Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 11, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
230741 7.5 危険 sadi samami - WEBBDOMAIN Multi Languages WebShop Online の detail.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6268 2012-12-20 19:10 2009-02-25 Show GitHub Exploit DB Packet Storm
230742 7.5 危険 ultrastats - Ultrastats の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6260 2012-12-20 19:10 2009-02-24 Show GitHub Exploit DB Packet Storm
230743 4.3 警告 quadcomm - QuadComm Q-Shop の search.asp におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-6259 2012-12-20 19:10 2009-02-24 Show GitHub Exploit DB Packet Storm
230744 7.5 危険 quadcomm - QuadComm Q-Shop の users.asp における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6258 2012-12-20 19:10 2009-02-24 Show GitHub Exploit DB Packet Storm
230745 6.5 警告 vBulletin Solutions, Inc. - vBulletin の admincp/admincalendar.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6256 2012-12-20 19:10 2009-02-24 Show GitHub Exploit DB Packet Storm
230746 6.5 警告 vBulletin Solutions, Inc. - vBulletin における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6255 2012-12-20 19:10 2009-02-24 Show GitHub Exploit DB Packet Storm
230747 6.8 警告 Pluck CMS - Pluck の data/inc/lib/pcltar.lib.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-6253 2012-12-20 19:10 2009-02-24 Show GitHub Exploit DB Packet Storm
230748 7.2 危険 smcfancontrol - smcFanControl の smc プログラムにおけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-6252 2012-12-20 19:10 2009-02-24 Show GitHub Exploit DB Packet Storm
230749 6.8 警告 scripts - phpFan の includes/init.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2008-6251 2012-12-20 19:10 2009-02-24 Show GitHub Exploit DB Packet Storm
230750 7.5 危険 scripts-for-sites - SFS EZ Top Sites の topsite.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6247 2012-12-20 19:10 2009-02-23 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 11, 2026, 5:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
197021 5.4 MEDIUM
Network
status301 coolclock The CoolClock WordPress plugin before 4.3.5 does not escape some shortcode attributes, allowing users with a role as low as Contributor toperform Stored Cross-Site Scripting attacks - CVE-2021-24670 2024-11-21 14:53 2021-09-28 Show GitHub Exploit DB Packet Storm
197022 9.8 CRITICAL
Network
podlove podlove_podcast_publisher The Podlove Podcast Publisher WordPress plugin before 3.5.6 contains a 'Social & Donations' module (not activated by default), which adds the rest route '/services/contributor/(?P<id>[\d]+), takes an… - CVE-2021-24666 2024-11-21 14:53 2021-09-28 Show GitHub Exploit DB Packet Storm
197023 4.3 MEDIUM
Network
wpxpo postx_-_gutenberg_blocks_for_post_grid The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10, with Saved Templates Addon enabled, allows users with Contributor roles or higher to read password-protected or private post… NVD-CWE-Other
CVE-2021-24661 2024-11-21 14:53 2021-09-28 Show GitHub Exploit DB Packet Storm
197024 5.4 MEDIUM
Network
wpxpo postx_-_gutenberg_blocks_for_post_grid The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10, with Saved Templates Addon enabled, allows users with a role as low as Contributor to perform Stored Cross-Site Scripting at… - CVE-2021-24660 2024-11-21 14:53 2021-09-28 Show GitHub Exploit DB Packet Storm
197025 5.4 MEDIUM
Network
wpxpo postx_-_gutenberg_blocks_for_post_grid The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10 allows users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks via the plugin's block. - CVE-2021-24659 2024-11-21 14:53 2021-09-28 Show GitHub Exploit DB Packet Storm
197026 6.5 MEDIUM
Network
wpxpo postx_-_gutenberg_blocks_for_post_grid The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10 performs incorrect checks before allowing any logged in user to perform some ajax based requests, allowing any user to modify… - CVE-2021-24652 2024-11-21 14:53 2021-09-28 Show GitHub Exploit DB Packet Storm
197027 5.4 MEDIUM
Network
wp_map_block_project wp_map_block The WP Map Block WordPress plugin before 1.2.3 does not escape some attributes of the WP Map Block, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting at… - CVE-2021-24643 2024-11-21 14:53 2021-09-28 Show GitHub Exploit DB Packet Storm
197028 5.4 MEDIUM
Network
wpzoom recipe_card_blocks_for_gutenberg_\&_elementor The Recipe Card Blocks by WPZOOM WordPress plugin before 2.8.3 does not properly sanitise or escape some of the properties of the Recipe Card Block (such as ingredientsLayout, iconSet, steps, ingredi… - CVE-2021-24634 2024-11-21 14:53 2021-09-28 Show GitHub Exploit DB Packet Storm
197029 4.3 MEDIUM
Network
wpdeveloper countdown_block The Countdown Block WordPress plugin before 1.1.2 does not have authorisation in the eb_write_block_css AJAX action, which allows any authenticated user, such as Subscriber, to modify post contents d… - CVE-2021-24633 2024-11-21 14:53 2021-09-28 Show GitHub Exploit DB Packet Storm
197030 6.1 MEDIUM
Network
wpzoom recipe_card_blocks_for_gutenberg_\&_elementor The Recipe Card Blocks by WPZOOM WordPress plugin before 2.8.1 does not escape the message parameter before outputting it back in the admin dashboard, leading to a Reflected Cross-Site Scripting issue - CVE-2021-24632 2024-11-21 14:53 2021-09-28 Show GitHub Exploit DB Packet Storm