Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 7, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
230641 7.5 危険 TYPO3 Association - TYPO3 用の Packman エクステンションにおける脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-3046 2012-12-20 18:52 2008-07-7 Show GitHub Exploit DB Packet Storm
230642 7.5 危険 TYPO3 Association - TYPO3 用の Industry Database エクステンションにおける脆弱性 CWE-noinfo
情報不足
CVE-2008-3045 2012-12-20 18:52 2008-07-7 Show GitHub Exploit DB Packet Storm
230643 7.5 危険 TYPO3 Association - TYPO3 用の News Calendar エクステンションにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3044 2012-12-20 18:52 2008-07-7 Show GitHub Exploit DB Packet Storm
230644 7.5 危険 Web-Empowered Church Team - TYPO3 用の WEC Discussion Forum エクステンションにおける任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2008-3043 2012-12-20 18:52 2008-07-7 Show GitHub Exploit DB Packet Storm
230645 10 危険 TYPO3 Association - TYPO3 用の DAM Frontend エクステンションにおける脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-3042 2012-12-20 18:52 2008-07-7 Show GitHub Exploit DB Packet Storm
230646 7.5 危険 TYPO3 Association - TYPO3 用の DAM Frontend エクステンションにおける脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-3041 2012-12-20 18:52 2008-07-7 Show GitHub Exploit DB Packet Storm
230647 5 警告 TYPO3 Association - TYPO3 用の DAM Frontend エクステンションにおける重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2008-3040 2012-12-20 18:52 2008-07-7 Show GitHub Exploit DB Packet Storm
230648 4.3 警告 Vtiger - vtiger CRM におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-3101 2012-12-20 18:52 2008-09-3 Show GitHub Exploit DB Packet Storm
230649 6.5 警告 phplizardo - ImperialBB における任意の PHP コードをアップロードされる脆弱性 CWE-94
コード・インジェクション
CVE-2008-3093 2012-12-20 18:52 2008-07-9 Show GitHub Exploit DB Packet Storm
230650 7.5 危険 xpoze - Xpoze Pro の user.html における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3089 2012-12-20 18:52 2008-07-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 7, 2026, 4:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
196371 7.2 HIGH
Network
connekthq ajax_load_more Unvalidated input in the Ajax Load More WordPress plugin, versions before 5.3.2, lead to SQL Injection in POST /wp-admin/admin-ajax.php with param repeater=' or sleep(5)#&type=test. CWE-89
SQL Injection
CVE-2021-24140 2024-11-21 14:52 2021-03-19 Show GitHub Exploit DB Packet Storm
196372 9.8 CRITICAL
Network
10web photo_gallery Unvalidated input in the Photo Gallery (10Web Photo Gallery) WordPress plugin, versions before 1.5.55, leads to SQL injection via the frontend/models/model.php bwg_search_x parameter. CWE-89
SQL Injection
CVE-2021-24139 2024-11-21 14:52 2021-03-19 Show GitHub Exploit DB Packet Storm
196373 5.5 MEDIUM
Network
ajdg adrotate Unvalidated input in the AdRotate WordPress plugin, versions before 5.8.4, leads to Authenticated SQL injection via param "id". This requires an admin privileged user. CWE-89
SQL Injection
CVE-2021-24138 2024-11-21 14:52 2021-03-19 Show GitHub Exploit DB Packet Storm
196374 8.8 HIGH
Network
adenion blog2social Unvalidated input in the Blog2Social WordPress plugin, versions before 6.3.1, lead to SQL Injection in the Re-Share Posts feature, allowing authenticated users to inject arbitrary SQL commands. CWE-89
SQL Injection
CVE-2021-24137 2024-11-21 14:52 2021-03-19 Show GitHub Exploit DB Packet Storm
196375 5.4 MEDIUM
Network
axelerant testimonials_widget Unvalidated input and lack of output encoding in the Testimonials Widget WordPress plugin, versions before 4.0.0, lead to multiple Cross-Site Scripting vulnerabilities, allowing remote attackers to i… CWE-79
Cross-site Scripting
CVE-2021-24136 2024-11-21 14:52 2021-03-19 Show GitHub Exploit DB Packet Storm
196376 6.1 MEDIUM
Network
gowebsolutions wp_customer_reviews Unvalidated input and lack of output encoding in the WP Customer Reviews WordPress plugin, versions before 3.4.3, lead to multiple Stored Cross-Site Scripting vulnerabilities allowing remote attacker… CWE-79
Cross-site Scripting
CVE-2021-24135 2024-11-21 14:52 2021-03-19 Show GitHub Exploit DB Packet Storm
196377 4.8 MEDIUM
Network
constantcontact constant_contact_forms Unvalidated input and lack of output encoding in the Constant Contact Forms WordPress plugin, versions before 1.8.8, lead to multiple Stored Cross-Site Scripting vulnerabilities, which allowed high-p… CWE-79
Cross-site Scripting
CVE-2021-24134 2024-11-21 14:52 2021-03-19 Show GitHub Exploit DB Packet Storm
196378 4.3 MEDIUM
Network
activecampaign activecampaign Lack of CSRF checks in the ActiveCampaign WordPress plugin, versions before 8.0.2, on its Settings form, which could allow attacker to make a logged-in administrator change API Credentials to attacke… CWE-352
 Origin Validation Error
CVE-2021-24133 2024-11-21 14:52 2021-03-19 Show GitHub Exploit DB Packet Storm
196379 8.8 HIGH
Network
10web slider The Slider by 10Web WordPress plugin, versions before 1.2.36, in the bulk_action, export_full and save_slider_db functionalities of the plugin were vulnerable, allowing a high privileged user (Admin)… CWE-89
SQL Injection
CVE-2021-24132 2024-11-21 14:52 2021-03-19 Show GitHub Exploit DB Packet Storm
196380 7.2 HIGH
Network
cleantalk anti-spam Unvalidated input in the Anti-Spam by CleanTalk WordPress plugin, versions before 5.149, lead to multiple authenticated SQL injection vulnerabilities, however, it requires high privilege user (admin+… CWE-89
SQL Injection
CVE-2021-24131 2024-11-21 14:52 2021-03-19 Show GitHub Exploit DB Packet Storm