Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
239931 7.5 危険 alkalinephp - AlkalinePHP における管理アクセス権を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-2346 2012-06-26 16:02 2008-05-20 Show GitHub Exploit DB Packet Storm
239932 7.5 危険 avalonnet - News Manager の ch_readalso.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2008-2341 2012-06-26 16:02 2008-05-19 Show GitHub Exploit DB Packet Storm
239933 7.5 危険 68classifieds - 68 Classifieds の category.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2336 2012-06-26 16:02 2008-05-19 Show GitHub Exploit DB Packet Storm
239934 7.5 危険 ASP indir - W1L3D4 Philboard における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2334 2012-06-26 16:02 2008-05-19 Show GitHub Exploit DB Packet Storm
239935 4.3 警告 Django Software Foundation - Django の管理アプリケーションのログインフォームにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-2302 2012-06-26 16:02 2008-05-23 Show GitHub Exploit DB Packet Storm
239936 6.5 警告 シトリックス・システムズ - Citrix Presentation Server などの製品における不正にデスクトップへアクセスされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-2300 2012-06-26 16:02 2008-05-13 Show GitHub Exploit DB Packet Storm
239937 5 警告 シトリックス・システムズ - Citrix Presentation Server などの製品で使用される SecureICA における制限を回避される脆弱性 CWE-310
暗号の問題
CVE-2008-2299 2012-06-26 16:02 2008-05-12 Show GitHub Exploit DB Packet Storm
239938 7.5 危険 Fusebox - Fusebox の fusebox5.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2008-2284 2012-06-26 16:02 2008-05-18 Show GitHub Exploit DB Packet Storm
239939 5 警告 freelanceauction - Freelance Auction Script における権限を取得される脆弱性 CWE-255
証明書・パスワード管理
CVE-2008-2279 2012-06-26 16:02 2008-05-16 Show GitHub Exploit DB Packet Storm
239940 7.5 危険 freelanceauction - Freelance Auction Script の browseproject.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2278 2012-06-26 16:02 2008-05-16 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 25, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
292121 - scivox vsp_stats_processor SQL injection vulnerability in vsp-core/pub/themes/bismarck/gamestat.php in vsp stats processor 0.45 allows remote attackers to execute arbitrary SQL commands via the gameID parameter. CWE-89
SQL Injection
CVE-2009-1224 2017-09-29 10:34 2009-04-3 Show GitHub Exploit DB Packet Storm
292122 - podcast_generator podcast_generator core/admin/delete.php in Podcast Generator 1.1 and earlier does not properly restrict access to administrative functions, which allows remote attackers to delete arbitrary files via the file paramete… CWE-264
Permissions, Privileges, and Access Controls
CVE-2009-1226 2017-09-29 10:34 2009-04-3 Show GitHub Exploit DB Packet Storm
292123 - arcadwy arcadwy_arcade_script_cms Cross-site scripting (XSS) vulnerability in register.php in Arcadwy Arcade Script CMS allows remote attackers to inject arbitrary web script or HTML via the username field (user_name parameter). CWE-79
Cross-site Scripting
CVE-2009-1228 2017-09-29 10:34 2009-04-3 Show GitHub Exploit DB Packet Storm
292124 - arcadwy arcadwy_arcade_script SQL injection vulnerability in Arcadwy Arcade Script allows remote attackers to execute arbitrary SQL commands via the user cookie parameter. CWE-89
SQL Injection
CVE-2009-1229 2017-09-29 10:34 2009-04-3 Show GitHub Exploit DB Packet Storm
292125 - podcast_generator podcast_generator Static code injection vulnerability in index.php in Podcast Generator 1.1 and earlier allows remote authenticated administrators to inject arbitrary PHP code into config.php via the recent parameter … CWE-94
Code Injection
CVE-2009-1230 2017-09-29 10:34 2009-04-3 Show GitHub Exploit DB Packet Storm
292126 - mozilla firefox Mozilla Firefox 3.0.8 and earlier 3.0.x versions allows remote attackers to cause a denial of service (memory corruption) via an XML document composed of a long series of start-tags with no correspon… CWE-20
 Improper Input Validation 
CVE-2009-1232 2017-09-29 10:34 2009-04-3 Show GitHub Exploit DB Packet Storm
292127 - apple safari Apple Safari 3.2.2 and 4 Beta on Windows allows remote attackers to cause a denial of service (application crash) via an XML document containing many nested A elements. CWE-20
 Improper Input Validation 
CVE-2009-1233 2017-09-29 10:34 2009-04-3 Show GitHub Exploit DB Packet Storm
292128 - opera opera_browser Opera 9.64 allows remote attackers to cause a denial of service (application crash) via an XML document containing a long series of start-tags with no corresponding end-tags. NOTE: it was later repo… CWE-20
 Improper Input Validation 
CVE-2009-1234 2017-09-29 10:34 2009-04-3 Show GitHub Exploit DB Packet Storm
292129 - apple mac_os_x
mac_os_x_server
XNU 1228.9.59 and earlier on Apple Mac OS X 10.5.6 and earlier does not properly restrict interaction between user space and the HFS IOCTL handler, which allows local users to overwrite kernel memory… CWE-264
Permissions, Privileges, and Access Controls
CVE-2009-1235 2017-09-29 10:34 2009-04-3 Show GitHub Exploit DB Packet Storm
292130 - apple mac_os_x
mac_os_x_server
Heap-based buffer overflow in the AppleTalk networking stack in XNU 1228.3.13 and earlier on Apple Mac OS X 10.5.6 and earlier allows remote attackers to cause a denial of service (system crash) via … CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2009-1236 2017-09-29 10:34 2009-04-3 Show GitHub Exploit DB Packet Storm