Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 11, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
232081 7.5 危険 WordPress.org - WordPress 用の WassUp プラグインにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0520 2012-12-20 18:34 2008-01-31 Show GitHub Exploit DB Packet Storm
232082 9.3 危険 SQLiteManager - SQLiteManager の spaw/dialogs/confirm.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2008-0516 2012-12-20 18:34 2008-01-31 Show GitHub Exploit DB Packet Storm
232083 7.8 危険 Phpcms - phpCMS の parser/include/class.cache_phpcms.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-0513 2012-12-20 18:34 2008-01-31 Show GitHub Exploit DB Packet Storm
232084 6.8 警告 WordPress.org - WordPress 用の Dean's Permalinks Migration プラグインにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2008-0508 2012-12-20 18:34 2008-01-31 Show GitHub Exploit DB Packet Storm
232085 7.5 危険 WordPress.org - WordPress 用の AdServe プラグインにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0507 2012-12-20 18:34 2008-01-31 Show GitHub Exploit DB Packet Storm
232086 5.8 警告 加藤和良 - phpMyClub におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-0501 2012-12-20 18:34 2008-01-30 Show GitHub Exploit DB Packet Storm
232087 7.5 危険 WordPress.org - WordPress 用の fGallery プラグインにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0491 2012-12-20 18:34 2008-01-30 Show GitHub Exploit DB Packet Storm
232088 7.5 危険 WordPress.org - WordPress 用の WP-Cal プラグインにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0490 2012-12-20 18:34 2008-01-30 Show GitHub Exploit DB Packet Storm
232089 7.5 危険 vb marketing - VB Marketing の tseekdir.cgi におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-0488 2012-12-20 18:34 2008-01-30 Show GitHub Exploit DB Packet Storm
232090 7.5 危険 the net guys - ASPired2Protect の login.asp における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0487 2012-12-20 18:34 2008-01-30 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 11, 2026, 5:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
199661 7.8 HIGH
Local
fujitsu scansnap_manager Untrusted search path vulnerability in the installers of ScanSnap Manager prior to versions V7.0L20 and the Software Download Installer prior to WinSSInst2JP.exe and WinSSInst2iX1500JP.exe allows an … CWE-427
 Uncontrolled Search Path Element
CVE-2021-20722 2024-11-21 14:47 2021-05-24 Show GitHub Exploit DB Packet Storm
199662 7.8 HIGH
Local
qualitysoft qnd Privilege escalation vulnerability in QND Advance/Premium/Standard Ver.11.0.4i and earlier allows an attacker who can log in to the PC where the product's Windows client is installed to gain administ… CWE-269
 Improper Privilege Management
CVE-2021-20713 2024-11-21 14:47 2021-05-24 Show GitHub Exploit DB Packet Storm
199663 9.8 CRITICAL
Network
kujirahand konawiki KonaWiki2 versions prior to 2.2.4 allows a remote attacker to upload arbitrary files via unspecified vectors. If the file contains PHP scripts, arbitrary code may be executed. CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2021-20721 2024-11-21 14:47 2021-05-20 Show GitHub Exploit DB Packet Storm
199664 9.8 CRITICAL
Network
kujirahand konawiki SQL injection vulnerability in the KonaWiki2 versions prior to 2.2.4 allows remote attackers to execute arbitrary SQL commands and to obtain/alter the information stored in the database via unspecifi… CWE-89
SQL Injection
CVE-2021-20720 2024-11-21 14:47 2021-05-20 Show GitHub Exploit DB Packet Storm
199665 6.8 MEDIUM
Adjacent
nippon-antenna rfntps_firmware RFNTPS firmware versions System_01000004 and earlier, and Web_01000004 and earlier allow an attacker on the same network segment to execute arbitrary OS commands with a root privilege via unspecified… CWE-78
OS Command 
CVE-2021-20719 2024-11-21 14:47 2021-05-20 Show GitHub Exploit DB Packet Storm
199666 7.5 HIGH
Network
openidc
fedoraproject
oracle
mod_auth_openidc
fedora
essbase
mod_auth_openidc 2.4.0 to 2.4.7 allows a remote attacker to cause a denial-of-service (DoS) condition via unspecified vectors. CWE-400
 Uncontrolled Resource Consumption
CVE-2021-20718 2024-11-21 14:47 2021-05-20 Show GitHub Exploit DB Packet Storm
199667 9.8 CRITICAL
Network
weidmueller uc20-wl2000-ac_firmware
uc20-wl2000-iot_firmware
iot-gw30_firmware
iot-gw30-4g-eu_firmware
In Weidmüller u-controls and IoT-Gateways in versions up to 1.12.1 a network port intended only for device-internal usage is accidentally accessible via external network interfaces. By exploiting thi… NVD-CWE-Other
CVE-2021-20999 2024-11-21 14:47 2021-05-13 Show GitHub Exploit DB Packet Storm
199668 9.8 CRITICAL
Network
wago 0852-0303_firmware
0852-1305_firmware
0852-1505_firmware
0852-1305\/000-001_firmware
0852-1505\/000-001_firmware
In multiple managed switches by WAGO in different versions without authorization and with specially crafted packets it is possible to create users. CWE-306
Missing Authentication for Critical Function
CVE-2021-20998 2024-11-21 14:47 2021-05-13 Show GitHub Exploit DB Packet Storm
199669 7.5 HIGH
Network
wago 0852-0303_firmware
0852-1305_firmware
0852-1505_firmware
0852-1305\/000-001_firmware
0852-1505\/000-001_firmware
In multiple managed switches by WAGO in different versions it is possible to read out the password hashes of all Web-based Management users. CWE-522
 Insufficiently Protected Credentials
CVE-2021-20997 2024-11-21 14:47 2021-05-13 Show GitHub Exploit DB Packet Storm
199670 5.3 MEDIUM
Network
wago 0852-0303_firmware
0852-1305_firmware
0852-1505_firmware
0852-1305\/000-001_firmware
0852-1505\/000-001_firmware
In multiple managed switches by WAGO in different versions special crafted requests can lead to cookies being transferred to third parties. CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2021-20996 2024-11-21 14:47 2021-05-13 Show GitHub Exploit DB Packet Storm