Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 15, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
224281 4.9 警告 Linux - Linux Kernel の net/ieee802154/dgram.c 内の dgram_recvmsg 関数における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2013-7281 2014-01-10 14:00 2013-12-8 Show GitHub Exploit DB Packet Storm
224282 4.3 警告 FolioVision - WordPress 用 Foliopress WYSIWYG プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-1232 2014-01-10 13:46 2014-01-3 Show GitHub Exploit DB Packet Storm
224283 6.8 警告 Technicolor - Technicolor TC7200 におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2014-0621 2014-01-10 13:39 2014-01-3 Show GitHub Exploit DB Packet Storm
224284 4.3 警告 Technicolor - Technicolor TC7200 におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-0620 2014-01-10 13:39 2014-01-3 Show GitHub Exploit DB Packet Storm
224285 5 警告 7 Media Web Solutions, LLC. - 7 Media Web Solutions の eduTrac におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2013-7097 2014-01-10 11:37 2013-12-16 Show GitHub Exploit DB Packet Storm
224286 4.3 警告 Anthony Mills - WordPress 用 S3 Video プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-7279 2014-01-10 11:01 2013-12-17 Show GitHub Exploit DB Packet Storm
224287 7.5 危険 Naxtech - Naxtech CMS Afroditi における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2013-7278 2014-01-10 10:39 2013-12-30 Show GitHub Exploit DB Packet Storm
224288 5.8 警告 Mozilla Foundation - Mozilla Firefox の Web App インストレーションサイトになりすまされる脆弱性 CWE-noinfo
情報不足
CVE-2013-5611 2014-01-10 09:44 2013-12-10 Show GitHub Exploit DB Packet Storm
224289 10 危険 Mozilla Foundation - Mozilla Firefox および SeaMonkey のブラウザエンジンにおけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2013-5610 2014-01-10 09:44 2013-12-10 Show GitHub Exploit DB Packet Storm
224290 7.8 危険 シスコシステムズ - Cisco Adaptive Security Appliance ソフトウェアの Clientless SSL VPN 機能におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2013-5515 2014-01-10 09:43 2013-10-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 16, 2026, 4:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
197711 5.4 MEDIUM
Network
ayecode geodirectory The GeoDirectory Business Directory WordPress plugin before 2.1.1.3 was vulnerable to Authenticated Stored Cross-Site Scripting (XSS). - CVE-2021-24720 2024-11-21 14:53 2021-10-11 Show GitHub Exploit DB Packet Storm
197712 6.1 MEDIUM
Network
kriesi enfold The Enfold Enfold WordPress theme before 4.8.4 was vulnerable to Reflected Cross-Site Scripting (XSS). The vulnerability is present on Enfold versions previous than 4.8.4 which use Avia Page Builder. CWE-79
Cross-site Scripting
CVE-2021-24719 2024-11-21 14:53 2021-10-11 Show GitHub Exploit DB Packet Storm
197713 5.4 MEDIUM
Network
dwbooster appointment_hour_booking The Appointment Hour Booking WordPress plugin before 1.3.17 does not properly sanitize values used when creating new calendars. CWE-79
Cross-site Scripting
CVE-2021-24712 2024-11-21 14:53 2021-10-11 Show GitHub Exploit DB Packet Storm
197714 8.8 HIGH
Network
tipsandtricks-hq software_license_manager The del_reistered_domains AJAX action of the Software License Manager WordPress plugin before 4.5.1 does not have any CSRF checks, and is vulnerable to a CSRF attack - CVE-2021-24711 2024-11-21 14:53 2021-10-11 Show GitHub Exploit DB Packet Storm
197715 4.8 MEDIUM
Network
awplife weather_effect The Weather Effect WordPress plugin before 1.3.6 does not properly validate and escape some of its settings (like *_size_leaf, *_flakes_leaf, *_speed) which could lead to Stored Cross-Site Scripting … - CVE-2021-24709 2024-11-21 14:53 2021-10-11 Show GitHub Exploit DB Packet Storm
197716 4.8 MEDIUM
Network
expresstech quiz_and_survey_master The Quiz And Survey Master WordPress plugin before 7.3.2 does not escape the Quiz Url Slug setting before outputting it in some pages, which could allow high privilege users to perform Cross-Site Scr… - CVE-2021-24691 2024-11-21 14:53 2021-10-11 Show GitHub Exploit DB Packet Storm
197717 5.4 MEDIUM
Network
kibokolabs chained_quiz The Chained Quiz WordPress plugin before 1.2.7.2 does not properly sanitize or escape inputs in the plugin's settings. - CVE-2021-24690 2024-11-21 14:53 2021-10-11 Show GitHub Exploit DB Packet Storm
197718 5.4 MEDIUM
Network
awplife weather_effect The Weather Effect WordPress plugin before 1.3.4 does not have any CSRF checks in place when saving its settings, and do not validate or escape them, which could lead to Stored Cross-Site Scripting i… CWE-352
CWE-79
 Origin Validation Error
Cross-site Scripting
CVE-2021-24683 2024-11-21 14:53 2021-10-11 Show GitHub Exploit DB Packet Storm
197719 4.8 MEDIUM
Network
duplicatepro duplicate_page The Duplicate Page WordPress plugin through 4.4.2 does not sanitise or escape the Duplicate Post Suffix settings before outputting it, which could allow high privilege users to perform Stored Cross-S… - CVE-2021-24681 2024-11-21 14:53 2021-10-11 Show GitHub Exploit DB Packet Storm
197720 4.8 MEDIUM
Network
wpbrigade simple_social_buttons The Simple Social Media Share Buttons WordPress plugin before 3.2.4 does not escape the Share Title settings before outputting it in the frontend pages or posts (depending on the settings used), allo… - CVE-2021-24656 2024-11-21 14:53 2021-10-11 Show GitHub Exploit DB Packet Storm