Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 7, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
227081 6.4 警告 The phpMyAdmin Project - phpMyAdmin におけるなりすましされる脆弱性 CWE-59
リンク解釈の問題
CVE-2008-3456 2012-12-20 18:52 2008-07-28 Show GitHub Exploit DB Packet Storm
227082 4 警告 phpwebgallery - PhpWebGallery における他のユーザの電子メールアドレスを取得される脆弱性 CWE-200
情報漏えい
CVE-2008-3451 2012-12-20 18:52 2008-08-4 Show GitHub Exploit DB Packet Storm
227083 7.5 危険 phpmyrealty - PMR の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3445 2012-12-20 18:52 2008-08-4 Show GitHub Exploit DB Packet Storm
227084 7.5 危険 winzip - WinZip における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2008-3442 2012-12-20 18:52 2008-08-1 Show GitHub Exploit DB Packet Storm
227085 7.5 危険 サン・マイクロシステムズ - Sun Java における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2008-3440 2012-12-20 18:52 2008-08-1 Show GitHub Exploit DB Packet Storm
227086 7.5 危険 speedbit - SpeedBit Video Acceleration における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2008-3439 2012-12-20 18:52 2008-08-1 Show GitHub Exploit DB Packet Storm
227087 7.5 危険 speedbit - SpeedBit DAP における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2008-3433 2012-12-20 18:52 2008-08-1 Show GitHub Exploit DB Packet Storm
227088 5 警告 Vtiger - Vtiger CRM におけるメールマージテンプレートを読まれる脆弱性 CWE-200
情報漏えい
CVE-2008-3458 2012-12-20 18:52 2006-09-9 Show GitHub Exploit DB Packet Storm
227089 7.2 危険 サン・マイクロシステムズ - IOCTL 用の METHOD_NEITHER 通信メソッドで使用されている Sun xVM VirtualBox における権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-3431 2012-12-20 18:52 2008-08-5 Show GitHub Exploit DB Packet Storm
227090 6.5 警告 PhpFreeChat - phpFreeChat におけるセッションをハイジャックされる脆弱性 CWE-287
不適切な認証
CVE-2008-3428 2012-12-20 18:52 2008-07-31 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 8, 2026, 4:54 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
223431 7.5 HIGH
Network
metabox meta_box The Meta Box plugin before 4.16.2 for WordPress mishandles the uploading of files to custom folders. CWE-19
 Data Processing Errors
CVE-2019-14794 2024-11-21 13:27 2019-08-9 Show GitHub Exploit DB Packet Storm
223432 6.1 MEDIUM
Network
codepeople appointment_booking_calendar The Appointment Booking Calendar plugin 1.3.18 for WordPress allows XSS via the wp-admin/admin-post.php editionarea parameter. CWE-79
Cross-site Scripting
CVE-2019-14791 2024-11-21 13:27 2019-08-9 Show GitHub Exploit DB Packet Storm
223433 6.1 MEDIUM
Network
foliovision fv_flowplayer_video_player The FV Flowplayer Video Player plugin before 7.3.14.727 for WordPress allows email subscription XSS. CWE-79
Cross-site Scripting
CVE-2019-14799 2024-11-21 13:27 2019-08-9 Show GitHub Exploit DB Packet Storm
223434 6.5 MEDIUM
Network
metabox meta_box The Meta Box plugin before 4.16.3 for WordPress allows file deletion via ajax, with the wp-admin/admin-ajax.php?action=rwmb_delete_file attachment_id parameter. CWE-862
 Missing Authorization
CVE-2019-14793 2024-11-21 13:27 2019-08-9 Show GitHub Exploit DB Packet Storm
223435 5.4 MEDIUM
Network
codecabin wp_go_maps The WP Google Maps plugin before 7.11.35 for WordPress allows XSS via the wp-admin/ rectangle_name or rectangle_opacity parameter. CWE-79
Cross-site Scripting
CVE-2019-14792 2024-11-21 13:27 2019-08-9 Show GitHub Exploit DB Packet Storm
223436 5.4 MEDIUM
Network
tribulant newsletters The Tribulant Newsletters plugin before 4.6.19 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=newsletters_load_new_editor contentarea parameter. CWE-79
Cross-site Scripting
CVE-2019-14787 2024-11-21 13:27 2019-08-9 Show GitHub Exploit DB Packet Storm
223437 5.4 MEDIUM
Network
codepeople cp_contact_form_with_paypal The "CP Contact Form with PayPal" plugin before 1.2.99 for WordPress has XSS in the publishing wizard via the wp-admin/admin.php?page=cp_contact_form_paypal.php&pwizard=1 cp_contactformpp_id paramete… CWE-79
Cross-site Scripting
CVE-2019-14785 2024-11-21 13:27 2019-08-9 Show GitHub Exploit DB Packet Storm
223438 5.5 MEDIUM
Local
google android On Samsung mobile devices with N(7.x), and O(8.x), P(9.0) software, FotaAgent allows a malicious application to create privileged files. The Samsung ID is SVE-2019-14764. NVD-CWE-noinfo
CVE-2019-14783 2024-11-21 13:27 2019-08-9 Show GitHub Exploit DB Packet Storm
223439 6.1 MEDIUM
Network
getwooplugins woo-variation-swatches The woo-variation-swatches (aka Variation Swatches for WooCommerce) plugin 1.0.61 for WordPress allows XSS via the wp-admin/admin.php?page=woo-variation-swatches-settings tab parameter. CWE-79
Cross-site Scripting
CVE-2019-14774 2024-11-21 13:27 2019-08-9 Show GitHub Exploit DB Packet Storm
223440 7.5 HIGH
Network
webcraftic woody_ad_snippets admin/includes/class.actions.snippet.php in the "Woody ad snippets" plugin through 2.2.5 for WordPress allows wp-admin/admin-post.php?action=close&post= deletion. NVD-CWE-noinfo
CVE-2019-14773 2024-11-21 13:27 2019-08-9 Show GitHub Exploit DB Packet Storm