Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 9, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
230751 9.3 危険 シマンテック - SAV における HTML ドキュメント内のマルウェアの検出を回避される脆弱性 CWE-20
不適切な入力確認
CVE-2008-5543 2012-12-20 18:52 2008-12-12 Show GitHub Exploit DB Packet Storm
230752 9.3 危険 ThreatTrack Security, Inc. - Subbelt VIPRE における HTML 文書内のマルウエアの検出を回避される脆弱性 CWE-20
不適切な入力確認
CVE-2008-5542 2012-12-20 18:52 2008-12-12 Show GitHub Exploit DB Packet Storm
230753 9.3 危険 ソフォス - Sophos Anti-Virus における HTML 文書内のマルウェアの検出を回避される脆弱性 CWE-20
不適切な入力確認
CVE-2008-5541 2012-12-20 18:52 2008-12-12 Show GitHub Exploit DB Packet Storm
230754 9.3 危険 securecomputing - Secure Computing Secure Web Gateway における HTML ドキュメント内のマルウェアの検出を回避される脆弱性 CWE-20
不適切な入力確認
CVE-2008-5540 2012-12-20 18:52 2008-12-12 Show GitHub Exploit DB Packet Storm
230755 9.3 危険 Beijing Rising International Software - RISING Antivirus における HTML 文書内のマルウェアの検出を回避される脆弱性 CWE-20
不適切な入力確認
CVE-2008-5539 2012-12-20 18:52 2008-12-12 Show GitHub Exploit DB Packet Storm
230756 9.3 危険 ウェブルート株式会社 - Prevx Prevx における HTML 文書内のマルウェアの検知を回避される脆弱性 CWE-20
不適切な入力確認
CVE-2008-5538 2012-12-20 18:52 2008-12-12 Show GitHub Exploit DB Packet Storm
230757 9.3 危険 クイックヒール・テクノロジーズ・ジャパン株式会社 - CAT-QuickHeal におけるマルウェアの検知を回避される脆弱性 CWE-20
不適切な入力確認
CVE-2008-5524 2012-12-20 18:52 2008-12-12 Show GitHub Exploit DB Packet Storm
230758 7.5 危険 pozscripts - PozScripts Business Directory Script の showcategory.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-5496 2012-12-20 18:52 2008-12-12 Show GitHub Exploit DB Packet Storm
230759 7.5 危険 phpstore - PHPStore Wholesales の track.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-5493 2012-12-20 18:52 2008-12-12 Show GitHub Exploit DB Packet Storm
230760 9.3 危険 verypdf - VeryDOC PDF Viewer OCX Control の pdfview.ocx におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-5492 2012-12-20 18:52 2008-12-12 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 9, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
196261 9.8 CRITICAL
Network
fortinet forticlient_endpoint_management_server An insufficient session expiration vulnerability [CWE- 613] in FortiClientEMS versions 6.4.2 and below, 6.2.8 and below may allow an attacker to reuse the unexpired admin user session IDs to gain adm… CWE-613
 Insufficient Session Expiration
CVE-2021-24019 2024-11-21 14:52 2021-10-6 Show GitHub Exploit DB Packet Storm
196262 7.8 HIGH
Local
mcafee drive_encryption Privilege Escalation vulnerability in a Windows system driver of McAfee Drive Encryption (DE) prior to 7.3.0 could allow a local non-admin user to gain elevated system privileges via exploiting an un… CWE-269
 Improper Privilege Management
CVE-2021-23893 2024-11-21 14:52 2021-10-1 Show GitHub Exploit DB Packet Storm
196263 4.3 MEDIUM
Network
fortinet fortimanager An improper authentication in Fortinet FortiManager version 6.4.3 and below, 6.2.6 and below allows attacker to assign arbitrary Policy and Object modules via crafted requests to the request handler. CWE-287
Improper Authentication
CVE-2021-24017 2024-11-21 14:52 2021-10-1 Show GitHub Exploit DB Packet Storm
196264 6.3 MEDIUM
Local
fortinet fortimanager An improper neutralization of formula elements in a csv file in Fortinet FortiManager version 6.4.3 and below, 6.2.7 and below allows attacker to execute arbitrary commands via crafted IPv4 field in … CWE-1236
 Improper Neutralization of Formula Elements in a CSV File
CVE-2021-24016 2024-11-21 14:52 2021-10-1 Show GitHub Exploit DB Packet Storm
196265 7.2 HIGH
Network
wp-domain-redirect_project wp-domain-redirect The Edit domain functionality in the WP Domain Redirect WordPress plugin through 1.0 has an `editid` parameter which is not sanitised, escaped or validated before inserting to a SQL statement, leadin… - CVE-2021-24401 2024-11-21 14:52 2021-09-20 Show GitHub Exploit DB Packet Storm
196266 7.2 HIGH
Network
wp-display-users_project wp-display-users The Edit Role functionality in the Display Users WordPress plugin through 2.0.0 had an `id` parameter which is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL … - CVE-2021-24400 2024-11-21 14:52 2021-09-20 Show GitHub Exploit DB Packet Storm
196267 7.2 HIGH
Network
ombu the_sorter The check_order function of The Sorter WordPress plugin through 1.0 uses an `area_id` parameter which is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL inject… - CVE-2021-24399 2024-11-21 14:52 2021-09-20 Show GitHub Exploit DB Packet Storm
196268 7.2 HIGH
Network
webpsilon responsive_3d_slider The Add new scene functionality in the Responsive 3D Slider WordPress plugin through 1.2 uses an id parameter which is not sanitised, escaped or validated before being inserted to a SQL statement, le… - CVE-2021-24398 2024-11-21 14:52 2021-09-20 Show GitHub Exploit DB Packet Storm
196269 7.2 HIGH
Network
activemedia microcopy The edit functionality in the MicroCopy WordPress plugin through 1.1.0 makes a get request to fetch the related option. The id parameter used is not sanitised, escaped or validated before inserting t… - CVE-2021-24397 2024-11-21 14:52 2021-09-20 Show GitHub Exploit DB Packet Storm
196270 7.2 HIGH
Network
bestiaweb gseor A pageid GET parameter of the GSEOR – WordPress SEO Plugin WordPress plugin through 1.3 is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection. - CVE-2021-24396 2024-11-21 14:52 2021-09-20 Show GitHub Exploit DB Packet Storm