Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 6, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
230541 7.5 危険 willo - Mobius for Mimsy XG における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3420 2012-12-20 18:52 2008-07-31 Show GitHub Exploit DB Packet Storm
230542 7.5 危険 willo - TriO の browse.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3418 2012-12-20 18:52 2008-07-31 Show GitHub Exploit DB Packet Storm
230543 7.5 危険 siteadmin - SiteAdmin の line2.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3414 2012-12-20 18:52 2008-07-31 Show GitHub Exploit DB Packet Storm
230544 5 警告 phplinkat - phpLinkat における認証を回避される脆弱性 CWE-287
不適切な認証
CVE-2008-3407 2012-12-20 18:52 2008-07-31 Show GitHub Exploit DB Packet Storm
230545 7.5 危険 phplinkat - TribunaLibre の ftag.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3406 2012-12-20 18:52 2008-07-31 Show GitHub Exploit DB Packet Storm
230546 4.3 警告 xrms - XRMS CRM における設定情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2008-3400 2012-12-20 18:52 2008-07-31 Show GitHub Exploit DB Packet Storm
230547 6.8 警告 xrms - XRMS CRM の activities/workflow-activities.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2008-3399 2012-12-20 18:52 2008-07-31 Show GitHub Exploit DB Packet Storm
230548 2.6 注意 xrms - XRMS CRM におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-3398 2012-12-20 18:52 2008-07-31 Show GitHub Exploit DB Packet Storm
230549 4.3 警告 runesoft - Runesoft Cerberus CMS におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-3397 2012-12-20 18:52 2008-07-31 Show GitHub Exploit DB Packet Storm
230550 5.8 警告 webwizguide - Web Wiz Forum におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2008-3392 2012-12-20 18:52 2008-07-31 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 7, 2026, 4:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
196121 5.4 MEDIUM
Network
fooplugins foogallery In the Best Image Gallery & Responsive Photo Gallery – FooGallery WordPress plugin before 2.0.35, the Custom CSS field of each gallery is not properly sanitised or validated before being being output… - CVE-2021-24357 2024-11-21 14:52 2021-06-14 Show GitHub Exploit DB Packet Storm
196122 8.8 HIGH
Network
wpdeveloper simple_301_redirects In the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, a lack of capability checks and insufficient nonce check on the AJAX action, simple301redirects/admin/activate_plugin, made i… - CVE-2021-24356 2024-11-21 14:52 2021-06-14 Show GitHub Exploit DB Packet Storm
196123 4.3 MEDIUM
Network
wpdeveloper simple_301_redirects In the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, the lack of capability checks and insufficient nonce check on the AJAX actions, simple301redirects/admin/get_wildcard and sim… - CVE-2021-24355 2024-11-21 14:52 2021-06-14 Show GitHub Exploit DB Packet Storm
196124 8.8 HIGH
Network
wpdeveloper simple_301_redirects A lack of capability checks and insufficient nonce check on the AJAX action in the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, made it possible for authenticated users to insta… - CVE-2021-24354 2024-11-21 14:52 2021-06-14 Show GitHub Exploit DB Packet Storm
196125 8.8 HIGH
Network
wpdeveloper simple_301_redirects The import_data function of the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4 had no capability or nonce checks making it possible for unauthenticated users to import a set of sit… - CVE-2021-24353 2024-11-21 14:52 2021-06-14 Show GitHub Exploit DB Packet Storm
196126 8.8 HIGH
Network
wpdeveloper simple_301_redirects The export_data function of the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4 had no capability or nonce checks making it possible for unauthenticated users to export a site's red… - CVE-2021-24352 2024-11-21 14:52 2021-06-14 Show GitHub Exploit DB Packet Storm
196127 6.1 MEDIUM
Network
posimyth the_plus_addons_for_elementor The theplus_more_post AJAX action of The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.12 did not properly sanitise some of its fields, leading to a reflected Cross-Site Scriptin… - CVE-2021-24351 2024-11-21 14:52 2021-06-14 Show GitHub Exploit DB Packet Storm
196128 6.1 MEDIUM
Network
bestwebsoft visitors_online The Visitors WordPress plugin through 0.3 is affected by an Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability. The plugin would display the user's user agent string without validation o… - CVE-2021-24350 2024-11-21 14:52 2021-06-14 Show GitHub Exploit DB Packet Storm
196129 6.1 MEDIUM
Network
gallery_from_files_project gallery_from_files This Gallery from files WordPress plugin through 1.6.0 gives the functionality of uploading images to the server. But filenames are not properly sanitized before being output in an error message when… - CVE-2021-24349 2024-11-21 14:52 2021-06-14 Show GitHub Exploit DB Packet Storm
196130 5.3 MEDIUM
Network
posimyth the_plus_addons_for_elementor The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.11 did not properly check that a user requesting a password reset was the legitimate user, allowing an attacker to send an arbit… CWE-287
Improper Authentication
CVE-2021-24359 2024-11-21 14:52 2021-06-14 Show GitHub Exploit DB Packet Storm