Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 3, 2025, 1:14 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
196921 4.3 警告 dream - Radio and TV Player addon for vBulletin の forum/radioandtv.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-2172 2012-06-26 16:10 2009-06-23 Show GitHub Exploit DB Packet Storm
196922 9.3 危険 EdrawSoft - Edraw PDF Viewer コンポーネントの pdfviewer.ocx における任意のファイルを作成される脆弱性 CWE-94
コード・インジェクション
CVE-2009-2169 2012-06-26 16:10 2009-06-22 Show GitHub Exploit DB Packet Storm
196923 7.5 危険 egyplus - EgyPlus 7ammel の cpanel/login.php における認証を回避される脆弱性 CWE-287
不適切な認証
CVE-2009-2168 2012-06-26 16:10 2009-06-22 Show GitHub Exploit DB Packet Storm
196924 6.8 警告 egyplus - EgyPlus 7ammel の cpanel/login.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-2167 2012-06-26 16:10 2009-06-22 Show GitHub Exploit DB Packet Storm
196925 5 警告 adaptweb - AdaptWeb の index.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2009-2151 2012-06-26 16:10 2009-06-22 Show GitHub Exploit DB Packet Storm
196926 6.8 警告 campusvirtualcomputrade - Campus Virtual-LMS におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2009-2150 2012-06-26 16:10 2009-06-22 Show GitHub Exploit DB Packet Storm
196927 4.3 警告 campusvirtualcomputrade - Campus Virtual-LMS におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-2149 2012-06-26 16:10 2009-06-22 Show GitHub Exploit DB Packet Storm
196928 7.5 危険 campusvirtualcomputrade - Campus Virtual-LMS の news/index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-2148 2012-06-26 16:10 2009-06-22 Show GitHub Exploit DB Packet Storm
196929 7.5 危険 WordPress.org
firestats
edgewall
- WordPress の FireStats プラグインにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-2144 2012-06-26 16:10 2009-06-13 Show GitHub Exploit DB Packet Storm
196930 7.5 危険 firestats
WordPress.org
- WordPress の FireStats プラグインの firestats-wordpress.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2009-2143 2012-06-26 16:10 2009-06-13 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Feb. 6, 2025, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1351 - - - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Teplitsa. Technologies for Social Good ShMapper by Teplitsa allows Stored XSS. This issue affects… CWE-79
Cross-site Scripting
CVE-2025-24674 2025-01-25 03:15 2025-01-25 Show GitHub Exploit DB Packet Storm
1352 - - - Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in AyeCode Ltd Ketchup Shortcodes allows Stored XSS. This issue affects Ketchup Shortcodes: from n/a throug… CWE-80
Basic XSS
CVE-2025-24673 2025-01-25 03:15 2025-01-25 Show GitHub Exploit DB Packet Storm
1353 - - - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CodePeople Form Builder CP allows SQL Injection. This issue affects Form Builder CP: from n/a thr… CWE-89
SQL Injection
CVE-2025-24672 2025-01-25 03:15 2025-01-25 Show GitHub Exploit DB Packet Storm
1354 - - - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SERPed SERPed.net allows SQL Injection. This issue affects SERPed.net: from n/a through 4.4. CWE-89
SQL Injection
CVE-2025-24669 2025-01-25 03:15 2025-01-25 Show GitHub Exploit DB Packet Storm
1355 - - - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeisle PPOM for WooCommerce allows Stored XSS. This issue affects PPOM for WooCommerce: from n… CWE-79
Cross-site Scripting
CVE-2025-24668 2025-01-25 03:15 2025-01-25 Show GitHub Exploit DB Packet Storm
1356 - - - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeIsle AI Chatbot for WordPress – Hyve Lite allows Stored XSS. This issue affects AI Chatbot f… CWE-79
Cross-site Scripting
CVE-2025-24666 2025-01-25 03:15 2025-01-25 Show GitHub Exploit DB Packet Storm
1357 - - - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tips and Tricks HQ, Ruhul Amin, Josh Lobe Simple Download Monitor allows Blind SQL Injection. Thi… CWE-89
SQL Injection
CVE-2025-24663 2025-01-25 03:15 2025-01-25 Show GitHub Exploit DB Packet Storm
1358 - - - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WordPress Download Manager Premium Packages allows Blind SQL Injection. This issue affects Premiu… CWE-89
SQL Injection
CVE-2025-24659 2025-01-25 03:15 2025-01-25 Show GitHub Exploit DB Packet Storm
1359 - - - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joe Hawes Auction Nudge – Your eBay on Your Site allows Stored XSS. This issue affects Auction Nu… CWE-79
Cross-site Scripting
CVE-2025-24658 2025-01-25 03:15 2025-01-25 Show GitHub Exploit DB Packet Storm
1360 - - - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebToffee Wishlist for WooCommerce allows Stored XSS. This issue affects Wishlist for WooCommerce… CWE-79
Cross-site Scripting
CVE-2025-24657 2025-01-25 03:15 2025-01-25 Show GitHub Exploit DB Packet Storm