Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 17, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228761 6.8 警告 smeego - Smeego の index.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-2352 2012-12-20 18:52 2008-05-20 Show GitHub Exploit DB Packet Storm
228762 7.5 危険 WebManager Pro - CMS WebManager-Pro の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2351 2012-12-20 18:52 2008-05-20 Show GitHub Exploit DB Packet Storm
228763 7.5 危険 zomp - Zomplog における管理アクセス権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-2349 2012-12-20 18:52 2008-05-20 Show GitHub Exploit DB Packet Storm
228764 10 危険 TYPO3 Association - TYPO3 用の air_filemanager エクステンションにおける任意の PHP コードされる脆弱性 CWE-94
コード・インジェクション
CVE-2008-2345 2012-12-20 18:52 2008-05-19 Show GitHub Exploit DB Packet Storm
228765 4.3 警告 TYPO3 Association - TYPO3 用の air_filemanager エクステンションにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-2344 2012-12-20 18:52 2008-05-19 Show GitHub Exploit DB Packet Storm
228766 7.5 危険 turnkey web tools - Turnkey Web Tools SunShop Shopping Cart の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2339 2012-12-20 18:52 2008-05-19 Show GitHub Exploit DB Packet Storm
228767 4.3 警告 Vastal I-Tech & Co. - Vastal I-Tech phpVID の search_results.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-2335 2012-12-20 18:52 2008-05-19 Show GitHub Exploit DB Packet Storm
228768 7.5 危険 phpway - Kostenloses Linkmanagementscript における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-2301 2012-12-20 18:52 2008-05-18 Show GitHub Exploit DB Packet Storm
228769 7.5 危険 加藤和良 - Web Slider の Admin.php における認証を回避される脆弱性 CWE-287
不適切な認証
CVE-2008-2298 2012-12-20 18:52 2008-05-18 Show GitHub Exploit DB Packet Storm
228770 7.5 危険 roticv - Rantx の admin.php における認証を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-2297 2012-12-20 18:52 2008-05-18 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 18, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
311521 6.3 MEDIUM
Network
icegram email_subscribers_\&_newsletters The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up … CWE-94
Code Injection
CVE-2024-8254 2024-10-9 04:08 2024-10-2 Show GitHub Exploit DB Packet Storm
311522 6.1 MEDIUM
Network
yoginetwork rabbitloader The RabbitLoader – Website Speed Optimization for improving Core Web Vital metrics with Cache, Image Optimization, and more plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to… CWE-79
Cross-site Scripting
CVE-2024-8800 2024-10-9 03:59 2024-10-2 Show GitHub Exploit DB Packet Storm
311523 6.1 MEDIUM
Network
themes4wp popularis_extra The Popularis Extra plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up … CWE-79
Cross-site Scripting
CVE-2024-9353 2024-10-9 03:50 2024-10-4 Show GitHub Exploit DB Packet Storm
311524 5.4 MEDIUM
Network
iworks pwa The PWA — easy way to Progressive Web App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.6.3 due to insufficient input … CWE-79
Cross-site Scripting
CVE-2024-8967 2024-10-9 03:47 2024-10-2 Show GitHub Exploit DB Packet Storm
311525 7.5 HIGH
Network
cisco meraki_mx65_firmware
meraki_mx64_firmware
meraki_z4c_firmware
meraki_z4_firmware
meraki_z3c_firmware
meraki_z3_firmware
meraki_vmx_firmware
meraki_mx600_firmware
meraki_mx450_…
A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a DoS condition on … CWE-400
 Uncontrolled Resource Consumption
CVE-2024-20502 2024-10-9 03:46 2024-10-3 Show GitHub Exploit DB Packet Storm
311526 6.5 MEDIUM
Network
soplanning soplanning SQL injection vulnerability in SOPlanning <1.45, via /soplanning/www/user_groupes.php in the by parameter, which could allow a remote user to submit a specially crafted query, allowing an attacker to… CWE-89
SQL Injection
CVE-2024-9574 2024-10-9 03:45 2024-10-8 Show GitHub Exploit DB Packet Storm
311527 6.5 MEDIUM
Network
soplanning soplanning SQL injection vulnerability in SOPlanning <1.45, through /soplanning/www/groupe_list.php, in the by parameter, which could allow a remote user to send a specially crafted query and extract all the in… CWE-89
SQL Injection
CVE-2024-9573 2024-10-9 03:45 2024-10-8 Show GitHub Exploit DB Packet Storm
311528 5.4 MEDIUM
Network
soplanning soplanning Cross-Site Scripting (XSS) vulnerability in SOPlanning <1.45, due to lack of proper validation of user input via /soplanning/www/process/groupe_save.php, in the groupe_id parameter. This could allow … CWE-79
Cross-site Scripting
CVE-2024-9572 2024-10-9 03:45 2024-10-8 Show GitHub Exploit DB Packet Storm
311529 5.4 MEDIUM
Network
soplanning soplanning Cross-Site Scripting (XSS) vulnerability in SOPlanning <1.45, due to lack of proper validation of user input via /soplanning/www/process/xajax_server.php, affecting multiple parameters. This could al… CWE-79
Cross-site Scripting
CVE-2024-9571 2024-10-9 03:45 2024-10-8 Show GitHub Exploit DB Packet Storm
311530 5.9 MEDIUM
Network
cisco meraki_mx65_firmware
meraki_mx64_firmware
meraki_z4c_firmware
meraki_z4_firmware
meraki_z3c_firmware
meraki_z3_firmware
meraki_vmx_firmware
meraki_mx600_firmware
meraki_mx450_…
A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to hijack an AnyConnect VPN … CWE-362
Race Condition
CVE-2024-20509 2024-10-9 03:45 2024-10-3 Show GitHub Exploit DB Packet Storm