Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 8, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
229811 7.5 危険 TYPO3 Association - TYPO3 用の autobeuser エクステンションにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6459 2012-12-20 19:10 2009-03-13 Show GitHub Exploit DB Packet Storm
229812 7.5 危険 walnutstreet - TYPO3 用の cgswigmore エクステンションにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6457 2012-12-20 19:10 2009-03-13 Show GitHub Exploit DB Packet Storm
229813 9.3 危険 quiksoft - QuikSoft EasyMail MailStore ActiveX コントロールの emmailstore.dll におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-6447 2012-12-20 19:10 2009-03-9 Show GitHub Exploit DB Packet Storm
229814 7.5 危険 yourplace - YourPlace における脆弱性 CWE-287
不適切な認証
CVE-2008-6445 2012-12-20 19:10 2009-03-9 Show GitHub Exploit DB Packet Storm
229815 7.5 危険 phpkf - phpKF の forum_duzen.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6443 2012-12-20 19:10 2009-03-9 Show GitHub Exploit DB Packet Storm
229816 5.8 警告 sina - Sina Inc. DLoader Class ActiveX コントロールにおける任意のファイルを上書きされる脆弱性 CWE-Other
その他
CVE-2008-6442 2012-12-20 19:10 2009-03-9 Show GitHub Exploit DB Packet Storm
229817 4.3 警告 phpsqlitecms - phpSQLiteCMS におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-6435 2012-12-20 19:10 2009-03-6 Show GitHub Exploit DB Packet Storm
229818 7.5 危険 psychostats - PsychoStats における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6422 2012-12-20 19:10 2009-03-6 Show GitHub Exploit DB Packet Storm
229819 7.5 危険 socialsitegenerator - Social Site Generator の social_game_play.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2008-6421 2012-12-20 19:10 2009-03-6 Show GitHub Exploit DB Packet Storm
229820 5 警告 socialsitegenerator - Social Site Generator における任意のファイルを読まれる脆弱性 CWE-200
情報漏えい
CVE-2008-6420 2012-12-20 19:10 2009-03-6 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 8, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
195581 8.8 HIGH
Network
core_tweaks_wp_setup_project core_tweaks_wp_setup The Core Tweaks WP Setup WordPress plugin through 4.1 allows to bulk-set many settings in WordPress, including the admin email, as well as creating a new admin account. There is no CSRF protection in… - CVE-2021-24803 2024-11-21 14:53 2022-02-28 Show GitHub Exploit DB Packet Storm
195582 4.3 MEDIUM
Network
infornweb logo_showcase_with_slick_slider The Logo Showcase with Slick Slider WordPress plugin before 1.2.5 does not have CSRF and authorisation checks in the lswss_save_attachment_data AJAX action, allowing any authenticated users, such as … - CVE-2021-24730 2024-11-21 14:53 2022-02-28 Show GitHub Exploit DB Packet Storm
195583 8.8 HIGH
Network
orange-form_project orange-form In the Orange Form WordPress plugin through 1.0, the process_bulk_action() function in "admin/orange-form-email.php" performs an unprepared SQL query with an unsanitized parameter ($id). Only admin c… - CVE-2021-24704 2024-11-21 14:53 2022-02-28 Show GitHub Exploit DB Packet Storm
195584 4.9 MEDIUM
Network
wpeverest contact_form The Contact Forms - Drag & Drop Contact Form Builder WordPress plugin through 1.0.5 allows high privilege users to download arbitrary files from the web server via a path traversal attack CWE-22
Path Traversal
CVE-2021-24689 2024-11-21 14:53 2022-02-28 Show GitHub Exploit DB Packet Storm
195585 4.3 MEDIUM
Network
orange-form_project orange-form The Orange Form WordPress plugin through 1.0.1 does not have any authorisation and CSRF checks in all of its AJAX calls, for example the or_delete_filed one which is available to both unauthenticated… CWE-352
 Origin Validation Error
CVE-2021-24688 2024-11-21 14:53 2022-02-28 Show GitHub Exploit DB Packet Storm
195586 9.8 CRITICAL
Network
accesspressthemes accessbuddy
accesspress_basic
accesspress_lite
accesspress_mag
accesspress_parallax
accesspress_ray
accesspress_root
accesspress_staple
accesspress_store
agency_lite
apl…
Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are a… - CVE-2021-24867 2024-11-21 14:53 2022-02-21 Show GitHub Exploit DB Packet Storm
195587 4.8 MEDIUM
Network
lenderd mortgage_calculators_wp The Mortgage Calculators WP WordPress plugin before 1.56 does not implement any sanitisation on the color setting of the background of a calculator, which could allow high privilege users to perform … - CVE-2021-24904 2024-11-21 14:53 2022-02-14 Show GitHub Exploit DB Packet Storm
195588 6.1 MEDIUM
Network
brevo newsletter\
_smtp\
_email_marketing_and_subscribe
The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.31 does not escape the lang and pid parameter before outputting them back in attributes, leading to… - CVE-2021-24874 2024-11-21 14:53 2022-02-14 Show GitHub Exploit DB Packet Storm
195589 5.4 MEDIUM
Network
wpchill remove_footer_credit The Remove Footer Credit WordPress plugin before 1.0.6 does not have CSRF check in place when saving its settings, which could allow attacker to make logged in admins change them and lead to Stored X… - CVE-2021-24446 2024-11-21 14:53 2022-02-14 Show GitHub Exploit DB Packet Storm
195590 5.4 MEDIUM
Network
supportcandy supportcandy The SupportCandy WordPress plugin before 2.2.7 does not validate and escape the page attribute of its shortcode, which could allow users with a role as low as Contributor to perform Cross-Site Script… CWE-79
Cross-site Scripting
CVE-2021-24880 2024-11-21 14:53 2022-02-8 Show GitHub Exploit DB Packet Storm