Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 13, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
226971 7.5 危険 smartsitecms - smartSite CMS の articles.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-0405 2012-12-20 19:10 2009-02-3 Show GitHub Exploit DB Packet Storm
226972 6.8 警告 socialengine - SocialEngine の blog.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-0400 2012-12-20 19:10 2009-02-3 Show GitHub Exploit DB Packet Storm
226973 7.8 危険 sony ericsson - Sony Ericsson W910i などの電話機におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2009-0396 2012-12-20 19:10 2009-02-2 Show GitHub Exploit DB Packet Storm
226974 7.5 危険 ple cms - PLEs CMS の login.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-0394 2012-12-20 19:10 2009-02-2 Show GitHub Exploit DB Packet Storm
226975 6.8 警告 sitexs cms - SiteXS CMS の post.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2009-0371 2012-12-20 19:10 2009-01-30 Show GitHub Exploit DB Packet Storm
226976 9.3 危険 wesnoth - Wesnoth の Python AI モジュールにおけるサンドボックスをエスケープされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2009-0367 2012-12-20 19:10 2009-03-2 Show GitHub Exploit DB Packet Storm
226977 4.3 警告 wesnoth - Wesnoth の src/server/simple_wml.cpp におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2009-0366 2012-12-20 19:10 2009-03-12 Show GitHub Exploit DB Packet Storm
226978 9 危険 WING FTP software - WinFTP の WFTPSRV.exe におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-0351 2012-12-20 19:10 2009-01-29 Show GitHub Exploit DB Packet Storm
226979 7.2 危険 Niels Provos - x86_64 Linux 上で稼動している Niels Provos Systrace におけるアクセス制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2009-0342 2012-12-20 19:10 2009-01-29 Show GitHub Exploit DB Packet Storm
226980 6.8 警告 Quirm - Simple PHP Newsletter におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2009-0340 2012-12-20 19:10 2009-01-29 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 13, 2026, 5:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
224031 8.8 HIGH
Network
wp-buy visitor_traffic_real_time_statistics The visitors-traffic-real-time-statistics plugin before 1.13 for WordPress has CSRF. CWE-352
 Origin Validation Error
CVE-2019-15832 2024-11-21 13:29 2019-08-30 Show GitHub Exploit DB Packet Storm
224032 8.8 HIGH
Network
wp-buy visitor_traffic_real_time_statistics The visitors-traffic-real-time-statistics plugin before 1.12 for WordPress has CSRF in the settings page. CWE-352
 Origin Validation Error
CVE-2019-15831 2024-11-21 13:29 2019-08-30 Show GitHub Exploit DB Packet Storm
224033 5.4 MEDIUM
Network
icegram icegram_engage The icegram plugin before 1.10.29 for WordPress has ig_cat_list XSS. CWE-79
Cross-site Scripting
CVE-2019-15830 2024-11-21 13:29 2019-08-30 Show GitHub Exploit DB Packet Storm
224034 4.8 MEDIUM
Network
greentreelabs gallery_photoblocks The photoblocks-grid-gallery plugin before 1.1.33 for WordPress has wp-admin/admin.php?page=photoblocks-edit&id= XSS. CWE-79
Cross-site Scripting
CVE-2019-15829 2024-11-21 13:29 2019-08-30 Show GitHub Exploit DB Packet Storm
224035 8.8 HIGH
Network
tribulant one_click_ssl The one-click-ssl plugin before 1.4.7 for WordPress has CSRF. CWE-352
 Origin Validation Error
CVE-2019-15828 2024-11-21 13:29 2019-08-30 Show GitHub Exploit DB Packet Storm
224036 5.4 MEDIUM
Network
onesignal onesignal-free-web-push-notifications The onesignal-free-web-push-notifications plugin before 1.17.8 for WordPress has XSS via the subdomain parameter. CWE-79
Cross-site Scripting
CVE-2019-15827 2024-11-21 13:29 2019-08-30 Show GitHub Exploit DB Packet Storm
224037 9.8 CRITICAL
Network
wpserveur wps_hide_login The wps-hide-login plugin before 1.5.3 for WordPress has a protection bypass via wp-login.php in the Referer field. NVD-CWE-noinfo
CVE-2019-15826 2024-11-21 13:29 2019-08-30 Show GitHub Exploit DB Packet Storm
224038 9.8 CRITICAL
Network
wpserveur wps_hide_login The wps-hide-login plugin before 1.5.3 for WordPress has an action=rp&key&login protection bypass. NVD-CWE-noinfo
CVE-2019-15825 2024-11-21 13:29 2019-08-30 Show GitHub Exploit DB Packet Storm
224039 9.8 CRITICAL
Network
wpserveur wps_hide_login The wps-hide-login plugin before 1.5.3 for WordPress has an adminhash protection bypass. NVD-CWE-noinfo
CVE-2019-15824 2024-11-21 13:29 2019-08-30 Show GitHub Exploit DB Packet Storm
224040 9.8 CRITICAL
Network
wpserveur wps_hide_login The wps-hide-login plugin before 1.5.3 for WordPress has an action=confirmaction protection bypass. NVD-CWE-noinfo
CVE-2019-15823 2024-11-21 13:29 2019-08-30 Show GitHub Exploit DB Packet Storm