Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 15, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
230841 4.3 警告 レッドハット - C2Net Stronghold におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-1349 2012-12-20 19:10 2009-04-21 Show GitHub Exploit DB Packet Storm
230842 6 警告 TWiki - TWiki におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2009-1339 2012-12-20 19:10 2009-04-5 Show GitHub Exploit DB Packet Storm
230843 5 警告 サン・マイクロシステムズ - Sun Java System Directory Server および Enterprise Edition の Online Help 機能におけるファイルの一部のコンテンツを取得される脆弱性 CWE-noinfo
情報不足
CVE-2009-1332 2012-12-20 19:10 2009-04-15 Show GitHub Exploit DB Packet Storm
230844 7.5 危険 webfileexplorer - Web File Explorer の body.asp における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-1323 2012-12-20 19:10 2009-04-17 Show GitHub Exploit DB Packet Storm
230845 4.3 警告 zazzle - Zazzle Store Builder の include/zstore.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-1320 2012-12-20 19:10 2009-04-17 Show GitHub Exploit DB Packet Storm
230846 10 危険 webfileexplorer - Web File Explorer の body.asp における任意のファイルを作成される脆弱性 CWE-noinfo
情報不足
CVE-2009-1314 2012-12-20 19:10 2009-04-16 Show GitHub Exploit DB Packet Storm
230847 5 警告 Rapid Leech - Rapidleech の upload.php における絶対パストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2009-1089 2012-12-20 19:10 2009-03-25 Show GitHub Exploit DB Packet Storm
230848 9.3 危険 pplive - PPLive の PPLive.exe における任意のコードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2009-1087 2012-12-20 19:10 2009-03-25 Show GitHub Exploit DB Packet Storm
230849 5 警告 Piwik - Piwik における API 鍵を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2009-1085 2012-12-20 19:10 2009-03-25 Show GitHub Exploit DB Packet Storm
230850 6.4 警告 サン・マイクロシステムズ - Sun Java System IdM における脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2009-1084 2012-12-20 19:10 2009-03-19 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 16, 2026, 4:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
209031 9.8 CRITICAL
Network
inxedu inxedu SQL Injection in com/inxedu/OS/edu/controller/letter/AdminMsgSystemController in Inxedu v2.0.6 via the ids parameter to admin/letter/delsystem. CWE-89
SQL Injection
CVE-2020-35430 2024-11-21 14:27 2021-04-30 Show GitHub Exploit DB Packet Storm
209032 5.4 MEDIUM
Network
unisys data_exchange_management_studio Unisys Data Exchange Management Studio through 5.0.34 doesn't sanitize the input to a HTML document field. This could be used for an XSS attack. CWE-79
Cross-site Scripting
CVE-2020-35542 2024-11-21 14:27 2021-04-27 Show GitHub Exploit DB Packet Storm
209033 9.8 CRITICAL
Network
wondercms wondercms A remote code execution vulnerability in the installUpdateThemePluginAction function in index.php in WonderCMS 3.1.3, allows remote attackers to upload a custom plugin which can contain arbitrary cod… CWE-78
OS Command 
CVE-2020-35314 2024-11-21 14:27 2021-04-21 Show GitHub Exploit DB Packet Storm
209034 9.8 CRITICAL
Network
wondercms wondercms A server-side request forgery (SSRF) vulnerability in the addCustomThemePluginRepository function in index.php in WonderCMS 3.1.3 allows remote attackers to execute arbitrary code via a crafted URL t… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2020-35313 2024-11-21 14:27 2021-04-21 Show GitHub Exploit DB Packet Storm
209035 5.4 MEDIUM
Network
monicahq monica Cross Site Scripting (XSS) in Monica before 2.19.1 via the journal page. CWE-79
Cross-site Scripting
CVE-2020-35660 2024-11-21 14:27 2021-04-15 Show GitHub Exploit DB Packet Storm
209036 6.1 MEDIUM
Network
group-office group_office Cross Site Scripting (XSS) in Group Office CRM 6.4.196 via the SET_LANGUAGE parameter. CWE-79
Cross-site Scripting
CVE-2020-35419 2024-11-21 14:27 2021-04-15 Show GitHub Exploit DB Packet Storm
209037 5.4 MEDIUM
Network
group-office group_office Cross Site Scripting (XSS) in the contact page of Group Office CRM 6.4.196 by uploading a crafted svg file. CWE-79
Cross-site Scripting
CVE-2020-35418 2024-11-21 14:27 2021-04-15 Show GitHub Exploit DB Packet Storm
209038 9.8 CRITICAL
Network
conquest_dicom_server_project conquest_dicom_server CONQUEST DICOM SERVER before 1.5.0 has a code execution vulnerability which can be exploited by attackers to execute malicious code. NVD-CWE-noinfo
CVE-2020-35308 2024-11-21 14:27 2021-04-1 Show GitHub Exploit DB Packet Storm
209039 5.3 MEDIUM
Network
redhat 389_directory_server
enterprise_linux
directory_server
When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an unauthenticated attacker to check the existence of a… CWE-203
 Information Exposure Through Discrepancy
CVE-2020-35518 2024-11-21 14:27 2021-03-27 Show GitHub Exploit DB Packet Storm
209040 4.5 MEDIUM
Local
linux
redhat
netapp
linux_kernel
enterprise_linux
a700s_firmware
brocade_fabric_operating_system_firmware
fas8300_firmware
fas8700_firmware
aff_a400_firmware
h300s_firmware
h500s_firmware
h700…
A flaw possibility of race condition and incorrect initialization of the process id was found in the Linux kernel child/parent process identification handling while filtering signal handlers. A local… - CVE-2020-35508 2024-11-21 14:27 2021-03-27 Show GitHub Exploit DB Packet Storm