Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Jan. 22, 2025, 6:04 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
197691 7.5 危険 comdev - Comdev News Publisher の home.news.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-1872 2012-06-26 16:02 2008-04-17 Show GitHub Exploit DB Packet Storm
197692 7.5 危険 geek247 - PIGMy-SQL の getdata.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-1870 2012-06-26 16:02 2008-04-17 Show GitHub Exploit DB Packet Storm
197693 6.8 警告 exbb - ExBB Italia におけるチェックを回避される脆弱性 CWE-20
CWE-94
CVE-2008-1862 2012-06-26 16:02 2008-04-17 Show GitHub Exploit DB Packet Storm
197694 5.1 警告 exbb - ExBB Italia の modules/threadstop/threadstop.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-1861 2012-06-26 16:02 2008-04-17 Show GitHub Exploit DB Packet Storm
197695 7.5 危険 724cms - 724Networks 724CMS の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-1858 2012-06-26 16:02 2008-04-16 Show GitHub Exploit DB Packet Storm
197696 7.5 危険 coronamatrix - CoronaMatrix phpAddressBook の view.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-1847 2012-06-26 16:02 2008-04-16 Show GitHub Exploit DB Packet Storm
197697 6.8 警告 Coppermine Photo Gallery - CPG の bridge/coppermine.inc.php のセッションハンドリング機能における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-1841 2012-06-26 16:02 2008-04-16 Show GitHub Exploit DB Packet Storm
197698 6.5 警告 Coppermine Photo Gallery - Coppermine Photo Gallery (CPG) の upload.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-1840 2012-06-26 16:02 2008-04-16 Show GitHub Exploit DB Packet Storm
197699 7.5 危険 bosdev - BosClassifieds Classified Ads System における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-1838 2012-06-26 16:02 2008-04-16 Show GitHub Exploit DB Packet Storm
197700 3.3 注意 cecilia - Cecilia の lib/prefs.tcl における任意のファイルを上書きされる脆弱性 CWE-59
リンク解釈の問題
CVE-2008-1832 2012-06-26 16:02 2008-04-16 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Jan. 23, 2025, 5:11 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
641 6.4 MEDIUM
Network
- - The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘list_tag’ parameter in all versions up to, and including, 3.6.2 due to insufficient input sanitization and out… CWE-79
Cross-site Scripting
CVE-2025-0369 2025-01-18 16:15 2025-01-18 Show GitHub Exploit DB Packet Storm
642 4.4 MEDIUM
Network
- - The MarketKing — Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin's settings in all versions up to, and including, 1.… CWE-79
Cross-site Scripting
CVE-2024-13519 2025-01-18 16:15 2025-01-18 Show GitHub Exploit DB Packet Storm
643 4.4 MEDIUM
Network
- - The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Title value in all versions up to, and including,… CWE-79
Cross-site Scripting
CVE-2024-13517 2025-01-18 16:15 2025-01-18 Show GitHub Exploit DB Packet Storm
644 6.4 MEDIUM
Network
- - The Utilities for MTG plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mtglink' shortcode in all versions up to, and including, 1.4.1 due to insufficient input sani… CWE-79
Cross-site Scripting
CVE-2024-13433 2025-01-18 16:15 2025-01-18 Show GitHub Exploit DB Packet Storm
645 6.1 MEDIUM
Network
- - The Webcamconsult plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.0. This is due to missing or incorrect nonce validation on a function. Thi… CWE-352
 Origin Validation Error
CVE-2024-13432 2025-01-18 16:15 2025-01-18 Show GitHub Exploit DB Packet Storm
646 6.4 MEDIUM
Network
- - The Video Share VOD – Turnkey Video Site Builder Script plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_videos' shortcode in all versions up to, and i… CWE-79
Cross-site Scripting
CVE-2024-13393 2025-01-18 16:15 2025-01-18 Show GitHub Exploit DB Packet Storm
647 6.4 MEDIUM
Network
- - The MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Tokens Wallet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_content_up… CWE-79
Cross-site Scripting
CVE-2024-13391 2025-01-18 16:15 2025-01-18 Show GitHub Exploit DB Packet Storm
648 6.4 MEDIUM
Network
- - The JSM Screenshot Machine Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ssm' shortcode in all versions up to, and including, 2.3.0 due to insufficient… CWE-79
Cross-site Scripting
CVE-2024-13385 2025-01-18 16:15 2025-01-18 Show GitHub Exploit DB Packet Storm
649 4.3 MEDIUM
Network
- - The ShipWorks Connector for Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.2.5. This is due to missing or incorrect nonce validat… CWE-352
 Origin Validation Error
CVE-2024-13317 2025-01-18 16:15 2025-01-18 Show GitHub Exploit DB Packet Storm
650 6.4 MEDIUM
Network
- - The Picture Gallery – Frontend Image Uploads, AJAX Photo List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's videowhisper_picture_upload_guest shortcode in all ver… CWE-79
Cross-site Scripting
CVE-2024-12696 2025-01-18 16:15 2025-01-18 Show GitHub Exploit DB Packet Storm