Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 12, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
231981 7.5 危険 PreProject.com - Pre Shopping Mall の emall/search.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2114 2012-12-20 18:52 2008-05-8 Show GitHub Exploit DB Packet Storm
231982 7.5 危険 phpeasydata - PHPEasyData の annuaire.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2113 2012-12-20 18:52 2008-05-8 Show GitHub Exploit DB Packet Storm
231983 5 警告 vicftps - VicFTPS におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2008-2031 2012-12-20 18:52 2008-04-30 Show GitHub Exploit DB Packet Storm
231984 5.8 警告 RSAセキュリティ - Web の IIS 用の RSA Authentication Agent におけるオープンリダイレクトの脆弱性 CWE-200
情報漏えい
CVE-2008-2027 2012-12-20 18:52 2008-04-30 Show GitHub Exploit DB Packet Storm
231985 4.3 警告 RSAセキュリティ - RSA Authentication Agent の WebID/IISWebAgentIF.dll におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-2026 2012-12-20 18:52 2008-04-30 Show GitHub Exploit DB Packet Storm
231986 7.5 危険 Simple Machines - SMF における CAPTCHA のテストを通過される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-2019 2012-12-20 18:52 2008-04-29 Show GitHub Exploit DB Packet Storm
231987 4 警告 phpizabi - PHPizabi の template.class.php の AssignUser 関数における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2008-2018 2012-12-20 18:52 2008-04-29 Show GitHub Exploit DB Packet Storm
231988 9.3 危険 watchfire - WatchFire AppScan の特定の ActiveX コントロールにおける絶対パストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-2015 2012-12-20 18:52 2008-04-29 Show GitHub Exploit DB Packet Storm
231989 6.8 警告 pnflashgames - PostNuke 用の pnFlashGames モジュールの index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2013 2012-12-20 18:52 2008-04-29 Show GitHub Exploit DB Packet Storm
231990 7.5 危険 postnuke software foundation - PostNuke 用の PostSchedule モジュールにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2012 2012-12-20 18:52 2008-04-29 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 12, 2026, 4:20 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
199451 9.8 CRITICAL
Network
zte zxhn_h168n_firmware A ZTE product is impacted by improper access control vulnerability. The attacker could exploit this vulnerability to access CLI by brute force attacks.This affects: ZXHN H168N V3.5.0_TY.T6 NVD-CWE-Other
CVE-2021-21730 2024-11-21 14:48 2021-04-14 Show GitHub Exploit DB Packet Storm
199452 6.5 MEDIUM
Network
zte zxhn_h168n_firmware
zxhn_h108n_firmware
Some ZTE products have CSRF vulnerability. Because some pages lack CSRF random value verification, attackers could perform illegal authorization operations by constructing messages.This affects: ZXHN… CWE-352
CWE-330
 Origin Validation Error
 Use of Insufficiently Random Values
CVE-2021-21729 2024-11-21 14:48 2021-04-14 Show GitHub Exploit DB Packet Storm
199453 6.5 MEDIUM
Network
matrix
fedoraproject
synapse
fedora
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.28.0 Synaps… CWE-20
 Improper Input Validation 
CVE-2021-21393 2024-11-21 14:48 2021-04-13 Show GitHub Exploit DB Packet Storm
199454 6.3 MEDIUM
Network
matrix
fedoraproject
synapse
fedora
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.28.0 reques… CWE-601
Open Redirect
CVE-2021-21392 2024-11-21 14:48 2021-04-13 Show GitHub Exploit DB Packet Storm
199455 7.8 HIGH
Local
dell peripheral_manager Dell Peripheral Manager 1.3.1 or greater contains remediation for a local privilege escalation vulnerability that could be potentially exploited to gain arbitrary code execution on the system with pr… CWE-427
 Uncontrolled Search Path Element
CVE-2021-21545 2024-11-21 14:48 2021-04-13 Show GitHub Exploit DB Packet Storm
199456 9.8 CRITICAL
Network
dell storage_resource_manager
storage_monitoring_and_reporting
Dell SRM versions prior to 4.5.0.1 and Dell SMR versions prior to 4.5.0.1 contain an Untrusted Deserialization Vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerabil… CWE-502
 Deserialization of Untrusted Data
CVE-2021-21524 2024-11-21 14:48 2021-04-13 Show GitHub Exploit DB Packet Storm
199457 6.5 MEDIUM
Network
matrix
fedoraproject
synapse
fedora
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.28.0 Synaps… CWE-20
 Improper Input Validation 
CVE-2021-21394 2024-11-21 14:48 2021-04-13 Show GitHub Exploit DB Packet Storm
199458 5.3 MEDIUM
Network
zte zxa10_c300m_firmware A ZTE product has a configuration error vulnerability. Because a certain port is open by default, an attacker can consume system processing resources by flushing a large number of packets to the port… CWE-400
 Uncontrolled Resource Consumption
CVE-2021-21728 2024-11-21 14:48 2021-04-10 Show GitHub Exploit DB Packet Storm
199459 8.8 HIGH
Network
demon1a discord-recon Discord Recon Server is a bot that allows you to do your reconnaissance process from your Discord. Remote code execution in version 0.0.1 would allow remote users to execute commands on the server re… CWE-78
OS Command 
CVE-2021-21433 2024-11-21 14:48 2021-04-10 Show GitHub Exploit DB Packet Storm
199460 6.5 MEDIUM
Network
go-vela vela Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. An authentication mechanism added in version 0.7.0 enables some malicious user to obtain secrets… CWE-862
 Missing Authorization
CVE-2021-21432 2024-11-21 14:48 2021-04-10 Show GitHub Exploit DB Packet Storm