Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 16, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
231891 6.8 警告 planetluc - Planetluc RateMe におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2008-4899 2012-12-20 18:52 2008-11-3 Show GitHub Exploit DB Packet Storm
231892 4.3 警告 planetluc - planetluc RateMe におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-4898 2012-12-20 18:52 2008-11-3 Show GitHub Exploit DB Packet Storm
231893 7.5 危険 YourFreeWorld.com - YourFreeWorld Downline Builder の tr.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-4895 2012-12-20 18:52 2008-11-3 Show GitHub Exploit DB Packet Storm
231894 5.1 警告 Tribal Ltd. - Tribiq CMS の templates/mytribiqsite/tribal-GPL-1066/includes/header.inc.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-4894 2012-12-20 18:52 2008-11-3 Show GitHub Exploit DB Packet Storm
231895 2.6 注意 Tribal Ltd. - Tribiq CMS の templates/mytribiqsite/tribal-GPL-1066/includes/header.inc.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-4893 2012-12-20 18:52 2008-11-3 Show GitHub Exploit DB Packet Storm
231896 4.3 警告 planetluc - Planetluc MyGallery の gallery.inc.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-4892 2012-12-20 18:52 2008-11-3 Show GitHub Exploit DB Packet Storm
231897 4.3 警告 planetluc - Planetluc SignMe の signme.inc.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-4891 2012-12-20 18:52 2008-11-3 Show GitHub Exploit DB Packet Storm
231898 7.5 危険 YourFreeWorld.com - YourFreeWorld Shopping Cart Script の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-4886 2012-12-20 18:52 2008-11-3 Show GitHub Exploit DB Packet Storm
231899 7.5 危険 YourFreeWorld.com - YourFreeWorld Scrolling Text Ads Script の tr1.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-4885 2012-12-20 18:52 2008-11-3 Show GitHub Exploit DB Packet Storm
231900 7.5 危険 YourFreeWorld.com - YourFreeWorld Classifieds Hosting Script の tr.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-4884 2012-12-20 18:52 2008-11-3 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 16, 2026, 4:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
210531 4.3 MEDIUM
Network
libslirp_project
debian
fedoraproject
libslirp
debian_linux
fedora
slirp.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length. CWE-125
Out-of-bounds Read
CVE-2020-29130 2024-11-21 14:23 2020-11-27 Show GitHub Exploit DB Packet Storm
210532 4.3 MEDIUM
Network
libslirp_project
fedoraproject
debian
libslirp
fedora
debian_linux
ncsi.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length. CWE-125
Out-of-bounds Read
CVE-2020-29129 2024-11-21 14:23 2020-11-27 Show GitHub Exploit DB Packet Storm
210533 7.5 HIGH
Network
bigbluebutton bigbluebutton An issue was discovered in BigBlueButton through 2.2.29. When at attacker is able to view an account_activations/edit?token= URI, the attacker can create an approved user account associated with an e… CWE-200
Information Exposure
CVE-2020-29043 2024-11-21 14:23 2020-11-27 Show GitHub Exploit DB Packet Storm
210534 3.7 LOW
Network
bigbluebutton bigbluebutton An issue was discovered in BigBlueButton through 2.2.29. A brute-force attack may occur because an unlimited number of codes can be entered for a meeting that is protected by an access code. CWE-307
mproper Restriction of Excessive Authentication Attempts
CVE-2020-29042 2024-11-21 14:23 2020-11-27 Show GitHub Exploit DB Packet Storm
210535 9.8 CRITICAL
Network
petl_project petl petl before 1.68, in some configurations, allows resolution of entities in an XML document. CWE-91
Blind XPath Injection
CVE-2020-29128 2024-11-21 14:23 2020-11-26 Show GitHub Exploit DB Packet Storm
210536 8.8 HIGH
Network
x11vnc_project
fedoraproject
debian
x11vnc
fedora
debian_linux
scan.c in x11vnc 0.9.16 uses IPC_CREAT|0777 in shmget calls, which allows access by actors other than the current user. CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2020-29074 2024-11-21 14:23 2020-11-26 Show GitHub Exploit DB Packet Storm
210537 4.8 MEDIUM
Network
oscommerce oscommerce osCommerce 2.3.4.1 has XSS vulnerability via the authenticated user entering the XSS payload into the title section of newsletters. CWE-79
Cross-site Scripting
CVE-2020-29070 2024-11-21 14:23 2020-11-26 Show GitHub Exploit DB Packet Storm
210538 6.1 MEDIUM
Network
liquidfiles liquidfiles A Cross-Site Script Inclusion vulnerability was found on LiquidFiles before 3.3.19. This client-side attack requires user interaction (opening a link) and successful exploitation could lead to encryp… CWE-829
 Inclusion of Functionality from Untrusted Control Sphere
CVE-2020-29072 2024-11-21 14:23 2020-11-25 Show GitHub Exploit DB Packet Storm
210539 9.0 CRITICAL
Network
liquidfiles liquidfiles An XSS issue was found in the Shares feature of LiquidFiles before 3.3.19. The issue arises from the insecure rendering of HTML files uploaded to the platform as attachments, when the -htmlview URL i… CWE-79
Cross-site Scripting
CVE-2020-29071 2024-11-21 14:23 2020-11-25 Show GitHub Exploit DB Packet Storm
210540 5.5 MEDIUM
Local
modern_honey_network_project modern_honey_network _get_flag_ip_localdb in server/mhn/ui/utils.py in Modern Honey Network (MHN) through 2020-11-23 allows attackers to cause a denial-of-service via an IP address that is absent from a local geolocation… NVD-CWE-noinfo
CVE-2020-29069 2024-11-21 14:23 2020-11-25 Show GitHub Exploit DB Packet Storm