Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 4, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228511 7.5 危険 TYPO3 Association - TYPO3 用の SBbanner エクステンションにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-4969 2012-12-20 19:28 2010-07-28 Show GitHub Exploit DB Packet Storm
228512 7.5 危険 thomas waggershauser - TYPO3 用の AIRware Lexicon エクステンションにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-4965 2012-12-20 19:28 2010-07-28 Show GitHub Exploit DB Packet Storm
228513 5 警告 ViewVC - ViewVC における非公開 root 名を発見される脆弱性 CWE-200
情報漏えい
CVE-2010-0004 2012-12-20 19:28 2009-12-2 Show GitHub Exploit DB Packet Storm
228514 4.3 警告 Urs Wolfer - kwebkitpart の webkitpart.cpp におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4976 2012-12-20 19:28 2009-12-5 Show GitHub Exploit DB Packet Storm
228515 3.5 注意 TYPO3 Association - TYPO3 用の Commerce エクステンションにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4963 2012-12-20 19:28 2010-07-28 Show GitHub Exploit DB Packet Storm
228516 7.5 危険 stefan koch - TYPO3 用の t3m エクステンションにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-4959 2012-12-20 19:28 2010-07-28 Show GitHub Exploit DB Packet Storm
228517 4.3 警告 wapplersystems - TYPO3 用の Visitor Tracking エクステンションにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4956 2012-12-20 19:28 2010-07-22 Show GitHub Exploit DB Packet Storm
228518 7.5 危険 thomas hempel - TYPO3 用の ultraCards エクステンションにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-4955 2012-12-20 19:28 2010-07-22 Show GitHub Exploit DB Packet Storm
228519 7.5 危険 websedit - TYPO3 用の sk_calendar エクステンションにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-4954 2012-12-20 19:28 2010-07-22 Show GitHub Exploit DB Packet Storm
228520 4.3 警告 stefan geith - TYPO3 用の sg_userdata エクステンションにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4953 2012-12-20 19:28 2010-07-22 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 5, 2026, 4:11 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
194501 5.4 MEDIUM
Network
fivestarplugins five_star_restaurant_reservations The Five Star Restaurant Reservations WordPress plugin before 2.4.8 does not have capability and CSRF checks in the rtb_welcome_set_schedule AJAX action, allowing any authenticated users to call it. … - CVE-2021-24965 2024-11-21 14:54 2022-01-24 Show GitHub Exploit DB Packet Storm
194502 8.0 HIGH
Network
wp_extra_file_types_project wp_extra_file_types The WP Extra File Types WordPress plugin before 0.5.1 does not have CSRF check when saving its settings, nor sanitise and escape some of them, which could allow attackers to make a logged in admin ch… - CVE-2021-24936 2024-11-21 14:54 2022-01-24 Show GitHub Exploit DB Packet Storm
194503 6.1 MEDIUM
Network
brevo newsletter\
_smtp\
_email_marketing_and_subscribe
The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.25 does not escape the sib-statistics-date parameter before outputting it back in an attribute, lea… - CVE-2021-24923 2024-11-21 14:54 2022-01-24 Show GitHub Exploit DB Packet Storm
194504 5.4 MEDIUM
Network
pluginops landing_page The Landing Page Builder WordPress plugin before 1.4.9.6 was affected by a reflected XSS in page-builder-add on the ulpb_post admin page. - CVE-2021-25067 2024-11-21 14:54 2022-01-17 Show GitHub Exploit DB Packet Storm
194505 5.4 MEDIUM
Network
smashballoon smash_balloon_social_post_feed The Smash Balloon Social Post Feed WordPress plugin before 4.1.1 was affected by a reflected XSS in custom-facebook-feed in cff-top admin page. - CVE-2021-25065 2024-11-21 14:54 2022-01-17 Show GitHub Exploit DB Packet Storm
194506 5.4 MEDIUM
Network
wpbookingsystem wp_booking_system The WP Booking System WordPress plugin before 2.0.15 was affected by a reflected xss in wp-booking-system on the wpbs-calendars admin page. - CVE-2021-25061 2024-11-21 14:54 2022-01-17 Show GitHub Exploit DB Packet Storm
194507 5.4 MEDIUM
Network
webnus modern_events_calendar_lite The Modern Events Calendar Lite WordPress plugin before 6.2.0 alloed any logged-in user, even a subscriber user, may add a category whose parameters are incorrectly escaped in the admin panel, leadin… - CVE-2021-25046 2024-11-21 14:54 2022-01-17 Show GitHub Exploit DB Packet Storm
194508 6.5 MEDIUM
Network
aioseo all_in_one_seo The All in One SEO WordPress plugin before 4.1.5.3 is affected by an authenticated SQL injection issue, which was discovered during an internal audit by the Jetpack Scan team, and could grant attacke… - CVE-2021-25037 2024-11-21 14:54 2022-01-17 Show GitHub Exploit DB Packet Storm
194509 8.8 HIGH
Network
aioseo all_in_one_seo The All in One SEO WordPress plugin before 4.1.5.3 is affected by a Privilege Escalation issue, which was discovered during an internal audit by the Jetpack Scan team, and may grant bad actors access… CWE-178
 Improper Handling of Case Sensitivity
CVE-2021-25036 2024-11-21 14:54 2022-01-17 Show GitHub Exploit DB Packet Storm
194510 4.3 MEDIUM
Network
theeventscalendar eventcalendar The EventCalendar WordPress plugin before 1.1.51 does not have proper authorisation and CSRF checks in the add_calendar_event AJAX actions, allowing users with a role as low as subscriber to create e… - CVE-2021-25025 2024-11-21 14:54 2022-01-17 Show GitHub Exploit DB Packet Storm