Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 4, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
241461 7.2 危険 dcgrendel
Canonical
- Ubuntu におけるログイン制限を回避される脆弱性 CWE-255
証明書・パスワード管理
CVE-2008-5104 2012-06-26 16:03 2008-11-13 Show GitHub Exploit DB Packet Storm
241462 7.2 危険 dcgrendel
Canonical
- Ubuntu の VMBuilder におけるログイン制限を回避される脆弱性 CWE-255
証明書・パスワード管理
CVE-2008-5103 2012-06-26 16:03 2008-11-13 Show GitHub Exploit DB Packet Storm
241463 10 危険 AEF Group - Electron Inc. Advanced Electron Forum における任意の PHP コードが実行される脆弱性 CWE-94
コード・インジェクション
CVE-2008-5090 2012-06-26 16:03 2008-11-14 Show GitHub Exploit DB Packet Storm
241464 9.3 危険 datadynamics - Data Dynamics ActiveReports の DDActiveReportsViewer2.ARViewer2 ActiveX コントロールにおける任意のファイルを上書きされる脆弱性 CWE-Other
その他
CVE-2008-5089 2012-06-26 16:03 2008-11-14 Show GitHub Exploit DB Packet Storm
241465 4.3 警告 Laurent Destailleur - AWStats の awstats.pl におけるクロスサイトスクリプティング攻撃を実行する脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-5080 2012-06-26 16:03 2008-12-3 Show GitHub Exploit DB Packet Storm
241466 7.5 危険 deeserver - Panuwat PromoteWeb MySQL の go.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-5069 2012-06-26 16:03 2008-11-14 Show GitHub Exploit DB Packet Storm
241467 10 危険 agaresmedia - Agares Media ThemeSiteScript の upload/admin/frontpage_right.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2008-5066 2012-06-26 16:03 2008-11-13 Show GitHub Exploit DB Packet Storm
241468 6.9 警告 enomaly - ECP における任意のファイルを上書きされる脆弱性 CWE-59
リンク解釈の問題
CVE-2008-4990 2012-06-26 16:03 2009-02-2 Show GitHub Exploit DB Packet Storm
241469 7.5 危険 easy-script - TlGuestBook における管理アクセス権を取得される脆弱性 CWE-287
不適切な認証
CVE-2008-5065 2012-06-26 16:03 2008-11-13 Show GitHub Exploit DB Packet Storm
241470 7.5 危険 ASP indir - Yigit Aybuga Dizi Portali の film.asp における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-5057 2012-06-26 16:03 2008-11-13 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 5, 2026, 4:51 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
267631 8.6 HIGH
Network
php php Use-after-free vulnerability in the Collator::sortWithSortKeys function in ext/intl/collator/collator_sort.c in PHP 7.x before 7.0.1 allows remote attackers to cause a denial of service (application … NVD-CWE-Other
CVE-2015-8616 2024-11-21 11:38 2016-01-19 Show GitHub Exploit DB Packet Storm
267632 5.4 MEDIUM
Network
gajim gajim Gajim before 0.16.5 allows remote attackers to modify the roster and intercept messages via a crafted roster-push IQ stanza. CWE-20
 Improper Input Validation 
CVE-2015-8688 2024-11-21 11:38 2016-01-16 Show GitHub Exploit DB Packet Storm
267633 6.1 MEDIUM
Network
dolibarr dolibarr Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.8.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) external calendar url or (2) the ba… CWE-79
Cross-site Scripting
CVE-2015-8685 2024-11-21 11:38 2016-01-16 Show GitHub Exploit DB Packet Storm
267634 6.2 MEDIUM
Local
huawei s5300_firmware Huawei S5300 Campus Series switches with software before V200R005SPH008 do not mask the password when uploading files, which allows physically proximate attackers to obtain sensitive password informa… CWE-255
Credentials Management
CVE-2015-8675 2024-11-21 11:38 2016-01-16 Show GitHub Exploit DB Packet Storm
267635 7.5 HIGH
Network
samsung web_viewer Web Viewer 1.0.0.193 on Samsung SRN-1670D devices allows attackers to bypass filesystem encryption via XOR calculations. CWE-310
Cryptographic Issues
CVE-2015-8281 2024-11-21 11:38 2016-01-15 Show GitHub Exploit DB Packet Storm
267636 7.5 HIGH
Network
samsung web_viewer Web Viewer 1.0.0.193 on Samsung SRN-1670D devices allows remote attackers to discover credentials by reading detailed error messages. CWE-200
Information Exposure
CVE-2015-8280 2024-11-21 11:38 2016-01-15 Show GitHub Exploit DB Packet Storm
267637 8.6 HIGH
Network
samsung web_viewer Web Viewer 1.0.0.193 on Samsung SRN-1670D devices allows remote attackers to read arbitrary files via a request to an unspecified PHP script. CWE-264
Permissions, Privileges, and Access Controls
CVE-2015-8279 2024-11-21 11:38 2016-01-15 Show GitHub Exploit DB Packet Storm
267638 6.5 MEDIUM
Adjacent
sophos
isc
debian
canonical
unified_threat_management_up2date
dhcp
debian_linux
ubuntu_linux
ISC DHCP 4.x before 4.1-ESV-R12-P1, 4.2.x, and 4.3.x before 4.3.3-P1 allows remote attackers to cause a denial of service (application crash) via an invalid length field in a UDP IPv4 packet. CWE-20
 Improper Input Validation 
CVE-2015-8605 2024-11-21 11:38 2016-01-15 Show GitHub Exploit DB Packet Storm
267639 7.3 HIGH
Network
canonical
perl
debian
ubuntu_linux
pathtools
debian_linux
The canonpath function in the File::Spec module in PathTools before 3.62, as used in Perl, does not properly preserve the taint attribute of data, which might allow context-dependent attackers to byp… CWE-20
 Improper Input Validation 
CVE-2015-8607 2024-11-21 11:38 2016-01-14 Show GitHub Exploit DB Packet Storm
267640 7.4 HIGH
Network
fedoraproject
openstack
fedora
swift3
Swift3 before 1.9 allows remote attackers to conduct replay attacks via an Authorization request that lacks a Date header. CWE-20
 Improper Input Validation 
CVE-2015-8466 2024-11-21 11:38 2016-01-14 Show GitHub Exploit DB Packet Storm