core_policy
In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. CWE-400
 Uncontrolled Resource Consumption
CVE-2020-13949 2024-11-21 14:02 2021-02-13 Show GitHub Exploit DB Packet Storm
214100 6.1 MEDIUM
Network
apache
oracle
activemq
communications_session_route_manager
communications_session_report_manager
An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the message.jsp page of Apache ActiveMQ versions 5.15.12 through 5.16.0. CWE-79
Cross-site Scripting
CVE-2020-13947 2024-11-21 14:02 2021-02-9 Show GitHub Exploit DB Packet Storm