Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
239921 4.3 警告 dotCMS - dotCMS の search-results.dot におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-2397 2012-06-26 16:02 2008-05-21 Show GitHub Exploit DB Packet Storm
239922 7.5 危険 alkalinephp - AlkalinePHP の thread.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2395 2012-06-26 16:02 2008-05-21 Show GitHub Exploit DB Packet Storm
239923 7.5 危険 entertainmentscript - EntertainmentScript の play.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2393 2012-06-26 16:02 2008-05-21 Show GitHub Exploit DB Packet Storm
239924 7.8 危険 Subsonic AS - SubSonic におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2008-2391 2012-06-26 16:02 2008-05-21 Show GitHub Exploit DB Packet Storm
239925 5.1 警告 courier-mta - Courier-Authlib の authpgsqllib.c における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2380 2012-06-26 16:02 2008-12-22 Show GitHub Exploit DB Packet Storm
239926 7.6 危険 GNU Project - GnuTLS の libgnutls におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2008-2377 2012-06-26 16:02 2008-08-8 Show GitHub Exploit DB Packet Storm
239927 7.2 危険 fedora 8
レッドハット
- system-config-network の consolehelper デフォルト設定におけるネットワーク設定を変更される脆弱性 CWE-16
環境設定
CVE-2008-2359 2012-06-26 16:02 2008-05-28 Show GitHub Exploit DB Packet Storm
239928 7.5 危険 archangelmgt - Archangel Weblog の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2356 2012-06-26 16:02 2008-05-20 Show GitHub Exploit DB Packet Storm
239929 7.5 危険 gnugallery - GNU/Gallery の admin.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-2353 2012-06-26 16:02 2008-05-20 Show GitHub Exploit DB Packet Storm
239930 5 警告 bcoos - bcoos の highlight.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-2350 2012-06-26 16:02 2008-05-20 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 25, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
292121 - scivox vsp_stats_processor SQL injection vulnerability in vsp-core/pub/themes/bismarck/gamestat.php in vsp stats processor 0.45 allows remote attackers to execute arbitrary SQL commands via the gameID parameter. CWE-89
SQL Injection
CVE-2009-1224 2017-09-29 10:34 2009-04-3 Show GitHub Exploit DB Packet Storm
292122 - podcast_generator podcast_generator core/admin/delete.php in Podcast Generator 1.1 and earlier does not properly restrict access to administrative functions, which allows remote attackers to delete arbitrary files via the file paramete… CWE-264
Permissions, Privileges, and Access Controls
CVE-2009-1226 2017-09-29 10:34 2009-04-3 Show GitHub Exploit DB Packet Storm
292123 - arcadwy arcadwy_arcade_script_cms Cross-site scripting (XSS) vulnerability in register.php in Arcadwy Arcade Script CMS allows remote attackers to inject arbitrary web script or HTML via the username field (user_name parameter). CWE-79
Cross-site Scripting
CVE-2009-1228 2017-09-29 10:34 2009-04-3 Show GitHub Exploit DB Packet Storm
292124 - arcadwy arcadwy_arcade_script SQL injection vulnerability in Arcadwy Arcade Script allows remote attackers to execute arbitrary SQL commands via the user cookie parameter. CWE-89
SQL Injection
CVE-2009-1229 2017-09-29 10:34 2009-04-3 Show GitHub Exploit DB Packet Storm
292125 - podcast_generator podcast_generator Static code injection vulnerability in index.php in Podcast Generator 1.1 and earlier allows remote authenticated administrators to inject arbitrary PHP code into config.php via the recent parameter … CWE-94
Code Injection
CVE-2009-1230 2017-09-29 10:34 2009-04-3 Show GitHub Exploit DB Packet Storm
292126 - mozilla firefox Mozilla Firefox 3.0.8 and earlier 3.0.x versions allows remote attackers to cause a denial of service (memory corruption) via an XML document composed of a long series of start-tags with no correspon… CWE-20
 Improper Input Validation 
CVE-2009-1232 2017-09-29 10:34 2009-04-3 Show GitHub Exploit DB Packet Storm
292127 - apple safari Apple Safari 3.2.2 and 4 Beta on Windows allows remote attackers to cause a denial of service (application crash) via an XML document containing many nested A elements. CWE-20
 Improper Input Validation 
CVE-2009-1233 2017-09-29 10:34 2009-04-3 Show GitHub Exploit DB Packet Storm
292128 - opera opera_browser Opera 9.64 allows remote attackers to cause a denial of service (application crash) via an XML document containing a long series of start-tags with no corresponding end-tags. NOTE: it was later repo… CWE-20
 Improper Input Validation 
CVE-2009-1234 2017-09-29 10:34 2009-04-3 Show GitHub Exploit DB Packet Storm
292129 - apple mac_os_x
mac_os_x_server
XNU 1228.9.59 and earlier on Apple Mac OS X 10.5.6 and earlier does not properly restrict interaction between user space and the HFS IOCTL handler, which allows local users to overwrite kernel memory… CWE-264
Permissions, Privileges, and Access Controls
CVE-2009-1235 2017-09-29 10:34 2009-04-3 Show GitHub Exploit DB Packet Storm
292130 - apple mac_os_x
mac_os_x_server
Heap-based buffer overflow in the AppleTalk networking stack in XNU 1228.3.13 and earlier on Apple Mac OS X 10.5.6 and earlier allows remote attackers to cause a denial of service (system crash) via … CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2009-1236 2017-09-29 10:34 2009-04-3 Show GitHub Exploit DB Packet Storm