Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 23, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
247161 5 警告 FreePBX - FreePBX における有効なユーザ名を列挙される脆弱性 CWE-200
情報漏えい
CVE-2009-1803 2012-06-26 16:10 2009-05-28 Show GitHub Exploit DB Packet Storm
247162 6.8 警告 FreePBX - FreePBX におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2009-1802 2012-06-26 16:10 2009-05-28 Show GitHub Exploit DB Packet Storm
247163 4.3 警告 FreePBX - FreePBX におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-1801 2012-06-26 16:10 2009-05-28 Show GitHub Exploit DB Packet Storm
247164 7.5 危険 chinagames - CGAgent.dll の Chinagames CGAgent ActiveX コントロールにおけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-1800 2012-06-26 16:10 2009-05-28 Show GitHub Exploit DB Packet Storm
247165 4.3 警告 philip moore
eggheads
- Eggheads Eggdrop の mod/server.mod/servmsg.c におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2009-1789 2012-06-26 16:10 2009-05-6 Show GitHub Exploit DB Packet Storm
247166 10 危険 AVG Technologies - 複数の AVG アンチウィルス製品で使用される AVG 解析処理エンジンにおけるマルウェア検出を回避される脆弱性 CWE-20
不適切な入力確認
CVE-2009-1784 2012-06-26 16:10 2009-05-22 Show GitHub Exploit DB Packet Storm
247167 10 危険 FRISK Software International - FRISK Software F-Prot アンチウイルス製品におけるマルウェア検知を回避される脆弱性 CWE-20
不適切な入力確認
CVE-2009-1783 2012-06-26 16:10 2009-05-22 Show GitHub Exploit DB Packet Storm
247168 6.8 警告 エフ・セキュア - 複数の F-Secure アンチウイルス製品におけるマルウェアの検知を回避される脆弱性 CWE-noinfo
情報不足
CVE-2009-1782 2012-06-26 16:10 2009-05-22 Show GitHub Exploit DB Packet Storm
247169 6.8 警告 BIGACE - BigACE CMS の新ユーザ登録機能における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-1778 2012-06-26 16:10 2009-04-27 Show GitHub Exploit DB Packet Storm
247170 5 警告 A51 D.O.O. - activeCollab における重要な情報を取得される脆弱性 CWE-20
不適切な入力確認
CVE-2009-1773 2012-06-26 16:10 2009-05-22 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 23, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
219321 8.8 HIGH
Network
foxitsoftware phantompdf
reader
In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can execute arbitrary code via a heap-based buffer overflow because dirty image-resource data is mishandled. CWE-787
 Out-of-bounds Write
CVE-2020-12248 2024-11-21 13:59 2020-09-4 Show GitHub Exploit DB Packet Storm
219322 7.1 HIGH
Local
foxitsoftware phantompdf
reader
In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can obtain sensitive information from an out-of-bounds read because a text-string index continues to be used after… CWE-125
Out-of-bounds Read
CVE-2020-12247 2024-11-21 13:59 2020-09-4 Show GitHub Exploit DB Packet Storm
219323 6.1 MEDIUM
Network
oscommerce ce_phoenix Several XSS vulnerabilities in osCommerce CE Phoenix before 1.0.6.0 allow an attacker to inject and execute arbitrary JavaScript code. The malicious code can be injected as follows: the page paramete… CWE-79
Cross-site Scripting
CVE-2020-12058 2024-11-21 13:59 2020-09-3 Show GitHub Exploit DB Packet Storm
219324 6.1 MEDIUM
Physics
teamwire teamwire The Teamwire application 5.3.0 for Android allows physically proximate attackers to exploit a flaw related to the pass-code component. CWE-306
Missing Authentication for Critical Function
CVE-2020-12621 2024-11-21 13:59 2020-09-3 Show GitHub Exploit DB Packet Storm
219325 5.4 MEDIUM
Network
open-xchange open-xchange_appsuite OX App Suite 7.10.3 and earlier allows XSS via text/x-javascript, text/rdf, or a PDF document. CWE-79
Cross-site Scripting
CVE-2020-12646 2024-11-21 13:59 2020-09-1 Show GitHub Exploit DB Packet Storm
219326 9.8 CRITICAL
Network
open-xchange open-xchange_appsuite OX App Suite 7.10.1 to 7.10.3 has improper input validation for rate limits with a crafted User-Agent header, spoofed vacation notices, and /apps/load memory consumption. CWE-307
mproper Restriction of Excessive Authentication Attempts
CVE-2020-12645 2024-11-21 13:59 2020-09-1 Show GitHub Exploit DB Packet Storm
219327 5.0 MEDIUM
Network
open-xchange open-xchange_appsuite OX App Suite 7.10.3 and earlier allows SSRF, related to the mail account API and the /folder/list API. CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2020-12644 2024-11-21 13:59 2020-09-1 Show GitHub Exploit DB Packet Storm
219328 4.3 MEDIUM
Network
open-xchange open-xchange_appsuite OX App Suite 7.10.3 and earlier has Incorrect Access Control via an /api/subscriptions request for a snippet containing an email address. CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2020-12643 2024-11-21 13:59 2020-09-1 Show GitHub Exploit DB Packet Storm
219329 8.8 HIGH
Network
mitel mivoice_connect A remote code execution vulnerability in Mitel MiVoice Connect Client before 214.100.1223.0 could allow an attacker to execute arbitrary code in the chat notification window, due to improper renderin… CWE-22
Path Traversal
CVE-2020-12456 2024-11-21 13:59 2020-08-27 Show GitHub Exploit DB Packet Storm
219330 7.5 HIGH
Network
wolfssl wolfssl An issue was discovered in wolfSSL before 4.5.0. It mishandles the change_cipher_spec (CCS) message processing logic for TLS 1.3. If an attacker sends ChangeCipherSpec messages in a crafted way invol… CWE-835
 Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2020-12457 2024-11-21 13:59 2020-08-21 Show GitHub Exploit DB Packet Storm