Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 9, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
231981 4.3 警告 ZyXEL - ZyXEL P-330W ルータの Web 管理インターフェースにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-6729 2012-12-20 18:34 2009-09-10 Show GitHub Exploit DB Packet Storm
231982 6.8 警告 webportal - WebPortal CMS における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0142 2012-12-20 18:34 2008-01-8 Show GitHub Exploit DB Packet Storm
231983 7.5 危険 webportal - WebPortal CMS の actions.php における任意のアカウントへのアクセス権を取得される脆弱性 CWE-255
証明書・パスワード管理
CVE-2008-0141 2012-12-20 18:34 2008-01-8 Show GitHub Exploit DB Packet Storm
231984 6.4 警告 uebimiau - Uebimiau Webmail の error.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-0140 2012-12-20 18:34 2008-01-8 Show GitHub Exploit DB Packet Storm
231985 7.5 危険 snetworks - SNETWORKS PHP CLASSIFIEDS の config.inc.php における PHP リモートファイルインクルージョンの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0137 2012-12-20 18:34 2008-01-8 Show GitHub Exploit DB Packet Storm
231986 5 警告 snitz forums 2000 - Snitz Forums 2000 における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2008-0136 2012-12-20 18:34 2008-01-8 Show GitHub Exploit DB Packet Storm
231987 5 警告 snitz forums 2000 - Snitz Forums 2000 におけるデータベースをダウンロードされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-0135 2012-12-20 18:34 2008-01-8 Show GitHub Exploit DB Packet Storm
231988 4.3 警告 snitz forums 2000 - Snitz Forums 2000 の Forums/setup.asp におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-0134 2012-12-20 18:34 2008-01-8 Show GitHub Exploit DB Packet Storm
231989 7.5 危険 thomas perez - Tribisur における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0133 2012-12-20 18:34 2008-01-8 Show GitHub Exploit DB Packet Storm
231990 5 警告 pragma systems - Pragma FortressSSH におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2008-0132 2012-12-20 18:34 2008-01-8 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 9, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
211431 6.1 MEDIUM
Network
magento magento Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by a persistent XSS vulnerability that allows users to upload malicious JavaScript via the file upload component. This vulnerability coul… - CVE-2020-24408 2024-11-21 14:14 2020-10-17 Show GitHub Exploit DB Packet Storm
211432 5.5 MEDIUM
Local
qemu qemu An issue was discovered in QEMU through 5.1.0. An out-of-bounds memory access was found in the ATI VGA device implementation. This flaw occurs in the ati_2d_blt() routine in hw/display/ati_2d.c while… CWE-125
CWE-787
Out-of-bounds Read
 Out-of-bounds Write
CVE-2020-24352 2024-11-21 14:14 2020-10-16 Show GitHub Exploit DB Packet Storm
211433 6.1 MEDIUM
Network
unitedplanet intrexx Cross-site scripting (XSS) vulnerability in the search functionality in Intrexx before 9.4.0 allows remote attackers to inject arbitrary web script or HTML via the request parameter. CWE-79
Cross-site Scripting
CVE-2020-24188 2024-11-21 14:14 2020-10-15 Show GitHub Exploit DB Packet Storm
211434 6.1 MEDIUM
Network
iproom mmc\+ IProom MMC+ Server login page does not validate specific parameters properly. Attackers can use the vulnerability to redirect to any malicious site and steal the victim's login credentials. CWE-601
Open Redirect
CVE-2020-24551 2024-11-21 14:14 2020-10-14 Show GitHub Exploit DB Packet Storm
211435 6.1 MEDIUM
Network
hapifhir testpage_overlay Users of the HAPI FHIR Testpage Overlay 5.0.0 and below can use a specially crafted URL to exploit an XSS vulnerability in this module, allowing arbitrary JavaScript to be executed in the user's brow… CWE-79
Cross-site Scripting
CVE-2020-24301 2024-11-21 14:14 2020-10-8 Show GitHub Exploit DB Packet Storm
211436 7.5 HIGH
Network
peplink balance_20x_firmware
balance_310x_firmware
mbx_firmware
epx_firmware
sdx_firmware
balance_30_lte_firmware
balance_20_firmware
balance_30_firmware
balance_30_pro_firmware
ba…
Peplink Balance before 8.1.0rc1 allows an unauthenticated attacker to download PHP configuration files (/filemanager/php/connector.php) from Web Admin. NVD-CWE-noinfo
CVE-2020-24246 2024-11-21 14:14 2020-10-8 Show GitHub Exploit DB Packet Storm
211437 7.5 HIGH
Network
szuray iptv\/h.264_video_encoder_firmware
iptv\/h.265_video_encoder_firmware
An issue was discovered on URayTech IPTV/H.264/H.265 video encoders through 1.97. Attackers can send crafted unauthenticated HTTP requests to exploit path traversal and pattern-matching programming f… CWE-22
Path Traversal
CVE-2020-24219 2024-11-21 14:14 2020-10-6 Show GitHub Exploit DB Packet Storm
211438 9.8 CRITICAL
Network
szuray iptv\/h.264_video_encoder_firmware
iptv\/h.265_video_encoder_firmware
An issue was discovered on URayTech IPTV/H.264/H.265 video encoders through 1.97. Attackers can log in as root via the password that is hard-coded in the executable file. CWE-798
 Use of Hard-coded Credentials
CVE-2020-24218 2024-11-21 14:14 2020-10-6 Show GitHub Exploit DB Packet Storm
211439 9.8 CRITICAL
Network
szuray
jtechdigital
provideoinstruments
iptv\/h.264_video_encoder_firmware
iptv\/h.265_video_encoder_firmware
h.264_iptv_encoder_1080p\@60hz_firmware
vecaster-hd-h264_firmware
vecaster-hd-hevc_firmware
vecaster-4k-hevc_firmw…
An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. The file-upload endpoint does not enforce authentication. Attackers can send an unauthenticated HTTP… CWE-306
Missing Authentication for Critical Function
CVE-2020-24217 2024-11-21 14:14 2020-10-6 Show GitHub Exploit DB Packet Storm
211440 7.5 HIGH
Network
szuray
jtechdigital
provideoinstruments
iptv\/h.264_video_encoder_firmware
iptv\/h.265_video_encoder_firmware
h.264_iptv_encoder_1080p\@60hz_firmware
vecaster-hd-h264_firmware
vecaster-hd-hevc_firmware
vecaster-4k-hevc_firmw…
An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. When the administrator configures a secret URL for RTSP streaming, the stream is still available via… NVD-CWE-noinfo
CVE-2020-24216 2024-11-21 14:14 2020-10-6 Show GitHub Exploit DB Packet Storm