Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 7, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
230421 7.5 危険 spice classifieds - Spice Classifieds の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-4039 2012-12-20 18:52 2008-09-11 Show GitHub Exploit DB Packet Storm
230422 4.3 警告 PunBB - PunBB の userlist.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-3968 2012-12-20 18:52 2008-08-20 Show GitHub Exploit DB Packet Storm
230423 2.6 注意 ssmtp - ssmtp の ssmtp.c における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2008-3962 2012-12-20 18:52 2008-08-10 Show GitHub Exploit DB Packet Storm
230424 7.5 危険 Vastal I-Tech & Co. - Vastal I-Tech Shaadi Zone の keyword_search_action.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3953 2012-12-20 18:52 2008-09-10 Show GitHub Exploit DB Packet Storm
230425 7.5 危険 Vastal I-Tech & Co. - Vastal I-Tech Agent Zone の view_ann.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3951 2012-12-20 18:52 2008-09-10 Show GitHub Exploit DB Packet Storm
230426 7.2 危険 SUSE - Emacs の emacs/lisp/progmodes/python.el における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2008-3949 2012-12-20 18:52 2008-09-19 Show GitHub Exploit DB Packet Storm
230427 7.5 危険 xrms - XRMS の admin/users/self-2.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3948 2012-12-20 18:52 2008-09-5 Show GitHub Exploit DB Packet Storm
230428 7.5 危険 source workshop - Words タグの index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3945 2012-12-20 18:52 2008-09-5 Show GitHub Exploit DB Packet Storm
230429 6.9 警告 r foundation - javareconf における任意のファイルを上書きされる脆弱性 CWE-59
リンク解釈の問題
CVE-2008-3931 2012-12-20 18:52 2008-09-4 Show GitHub Exploit DB Packet Storm
230430 7.2 危険 tiger - genmsgidx の Tiger における任意のファイルを上書きされる脆弱性 CWE-59
リンク解釈の問題
CVE-2008-3927 2012-12-20 18:52 2008-09-4 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 7, 2026, 4:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
195981 5.4 MEDIUM
Network
steam_group_viewer_project steam_group_viewer The Steam Group Viewer WordPress plugin through 2.1 does not sanitise or escape its "Steam Group Address" settings before outputting it in the page, leading to an authenticated Stored Cross-Site Scri… - CVE-2021-24476 2024-11-21 14:53 2021-08-2 Show GitHub Exploit DB Packet Storm
195982 6.1 MEDIUM
Network
awesome_weather_widget_project awesome_weather_widget The Awesome Weather Widget WordPress plugin through 3.0.2 does not sanitize the id parameter of its awesome_weather_refresh AJAX action, leading to an unauthenticated Reflected Cross-Site Scripting (… CWE-79
Cross-site Scripting
CVE-2021-24474 2024-11-21 14:53 2021-08-2 Show GitHub Exploit DB Packet Storm
195983 5.4 MEDIUM
Network
cozmoslabs user_profile_picture The User Profile Picture WordPress plugin before 2.6.0 was affected by an IDOR issue, allowing users with the upload_image capability (by default author and above) to change and delete the profile pi… CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2021-24473 2024-11-21 14:53 2021-08-2 Show GitHub Exploit DB Packet Storm
195984 9.8 CRITICAL
Network
qantumthemes kentharadio
onair2
The OnAir2 WordPress theme before 3.9.9.2 and QT KenthaRadio WordPress plugin before 2.0.2 have exposed proxy functionality to unauthenticated users, sending requests to this proxy functionality will… - CVE-2021-24472 2024-11-21 14:53 2021-08-2 Show GitHub Exploit DB Packet Storm
195985 5.4 MEDIUM
Network
yada_wiki_project yada_wiki The Yada Wiki WordPress plugin before 3.4.1 did not sanitise, validate or escape the anchor attribute of its shortcode, leading to a Stored Cross-Site Scripting issue CWE-79
Cross-site Scripting
CVE-2021-24470 2024-11-21 14:53 2021-08-2 Show GitHub Exploit DB Packet Storm
195986 5.4 MEDIUM
Network
bozdoz leaflet_map The Leaflet Map WordPress plugin before 3.0.0 does not escape some shortcode attributes before they are used in JavaScript code or HTML, which could allow users with a role as low as Contributors to … CWE-79
Cross-site Scripting
CVE-2021-24468 2024-11-21 14:53 2021-08-2 Show GitHub Exploit DB Packet Storm
195987 5.4 MEDIUM
Network
wpdevart youtube_embed\
_playlist_and_popup
The YouTube Embed, Playlist and Popup by WpDevArt WordPress plugin before 2.3.9 did not escape, validate or sanitise some of its shortcode options, available to users with a role as low as Contributo… - CVE-2021-24464 2024-11-21 14:53 2021-08-2 Show GitHub Exploit DB Packet Storm
195988 8.8 HIGH
Network
ays-pro image_slider The get_sliders() function in the Image Slider by Ays- Responsive Slider and Carousel WordPress plugin before 2.5.0 did not use whitelist or validate the orderby parameter before using it in SQL stat… - CVE-2021-24463 2024-11-21 14:53 2021-08-2 Show GitHub Exploit DB Packet Storm
195989 8.8 HIGH
Network
ays-pro photo_gallery The get_gallery_categories() and get_galleries() functions in the Photo Gallery by Ays – Responsive Image Gallery WordPress plugin before 4.4.4 did not use whitelist or validate the orderby parameter… - CVE-2021-24462 2024-11-21 14:53 2021-08-2 Show GitHub Exploit DB Packet Storm
195990 8.8 HIGH
Network
ays-pro faq_builder The get_faqs() function in the FAQ Builder AYS WordPress plugin before 1.3.6 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB c… - CVE-2021-24461 2024-11-21 14:53 2021-08-2 Show GitHub Exploit DB Packet Storm