Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 17, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
231731 7.5 危険 socialsitegenerator - Social Site Generator における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6419 2012-12-20 19:10 2009-03-6 Show GitHub Exploit DB Packet Storm
231732 7.5 危険 torrenttrader - TorrentTrader の scrape.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6418 2012-12-20 19:10 2009-03-6 Show GitHub Exploit DB Packet Storm
231733 10 危険 Youngzsoft - YoungZSoft CCProxy におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-6415 2012-12-20 19:10 2009-03-6 Show GitHub Exploit DB Packet Storm
231734 7.5 危険 vignette - Vignette Content Management における管理者権限を取得される脆弱性 CWE-noinfo
情報不足
CVE-2008-6412 2012-12-20 19:10 2009-03-6 Show GitHub Exploit DB Packet Storm
231735 4.3 警告 refbase - refbase におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-6400 2012-12-20 19:10 2009-03-5 Show GitHub Exploit DB Packet Storm
231736 10 危険 psi-im - PSI Jabber クライアントにおける整数オーバーフローの脆弱性 CWE-189
数値処理の問題
CVE-2008-6393 2012-12-20 19:10 2009-03-3 Show GitHub Exploit DB Packet Storm
231737 4.3 警告 w3matter - W3matter RevSense の index.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-6385 2012-12-20 19:10 2009-03-2 Show GitHub Exploit DB Packet Storm
231738 7.5 危険 phpbb-seo - Multi SEO phpBB の include/global.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2008-6377 2012-12-20 19:10 2009-03-2 Show GitHub Exploit DB Packet Storm
231739 8.5 危険 socialgroupie - Social Groupie の Photos/create_album.php における任意のコードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2008-6367 2012-12-20 19:10 2009-03-2 Show GitHub Exploit DB Packet Storm
231740 4.3 警告 phpf1 - Max's Guestbook の index.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-6359 2012-12-20 19:10 2009-03-2 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 17, 2026, 4:19 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
210591 5.6 MEDIUM
Network
jenkins amazon_ec2 Jenkins Amazon EC2 Plugin 1.50.1 and earlier unconditionally accepts self-signed certificates and does not perform hostname validation, enabling man-in-the-middle attacks. CWE-295
Improper Certificate Validation 
CVE-2020-2187 2024-11-21 14:24 2020-05-6 Show GitHub Exploit DB Packet Storm
210592 4.3 MEDIUM
Network
jenkins amazon_ec2 A cross-site request forgery vulnerability in Jenkins Amazon EC2 Plugin 1.50.1 and earlier allows attackers to provision instances. CWE-352
 Origin Validation Error
CVE-2020-2186 2024-11-21 14:24 2020-05-6 Show GitHub Exploit DB Packet Storm
210593 5.6 MEDIUM
Network
jenkins amazon_ec2 Jenkins Amazon EC2 Plugin 1.50.1 and earlier does not validate SSH host keys when connecting agents, enabling man-in-the-middle attacks. NVD-CWE-Other
CVE-2020-2185 2024-11-21 14:24 2020-05-6 Show GitHub Exploit DB Packet Storm
210594 4.3 MEDIUM
Network
jenkins current_versions_systems A cross-site request forgery vulnerability in Jenkins CVS Plugin 2.15 and earlier allows attackers to create and manipulate tags, and to connect to an attacker-specified URL. CWE-352
 Origin Validation Error
CVE-2020-2184 2024-11-21 14:24 2020-05-6 Show GitHub Exploit DB Packet Storm
210595 6.5 MEDIUM
Network
jenkins copy_artifact Jenkins Copy Artifact Plugin 1.43.1 and earlier performs improper permission checks, allowing attackers to copy artifacts from jobs they have no permission to access. CWE-276
Incorrect Default Permissions 
CVE-2020-2183 2024-11-21 14:24 2020-05-6 Show GitHub Exploit DB Packet Storm
210596 4.3 MEDIUM
Network
jenkins credentials_binding Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets containing a `$` character in some circumstances. CWE-522
 Insufficiently Protected Credentials
CVE-2020-2182 2024-11-21 14:24 2020-05-6 Show GitHub Exploit DB Packet Storm
210597 6.5 MEDIUM
Network
jenkins credentials_binding Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets in the build log when the build contains no build steps. CWE-522
 Insufficiently Protected Credentials
CVE-2020-2181 2024-11-21 14:24 2020-05-6 Show GitHub Exploit DB Packet Storm
210598 8.8 HIGH
Network
jenkins amazon_web_services_serverless_application_model Jenkins AWS SAM Plugin 1.2.2 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability. CWE-502
 Deserialization of Untrusted Data
CVE-2020-2180 2024-11-21 14:24 2020-04-17 Show GitHub Exploit DB Packet Storm
210599 8.8 HIGH
Network
jenkins yaml_axis Jenkins Yaml Axis Plugin 0.2.0 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability. CWE-502
 Deserialization of Untrusted Data
CVE-2020-2179 2024-11-21 14:24 2020-04-17 Show GitHub Exploit DB Packet Storm
210600 7.1 HIGH
Network
jenkins parasoft_findings Jenkins Parasoft Findings Plugin 10.4.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. CWE-611
XXE
CVE-2020-2178 2024-11-21 14:24 2020-04-17 Show GitHub Exploit DB Packet Storm