Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 10, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
231991 7.5 危険 the sword project - The SWORD Project Diatheke の diatheke.pl における任意のコマンドを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2008-0932 2012-12-20 18:34 2008-02-25 Show GitHub Exploit DB Packet Storm
231992 6.3 警告 xwine - Debian GNU/Linux 上で稼動する XWine の w_export.c における任意のコマンドを実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-0931 2012-12-20 18:34 2008-03-3 Show GitHub Exploit DB Packet Storm
231993 7.5 危険 PHPNUKE - PHP-Nuke 用の Manuales モジュールにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0922 2012-12-20 18:34 2008-02-22 Show GitHub Exploit DB Packet Storm
231994 4.3 警告 tendenci - Tendenci CMS の search.asp におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-0793 2012-12-20 18:34 2008-02-14 Show GitHub Exploit DB Packet Storm
231995 4.3 警告 Simple Machines - SMF Shoutbox の sboxDB.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-0775 2012-12-20 18:34 2008-02-13 Show GitHub Exploit DB Packet Storm
231996 7.5 危険 site2nite - Site2Nite の default.asp における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0771 2012-12-20 18:34 2008-02-13 Show GitHub Exploit DB Packet Storm
231997 5 警告 SafeNet, Inc - SafeNet Sentinel Protection Server におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-0760 2012-12-20 18:34 2008-02-13 Show GitHub Exploit DB Packet Storm
231998 10 危険 サイベース - SQL Anywhere で使用されている Sybase MobiLink の mlsrv10.exe におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-0912 2012-12-20 18:34 2008-02-22 Show GitHub Exploit DB Packet Storm
231999 4.3 警告 schoolwires - Schoolwires Academic Portal の browse.asp におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-0909 2012-12-20 18:34 2008-02-22 Show GitHub Exploit DB Packet Storm
232000 7.5 危険 schoolwires - browse.asp の Schoolwires Academic Portal における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0908 2012-12-20 18:34 2008-02-22 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 11, 2026, 5:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
211181 7.2 HIGH
Network
inspur nf8480m5_firmware
nf8260m5_firmware
ns5162m5_firmware
ns5488m5_firmware
ns5484m5_firmware
ns5482m5_firmware
nf5280m5_firmware
nf5468m5_firmware
nf5488m5-d_firmware
nf5180m5…
Inspur NF5266M5 through 3.21.2 and other server M5 devices allow remote code execution via administrator privileges. The Baseboard Management Controller (BMC) program of INSPUR server is weak in chec… CWE-347
 Improper Verification of Cryptographic Signature
CVE-2020-26122 2024-11-21 14:19 2020-12-8 Show GitHub Exploit DB Packet Storm
211182 8.2 HIGH
Network
prestashop productcomments In the PrestaShop module "productcomments" before version 4.2.1, an attacker can use a Blind SQL injection to retrieve data or stop the MySQL service. The problem is fixed in 4.2.1 of the module. CWE-89
SQL Injection
CVE-2020-26248 2024-11-21 14:19 2020-12-4 Show GitHub Exploit DB Packet Storm
211183 6.5 MEDIUM
Network
pimcore pimcore Pimcore is an open source digital experience platform. In Pimcore before version 6.8.5 it is possible to modify & create website settings without having the appropriate permissions. CWE-281
 Improper Preservation of Permissions
CVE-2020-26246 2024-11-21 14:19 2020-12-3 Show GitHub Exploit DB Packet Storm
211184 6.8 MEDIUM
Network
python_openid_connect_project python_openid_connect Python oic is a Python OpenID Connect implementation. In Python oic before version 1.2.1, there are several related cryptographic issues affecting client implementations that use the library. The iss… CWE-347
 Improper Verification of Cryptographic Signature
CVE-2020-26244 2024-11-21 14:19 2020-12-3 Show GitHub Exploit DB Packet Storm
211185 6.3 MEDIUM
Network
jupyter oauthenticator OAuthenticator is an OAuth login mechanism for JupyterHub. In oauthenticator from version 0.12.0 and before 0.12.2, the deprecated (in jupyterhub 1.2) configuration `Authenticator.whitelist`, which s… CWE-863
 Incorrect Authorization
CVE-2020-26250 2024-11-21 14:19 2020-12-2 Show GitHub Exploit DB Packet Storm
211186 9.8 CRITICAL
Network
systeminformation systeminformation npm package systeminformation before version 4.30.5 is vulnerable to Prototype Pollution leading to Command Injection. The issue was fixed with a rewrite of shell sanitations to avoid prototyper poll… CWE-78
OS Command 
CVE-2020-26245 2024-11-21 14:19 2020-11-28 Show GitHub Exploit DB Packet Storm
211187 7.5 HIGH
Network
nanopb_project nanopb Nanopb is a small code-size Protocol Buffers implementation. In Nanopb before versions 0.4.4 and 0.3.9.7, decoding specifically formed message can leak memory if dynamic allocation is enabled and an … - CVE-2020-26243 2024-11-21 14:19 2020-11-26 Show GitHub Exploit DB Packet Storm
211188 6.5 MEDIUM
Network
glpi-project glpi GLPI stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. I… - CVE-2020-26212 2024-11-21 14:19 2020-11-26 Show GitHub Exploit DB Packet Storm
211189 7.5 HIGH
Network
ethereum go_ethereum Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. In Geth before version 1.9.18, there is a Denial-of-service (crash) during block processing. This is fixed in 1… NVD-CWE-noinfo
CVE-2020-26242 2024-11-21 14:19 2020-11-25 Show GitHub Exploit DB Packet Storm
211190 7.1 HIGH
Network
ethereum go_ethereum Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. This is a Consensus vulnerability in Geth before version 1.9.17 which can be used to cause a chain-split where … - CVE-2020-26241 2024-11-21 14:19 2020-11-25 Show GitHub Exploit DB Packet Storm