Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228041 4.3 警告 dkscript - DKScript.com Dragon's Kingdom Script におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2006-3539 2012-12-20 18:02 2006-07-12 Show GitHub Exploit DB Packet Storm
228042 5.8 警告 beatificfaith - BeatificFaith Eprayer Alpha の demo.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-3538 2012-12-20 18:02 2006-07-12 Show GitHub Exploit DB Packet Storm
228043 7.5 危険 randshop - Randshop の index.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-3537 2012-12-20 18:02 2006-07-12 Show GitHub Exploit DB Packet Storm
228044 7.5 危険 ej3 - EJ3 TOPo の code/class_db_text.php における任意の PHP コードを実行される脆弱性 - CVE-2006-3536 2012-12-20 18:02 2006-07-12 Show GitHub Exploit DB Packet Storm
228045 5 警告 Nullsoft - Nullsoft SHOUTcast DSP におけるディレクトリトラバーサルの脆弱性 - CVE-2006-3535 2012-12-20 18:02 2006-07-12 Show GitHub Exploit DB Packet Storm
228046 7.8 危険 Nullsoft - Nullsoft SHOUTcast DSP におけるディレクトリトラバーサルの脆弱性 - CVE-2006-3534 2012-12-20 18:02 2006-07-12 Show GitHub Exploit DB Packet Storm
228047 5.8 警告 pivot - Pivot におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-3533 2012-12-20 18:02 2006-07-12 Show GitHub Exploit DB Packet Storm
228048 5.1 警告 pivot - Pivot の includes/edit_new.php における任意の PHP コードを実行される脆弱性 - CVE-2006-3532 2012-12-20 18:02 2006-07-12 Show GitHub Exploit DB Packet Storm
228049 7.5 危険 pivot - Pivot の includes/editor/insert_image.php における任意のファイルをアップロードされる脆弱性 - CVE-2006-3531 2012-12-20 18:02 2006-07-12 Show GitHub Exploit DB Packet Storm
228050 6.8 警告 Joomla! - Mambo 用の PccookBook Component の com_pccookbook/pccookbook.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2006-3530 2012-12-20 18:02 2006-07-12 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 26, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
211211 8.8 HIGH
Network
simpolio_project simpolio The Simpolio theme 1.3.2 for WordPress has insufficient restrictions on option updates. CWE-276
Incorrect Default Permissions 
CVE-2015-9474 2024-11-21 11:40 2019-10-11 Show GitHub Exploit DB Packet Storm
211212 7.5 HIGH
Network
estrutura-basica_project estrutura-basica The estrutura-basica theme through 2015-09-13 for WordPress has directory traversal via the scripts/download.php arquivo parameter. CWE-22
Path Traversal
CVE-2015-9473 2024-11-21 11:40 2019-10-11 Show GitHub Exploit DB Packet Storm
211213 6.1 MEDIUM
Network
monitorbacklinks incoming_links The incoming-links plugin before 0.9.10b for WordPress has referrers.php XSS via the Referer HTTP header. CWE-79
Cross-site Scripting
CVE-2015-9472 2024-11-21 11:40 2019-10-11 Show GitHub Exploit DB Packet Storm
211214 9.8 CRITICAL
Network
digitalzoomstudio zoomsounds The dzs-zoomsounds plugin through 2.0 for WordPress has admin/upload.php arbitrary file upload. CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2015-9471 2024-11-21 11:40 2019-10-11 Show GitHub Exploit DB Packet Storm
211215 7.5 HIGH
Network
ionadas history_collection The history-collection plugin through 1.1.1 for WordPress has directory traversal via the download.php var parameter. CWE-22
Path Traversal
CVE-2015-9470 2024-11-21 11:40 2019-10-11 Show GitHub Exploit DB Packet Storm
211216 4.8 MEDIUM
Network
cybercraftit content-grabber The content-grabber plugin 1.0 for WordPress has XSS via obj_field_name or obj_field_id. CWE-79
Cross-site Scripting
CVE-2015-9469 2024-11-21 11:40 2019-10-11 Show GitHub Exploit DB Packet Storm
211217 6.1 MEDIUM
Network
k-78 broken_link_manager The broken-link-manager plugin 0.4.5 for WordPress has XSS via the page parameter in a delURL action. CWE-79
Cross-site Scripting
CVE-2015-9468 2024-11-21 11:40 2019-10-11 Show GitHub Exploit DB Packet Storm
211218 9.8 CRITICAL
Network
k-78 broken_link_manager The broken-link-manager plugin before 0.5.0 for WordPress has wpslDelURL or wpslEditURL SQL injection via the url parameter. CWE-89
SQL Injection
CVE-2015-9467 2024-11-21 11:40 2019-10-11 Show GitHub Exploit DB Packet Storm
211219 9.8 CRITICAL
Network
webtechideas wti_like_post The wti-like-post plugin before 1.4.3 for WordPress has WtiLikePostProcessVote SQL injection via the HTTP_CLIENT_IP, HTTP_X_FORWARDED_FOR, HTTP_X_FORWARDED, HTTP_FORWARDED_FOR, or HTTP_FORWARDED vari… CWE-89
SQL Injection
CVE-2015-9466 2024-11-21 11:40 2019-10-11 Show GitHub Exploit DB Packet Storm
211220 8.8 HIGH
Network
yet_another_stars_rating_project yet_another_stars_rating The yet-another-stars-rating plugin before 0.9.1 for WordPress has yasr_get_multi_set_values_and_field SQL injection via the set_id parameter. CWE-89
SQL Injection
CVE-2015-9465 2024-11-21 11:40 2019-10-11 Show GitHub Exploit DB Packet Storm