Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 14, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
224721 9.3 危険 FFmpeg - FFmpeg の libavcodec/mjpegdec.c の mjpeg_decode_scan_progressive_ac 関数における脆弱性 CWE-20
不適切な入力確認
CVE-2013-0854 2013-12-11 11:01 2013-07-16 Show GitHub Exploit DB Packet Storm
224722 9.3 危険 FFmpeg - FFmpeg の libavcodec/roqvideodec.c の roq_decode_init 関数における脆弱性 CWE-20
不適切な入力確認
CVE-2013-0849 2013-12-11 10:50 2013-07-16 Show GitHub Exploit DB Packet Storm
224723 9.3 危険 FFmpeg - FFmpeg の libavcodec/qdm2.c の qdm2_decode_super_block 関数における脆弱性 CWE-20
不適切な入力確認
CVE-2013-0846 2013-12-11 10:36 2013-07-16 Show GitHub Exploit DB Packet Storm
224724 9.3 危険 FFmpeg - FFmpeg の libavcodec/alsdec.c における脆弱性 CWE-119
バッファエラー
CVE-2013-0845 2013-12-11 10:33 2013-02-7 Show GitHub Exploit DB Packet Storm
224725 9.3 危険 FFmpeg - FFmpeg の libavcodec/adpcm.c の adpcm_decode_frame 関数における脆弱性 CWE-189
数値処理の問題
CVE-2013-0844 2013-12-11 10:29 2013-02-7 Show GitHub Exploit DB Packet Storm
224726 4.3 警告 Twibright Labs - links における整数オーバーフローの脆弱性 CWE-189
数値処理の問題
CVE-2013-6050 2013-12-11 10:17 2013-05-15 Show GitHub Exploit DB Packet Storm
224727 7.5 危険 Wouter Verhelst - Network Block Device の nbd-server におけるアクセス制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-6410 2013-12-11 09:49 2013-11-29 Show GitHub Exploit DB Packet Storm
224728 6.8 警告 Apache Software Foundation - Apache Roller の ActionSupport コントローラの特定の getText メソッドにおける任意の OGNL 式を実行される脆弱性 CWE-94
コード・インジェクション
CVE-2013-4212 2013-12-10 18:28 2013-11-3 Show GitHub Exploit DB Packet Storm
224729 4.3 警告 Apache Software Foundation - Apache Roller におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-4171 2013-12-10 18:25 2013-11-3 Show GitHub Exploit DB Packet Storm
224730 6.2 警告 Debian - Debian adequate における tty をハイジャックされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-6409 2013-12-10 16:22 2013-11-28 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 15, 2026, 4:10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
197781 5.4 MEDIUM
Network
steam_group_viewer_project steam_group_viewer The Steam Group Viewer WordPress plugin through 2.1 does not sanitise or escape its "Steam Group Address" settings before outputting it in the page, leading to an authenticated Stored Cross-Site Scri… - CVE-2021-24476 2024-11-21 14:53 2021-08-2 Show GitHub Exploit DB Packet Storm
197782 6.1 MEDIUM
Network
awesome_weather_widget_project awesome_weather_widget The Awesome Weather Widget WordPress plugin through 3.0.2 does not sanitize the id parameter of its awesome_weather_refresh AJAX action, leading to an unauthenticated Reflected Cross-Site Scripting (… CWE-79
Cross-site Scripting
CVE-2021-24474 2024-11-21 14:53 2021-08-2 Show GitHub Exploit DB Packet Storm
197783 5.4 MEDIUM
Network
cozmoslabs user_profile_picture The User Profile Picture WordPress plugin before 2.6.0 was affected by an IDOR issue, allowing users with the upload_image capability (by default author and above) to change and delete the profile pi… CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2021-24473 2024-11-21 14:53 2021-08-2 Show GitHub Exploit DB Packet Storm
197784 9.8 CRITICAL
Network
qantumthemes kentharadio
onair2
The OnAir2 WordPress theme before 3.9.9.2 and QT KenthaRadio WordPress plugin before 2.0.2 have exposed proxy functionality to unauthenticated users, sending requests to this proxy functionality will… - CVE-2021-24472 2024-11-21 14:53 2021-08-2 Show GitHub Exploit DB Packet Storm
197785 5.4 MEDIUM
Network
yada_wiki_project yada_wiki The Yada Wiki WordPress plugin before 3.4.1 did not sanitise, validate or escape the anchor attribute of its shortcode, leading to a Stored Cross-Site Scripting issue CWE-79
Cross-site Scripting
CVE-2021-24470 2024-11-21 14:53 2021-08-2 Show GitHub Exploit DB Packet Storm
197786 5.4 MEDIUM
Network
bozdoz leaflet_map The Leaflet Map WordPress plugin before 3.0.0 does not escape some shortcode attributes before they are used in JavaScript code or HTML, which could allow users with a role as low as Contributors to … CWE-79
Cross-site Scripting
CVE-2021-24468 2024-11-21 14:53 2021-08-2 Show GitHub Exploit DB Packet Storm
197787 5.4 MEDIUM
Network
wpdevart youtube_embed\
_playlist_and_popup
The YouTube Embed, Playlist and Popup by WpDevArt WordPress plugin before 2.3.9 did not escape, validate or sanitise some of its shortcode options, available to users with a role as low as Contributo… - CVE-2021-24464 2024-11-21 14:53 2021-08-2 Show GitHub Exploit DB Packet Storm
197788 8.8 HIGH
Network
ays-pro image_slider The get_sliders() function in the Image Slider by Ays- Responsive Slider and Carousel WordPress plugin before 2.5.0 did not use whitelist or validate the orderby parameter before using it in SQL stat… - CVE-2021-24463 2024-11-21 14:53 2021-08-2 Show GitHub Exploit DB Packet Storm
197789 8.8 HIGH
Network
ays-pro photo_gallery The get_gallery_categories() and get_galleries() functions in the Photo Gallery by Ays – Responsive Image Gallery WordPress plugin before 4.4.4 did not use whitelist or validate the orderby parameter… - CVE-2021-24462 2024-11-21 14:53 2021-08-2 Show GitHub Exploit DB Packet Storm
197790 8.8 HIGH
Network
ays-pro faq_builder The get_faqs() function in the FAQ Builder AYS WordPress plugin before 1.3.6 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB c… - CVE-2021-24461 2024-11-21 14:53 2021-08-2 Show GitHub Exploit DB Packet Storm