Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 20, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
247781 7.5 危険 badongo - Campus Bulletin Board における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2492 2012-06-26 16:02 2008-05-28 Show GitHub Exploit DB Packet Storm
247782 9.3 危険 ebay - eBay Enhanced Picture Uploader ActiveX コントロールにおける任意のコマンドを実行される脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2008-2475 2012-06-26 16:02 2009-06-9 Show GitHub Exploit DB Packet Storm
247783 6.5 警告 beaussier - RoomPHPlanning の admin/userform.php における新規に admin アカウントを作成される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-2488 2012-06-26 16:02 2008-05-28 Show GitHub Exploit DB Packet Storm
247784 10 危険 emule - eMule Plus における詳細不明な脆弱性 CWE-noinfo
情報不足
CVE-2008-2486 2012-06-26 16:02 2008-05-28 Show GitHub Exploit DB Packet Storm
247785 6.8 警告 badongo - phpFix における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2479 2012-06-26 16:02 2008-05-28 Show GitHub Exploit DB Packet Storm
247786 6.8 警告 entertainmentscript - EntertainmentScript の page.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-2459 2012-06-26 16:02 2008-05-27 Show GitHub Exploit DB Packet Storm
247787 4.3 警告 4shared - Starsgames Control Panel の index.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-2458 2012-06-26 16:02 2008-05-27 Show GitHub Exploit DB Packet Storm
247788 7.5 危険 bitmixsoft - PHP-Jokesite の jokes_category.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2457 2012-06-26 16:02 2008-05-27 Show GitHub Exploit DB Packet Storm
247789 7.5 危険 comicshout - ComicShout の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2456 2012-06-26 16:02 2008-05-27 Show GitHub Exploit DB Packet Storm
247790 7.5 危険 e107coders - e107用 MacGuru BLOG Engine プラグインの comment.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2455 2012-06-26 16:02 2008-05-27 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 21, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
211781 8.8 HIGH
Network
vfairs vfairs vFairs 3.3 is affected by Remote Code Execution. Any user logged in to a vFairs virtual conference or event can abuse the functionality to upload a profile picture in order to place a malicious PHP f… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2020-26678 2024-11-21 14:20 2021-05-26 Show GitHub Exploit DB Packet Storm
211782 8.8 HIGH
Network
vfairs vfairs Any user logged in to a vFairs 3.3 virtual conference or event can perform SQL injection with a malicious query to the API. CWE-89
SQL Injection
CVE-2020-26677 2024-11-21 14:20 2021-05-26 Show GitHub Exploit DB Packet Storm
211783 8.1 HIGH
Adjacent
bluetooth mesh_profile Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, reflecting the authentication evidence from a Provisioner, to complete authentication without posse… CWE-863
 Incorrect Authorization
CVE-2020-26560 2024-11-21 14:20 2021-05-25 Show GitHub Exploit DB Packet Storm
211784 8.8 HIGH
Adjacent
bluetooth mesh_profile Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (participating in the provisioning protocol) to identify the AuthValue used given the Provisioner’s … CWE-863
 Incorrect Authorization
CVE-2020-26559 2024-11-21 14:20 2021-05-25 Show GitHub Exploit DB Packet Storm
211785 4.2 MEDIUM
Adjacent
bluetooth
fedoraproject
debian
linux
intel
bluetooth_core_specification
fedora
debian_linux
linux_kernel
ax210_firmware
ax201_firmware
ax200_firmware
ac_9560_firmware
ac_9462_firmware
ac_9461_firmware
ac_9260_fir…
Bluetooth LE and BR/EDR secure pairing in Bluetooth Core Specification 2.1 through 5.2 may permit a nearby man-in-the-middle attacker to identify the Passkey used during pairing (in the Passkey authe… CWE-287
Improper Authentication
CVE-2020-26558 2024-11-21 14:20 2021-05-25 Show GitHub Exploit DB Packet Storm
211786 7.5 HIGH
Adjacent
bluetooth mesh_profile Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (without possession of the AuthValue used in the provisioning protocol) to determine the AuthValue via a brute… CWE-287
Improper Authentication
CVE-2020-26557 2024-11-21 14:20 2021-05-25 Show GitHub Exploit DB Packet Storm
211787 7.5 HIGH
Adjacent
bluetooth mesh_profile
bluetooth_core_specification
Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, able to conduct a successful brute-force attack on an insufficiently random AuthValue before the provisioning… CWE-307
mproper Restriction of Excessive Authentication Attempts
CVE-2020-26556 2024-11-21 14:20 2021-05-25 Show GitHub Exploit DB Packet Storm
211788 5.4 MEDIUM
Adjacent
bluetooth
fedoraproject
intel
bluetooth_core_specification
fedora
ax210_firmware
ax201_firmware
ax200_firmware
ac_9560_firmware
ac_9462_firmware
ac_9461_firmware
ac_9260_firmware
ac_8265_firmware
ac_…
Bluetooth legacy BR/EDR PIN code pairing in Bluetooth Core Specification 1.0B through 5.2 may permit an unauthenticated nearby device to spoof the BD_ADDR of the peer device to complete pairing witho… CWE-863
 Incorrect Authorization
CVE-2020-26555 2024-11-21 14:20 2021-05-25 Show GitHub Exploit DB Packet Storm
211789 5.7 MEDIUM
Physics
nordicsemi nrf52840_firmware Nordic Semiconductor nRF52840 devices through 2020-10-19 have improper protection against physical side channels. The flash read-out protection (APPROTECT) can be bypassed by injecting a fault during… CWE-203
 Information Exposure Through Discrepancy
CVE-2020-27211 2024-11-21 14:20 2021-05-21 Show GitHub Exploit DB Packet Storm
211790 7.0 HIGH
Local
st stm32cubel4_firmware STMicroelectronics STM32L4 devices through 2020-10-19 have incorrect access control. The flash read-out protection (RDP) can be degraded from RDP level 2 (no access via debug interface) to level 1 (l… CWE-74
Injection
CVE-2020-27212 2024-11-21 14:20 2021-05-21 Show GitHub Exploit DB Packet Storm