Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 23, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
227601 4.3 警告 Tenable, Inc. - Tenable SecurityCenter の devform.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-5911 2013-09-26 11:50 2013-09-23 Show GitHub Exploit DB Packet Storm
227602 5.4 警告 シスコシステムズ - Cisco Unified Computing System のファブリックインターコネクトにおけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2012-4094 2013-09-26 11:49 2013-09-24 Show GitHub Exploit DB Packet Storm
227603 6.6 警告 シスコシステムズ - Cisco Unified Computing System における任意の Baseboard Management Controller コマンドを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2012-4089 2013-09-26 11:48 2013-09-24 Show GitHub Exploit DB Packet Storm
227604 5.1 警告 シスコシステムズ - Cisco Unified Computing System のファブリックインターコネクトデバイスのセットアップスクリプトにおける任意のコマンドを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2012-4087 2013-09-26 11:47 2013-09-24 Show GitHub Exploit DB Packet Storm
227605 5 警告 シスコシステムズ - Cisco Unified Computing System の Blade Management Controller における有効なユーザ名を列挙される脆弱性 CWE-20
不適切な入力確認
CVE-2012-4085 2013-09-26 11:47 2013-09-24 Show GitHub Exploit DB Packet Storm
227606 8.5 危険 シスコシステムズ - Cisco Unified Computing System の Baseboard Management Controller における不特定の認証のステップを回避される脆弱性 CWE-287
不適切な認証
CVE-2012-4078 2013-09-26 11:46 2013-09-24 Show GitHub Exploit DB Packet Storm
227607 10 危険 ソフォス - Sophos UTM の WebAdmin における脆弱性 CWE-noinfo
情報不足
CVE-2013-5932 2013-09-26 11:46 2013-08-21 Show GitHub Exploit DB Packet Storm
227608 7.5 危険 Real Estate PHP Script - Real Estate PHP Script の property_listings_detail.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2013-5931 2013-09-26 11:45 2013-09-23 Show GitHub Exploit DB Packet Storm
227609 4.3 警告 Real Estate PHP Script - Real Estate PHP Script の search_residential.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-5930 2013-09-26 11:44 2013-09-23 Show GitHub Exploit DB Packet Storm
227610 6.8 警告 Zimbra - Zimbra Collaboration Suite におけるアクセス権を取得される脆弱性 CWE-287
不適切な認証
CVE-2013-5119 2013-09-26 11:22 2013-09-13 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 23, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
319461 - - - Directory Traversal vulnerability in Centro de Tecnologia da Informaco Renato Archer InVesalius3 v3.1.99995 allows attackers to write arbitrary files unto the system via a crafted .inv3 file. - CVE-2024-44825 2024-09-27 01:35 2024-09-26 Show GitHub Exploit DB Packet Storm
319462 9.8 CRITICAL
Network
code-projects student_record_system A vulnerability was found in code-projects Student Record System 1.0. It has been classified as critical. Affected is an unknown function of the file /pincode-verification.php. The manipulation of th… CWE-89
SQL Injection
CVE-2024-9080 2024-09-27 01:32 2024-09-22 Show GitHub Exploit DB Packet Storm
319463 9.8 CRITICAL
Network
code-projects student_record_system A vulnerability was found in code-projects Student Record System 1.0 and classified as critical. This issue affects some unknown processing of the file /marks.php. The manipulation of the argument co… CWE-89
SQL Injection
CVE-2024-9079 2024-09-27 01:32 2024-09-22 Show GitHub Exploit DB Packet Storm
319464 9.8 CRITICAL
Network
code-projects student_record_system A vulnerability has been found in code-projects Student Record System 1.0 and classified as critical. This vulnerability affects unknown code of the file /course.php. The manipulation of the argument… CWE-89
SQL Injection
CVE-2024-9078 2024-09-27 01:31 2024-09-22 Show GitHub Exploit DB Packet Storm
319465 4.3 MEDIUM
Network
infiniteuploads big_file_uploads The Big File Uploads – Increase Maximum File Upload Size plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.1.2. This is due the plugin not sanitizing … CWE-22
Path Traversal
CVE-2024-8538 2024-09-27 01:28 2024-09-7 Show GitHub Exploit DB Packet Storm
319466 9.8 CRITICAL
Network
wpcharitable charitable The Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.8.1.14. Thi… CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2024-8791 2024-09-27 01:25 2024-09-24 Show GitHub Exploit DB Packet Storm
319467 5.3 MEDIUM
Network
ba-booking ba_book_everything The BA Book Everything plugin for WordPress is vulnerable to arbitrary password reset in all versions up to, and including, 1.6.20. This is due to the reset_user_password() function not verifying a u… NVD-CWE-Other
CVE-2024-8794 2024-09-27 01:23 2024-09-24 Show GitHub Exploit DB Packet Storm
319468 6.1 MEDIUM
Network
ninjaforms ninja_forms_file_uploads The Ninja Forms - File Uploads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded file (e.g. RTX file) in all versions up to, and including, 3.3.16 due to insufficient … CWE-79
Cross-site Scripting
CVE-2024-1596 2024-09-27 01:23 2024-09-7 Show GitHub Exploit DB Packet Storm
319469 5.4 MEDIUM
Network
master-addons master_addons The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-jltma-wrapper-link element… CWE-79
Cross-site Scripting
CVE-2024-6282 2024-09-27 01:19 2024-09-10 Show GitHub Exploit DB Packet Storm
319470 - - - Mellium mellium.im/xmpp 0.0.1 through 0.21.4 allows response spoofing if the implementation uses predictable IDs because the stanza type is not checked. This is fixed in 0.22.0. - CVE-2024-46957 2024-09-27 01:15 2024-09-25 Show GitHub Exploit DB Packet Storm