Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 16, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228281 7.5 危険 select development solutions - PHP Auto Dealer の view_cat.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-4495 2012-12-20 18:52 2008-10-8 Show GitHub Exploit DB Packet Storm
228282 7.5 危険 torrenttrader - TorrentTrader Classic の completed-advance.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-4494 2012-12-20 18:52 2008-10-8 Show GitHub Exploit DB Packet Storm
228283 7.5 危険 yourownbux - YourOwnBux の referrals.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-4492 2012-12-20 18:52 2008-10-8 Show GitHub Exploit DB Packet Storm
228284 10 危険 yerba - Yerba で使用される SACphp の index.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-4486 2012-12-20 18:52 2008-10-7 Show GitHub Exploit DB Packet Storm
228285 6.9 警告 Sympa - sympa の sympa.pl における任意のファイルを上書きされる脆弱性 CWE-59
リンク解釈の問題
CVE-2008-4476 2012-12-20 18:52 2008-10-7 Show GitHub Exploit DB Packet Storm
228286 7.5 危険 Vastal I-Tech & Co. - Vastal I-Tech Freelance Zone の view_cresume.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-4469 2012-12-20 18:52 2008-10-6 Show GitHub Exploit DB Packet Storm
228287 7.5 危険 Vastal I-Tech & Co. - Vastal I-Tech Share Zone の view_news.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-4468 2012-12-20 18:52 2008-10-6 Show GitHub Exploit DB Packet Storm
228288 7.5 危険 Vastal I-Tech & Co. - Vastal I-Tech Toner Cart の show_series_ink.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-4467 2012-12-20 18:52 2008-10-6 Show GitHub Exploit DB Packet Storm
228289 7.5 危険 Vastal I-Tech & Co. - Vastal I-Tech Cosmetics Zone の view_products_cat.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-4466 2012-12-20 18:52 2008-10-6 Show GitHub Exploit DB Packet Storm
228290 7.5 危険 Vastal I-Tech & Co. - Vastal I-Tech DVD Zone の view_mags.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-4465 2012-12-20 18:52 2008-10-6 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 17, 2026, 4:15 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
225091 8.8 HIGH
Network
facebook facebook_for_woocommerce The facebook-for-woocommerce plugin before 1.9.15 for WordPress has CSRF via ajax_woo_infobanner_post_click, ajax_woo_infobanner_post_xout, or ajax_fb_toggle_visibility. CWE-352
 Origin Validation Error
CVE-2019-15841 2024-11-21 13:29 2019-08-31 Show GitHub Exploit DB Packet Storm
225092 8.8 HIGH
Network
facebook facebook_for_woocommerce The facebook-for-woocommerce plugin before 1.9.14 for WordPress has CSRF. CWE-352
 Origin Validation Error
CVE-2019-15840 2024-11-21 13:29 2019-08-31 Show GitHub Exploit DB Packet Storm
225093 7.5 HIGH
Network
shaosina sina_extension_for_elementor The sina-extension-for-elementor plugin before 2.2.1 for WordPress has local file inclusion. CWE-22
CWE-829
Path Traversal
 Inclusion of Functionality from Untrusted Control Sphere
CVE-2019-15839 2024-11-21 13:29 2019-08-31 Show GitHub Exploit DB Packet Storm
225094 6.1 MEDIUM
Network
kunalnagar custom_404_pro The custom-404-pro plugin before 3.2.8 for WordPress has reflected XSS, a different vulnerability than CVE-2019-14789. CWE-79
Cross-site Scripting
CVE-2019-15838 2024-11-21 13:29 2019-08-31 Show GitHub Exploit DB Packet Storm
225095 5.4 MEDIUM
Network
bitwise-it webp_express The webp-express plugin before 0.14.8 for WordPress has stored XSS. CWE-79
Cross-site Scripting
CVE-2019-15837 2024-11-21 13:29 2019-08-31 Show GitHub Exploit DB Packet Storm
225096 5.4 MEDIUM
Network
bootstrapped wp_ultimate_recipe The wp-ultimate-recipe plugin before 3.12.7 for WordPress has stored XSS. CWE-79
Cross-site Scripting
CVE-2019-15836 2024-11-21 13:29 2019-08-31 Show GitHub Exploit DB Packet Storm
225097 8.8 HIGH
Network
wp_better_permalinks_project wp_better_permalinks The wp-better-permalinks plugin before 3.0.5 for WordPress has CSRF. CWE-352
 Origin Validation Error
CVE-2019-15835 2024-11-21 13:29 2019-08-31 Show GitHub Exploit DB Packet Storm
225098 8.8 HIGH
Network
webp_converter_for_media_project webp_converter_for_media The webp-converter-for-media plugin before 1.0.3 for WordPress has CSRF. CWE-352
 Origin Validation Error
CVE-2019-15834 2024-11-21 13:29 2019-08-31 Show GitHub Exploit DB Packet Storm
225099 7.5 HIGH
Network
mulesoft mule_runtime
api_gateway
Directory Traversal in APIkit, HTTP connector, and OAuth2 Provider components in MuleSoft Mule Runtime 3.2.0 and higher released before August 1 2019, MuleSoft Mule Runtime 4.1.0 and higher released … CWE-22
Path Traversal
CVE-2019-15630 2024-11-21 13:29 2019-08-31 Show GitHub Exploit DB Packet Storm
225100 6.1 MEDIUM
Network
simple_mail_address_encoder_project simple_mail_address_encoder The simple-mail-address-encoder plugin before 1.7 for WordPress has reflected XSS. CWE-79
Cross-site Scripting
CVE-2019-15833 2024-11-21 13:29 2019-08-30 Show GitHub Exploit DB Packet Storm