Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 19, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
232421 4.3 警告 ZoneO-soft - ZoneO-soft freeForum におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-3566 2012-12-20 18:52 2008-08-10 Show GitHub Exploit DB Packet Storm
232422 7.5 危険 Plogger Project - Plogger における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3563 2012-12-20 18:52 2008-07-29 Show GitHub Exploit DB Packet Storm
232423 6.8 警告 powergap - Powergap Shopsystem の s03.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3561 2012-12-20 18:52 2008-08-10 Show GitHub Exploit DB Packet Storm
232424 6.8 警告 wsnlinks - WSN Forum などの index.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-3555 2012-12-20 18:52 2008-08-8 Show GitHub Exploit DB Packet Storm
232425 10 危険 サン・マイクロシステムズ - Nokia Series 40 3rd エディションデバイスにおける任意のコードを実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-3553 2012-12-20 18:52 2008-08-8 Show GitHub Exploit DB Packet Storm
232426 10 危険 サン・マイクロシステムズ - Sun Wireless Toolkit で同梱されている Sun Java Platform Micro Edition における任意のコードを実行される脆弱性 CWE-noinfo
情報不足
CVE-2008-3551 2012-12-20 18:52 2008-08-8 Show GitHub Exploit DB Packet Storm
232427 4.9 警告 サン・マイクロシステムズ - Sun Netra T5220 Server におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2008-3548 2012-12-20 18:52 2008-08-4 Show GitHub Exploit DB Packet Storm
232428 4.7 警告 レッドハット - Fedora などの Linux 上で稼動している initscripts の rc.sysinit における任意のファイルを削除される脆弱性 CWE-59
リンク解釈の問題
CVE-2008-3524 2012-12-20 18:52 2008-09-25 Show GitHub Exploit DB Packet Storm
232429 4.3 警告 レッドハット - Red Hat JBoss Enterprise Application Platform の JBossAs コンポーネントにおける重要な情報を取得される脆弱性 CWE-16
環境設定
CVE-2008-3519 2012-12-20 18:52 2008-09-22 Show GitHub Exploit DB Packet Storm
232430 4.3 警告 softbiz - Softbiz Photo Gallery におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-3511 2012-12-20 18:52 2008-08-7 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 20, 2026, 4:01 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
313671 - - - A vulnerability in the Incoming Goods Suite allows a user with unprivileged access to the underlying system (e.g. local or via SSH) a privilege escalation to the administrative level due to the usage… - CVE-2024-11075 2024-11-19 23:15 2024-11-19 Show GitHub Exploit DB Packet Storm
313672 - - - Heap-based Buffer Overflow and Uninitialized Variable vulnerabilities exist in the X_B and SAT file reading procedure in eDrawings from Release SOLIDWORKS 2024 through Release SOLIDWORKS 2025. These … - CVE-2024-10204 2024-11-19 23:15 2024-11-19 Show GitHub Exploit DB Packet Storm
313673 - - - Versions of the package cross-spawn before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash th… - CVE-2024-21538 2024-11-19 23:15 2024-11-8 Show GitHub Exploit DB Packet Storm
313674 - - - The Bard theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.216. This … CWE-79
Cross-site Scripting
CVE-2024-9830 2024-11-19 22:15 2024-11-19 Show GitHub Exploit DB Packet Storm
313675 6.1 MEDIUM
Network
- - The Ashe theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.243. This … CWE-79
Cross-site Scripting
CVE-2024-9777 2024-11-19 22:15 2024-11-19 Show GitHub Exploit DB Packet Storm
313676 6.4 MEDIUM
Network
- - The Parallax Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘position’ parameter in all versions up to, and including, 1.9 due to insufficient input sanitization and … CWE-79
Cross-site Scripting
CVE-2024-11224 2024-11-19 22:15 2024-11-19 Show GitHub Exploit DB Packet Storm
313677 6.4 MEDIUM
Network
- - The GD Rating System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘extra_class’ parameter in all versions up to, and including, 3.6.1 due to insufficient input sanitizati… CWE-79
Cross-site Scripting
CVE-2024-11198 2024-11-19 22:15 2024-11-19 Show GitHub Exploit DB Packet Storm
313678 8.8 HIGH
Network
- - The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a misconfigure… - CVE-2024-11194 2024-11-19 21:15 2024-11-19 Show GitHub Exploit DB Packet Storm
313679 - - - The Email Subscription Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's print_email_subscribe_form shortcode in all versions up to, and including, 1.2.22 due t… CWE-79
Cross-site Scripting
CVE-2024-11195 2024-11-19 20:15 2024-11-19 Show GitHub Exploit DB Packet Storm
313680 7.3 HIGH
Network
- - The The WPB Popup for Contact Form 7 – Showing The Contact Form 7 Popup on Button Click – CF7 Popup plugin for WordPress is vulnerable to arbitrary shortcode execution via wpb_pcf_fire_contact_form A… CWE-94
Code Injection
CVE-2024-11038 2024-11-19 20:15 2024-11-19 Show GitHub Exploit DB Packet Storm