Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 29, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
247351 4.3 警告 fr.simon rundell
TYPO3 Association
- TYPO3 の ste_parish_admin 拡張におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4400 2012-06-26 16:18 2008-07-9 Show GitHub Exploit DB Packet Storm
247352 7.5 危険 fr.simon rundell
TYPO3 Association
- TYPO3 の hs_religiousartgallery 拡張における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-4399 2012-06-26 16:18 2008-07-9 Show GitHub Exploit DB Packet Storm
247353 4.3 警告 fr.simon rundell
TYPO3 Association
- TYPO3 の hs_religiousartgallery 拡張におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4398 2012-06-26 16:18 2008-07-9 Show GitHub Exploit DB Packet Storm
247354 4.3 警告 fr.simon rundell
TYPO3 Association
- TYPO3 の pd_resources 拡張におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4397 2012-06-26 16:18 2008-07-9 Show GitHub Exploit DB Packet Storm
247355 4.3 警告 fr.simon rundell
TYPO3 Association
- TYPO3 の ste_prayer2 拡張におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4395 2012-06-26 16:18 2008-07-9 Show GitHub Exploit DB Packet Storm
247356 7.5 危険 fr.simon rundell
TYPO3 Association
- TYPO3 の ste_prayer2 における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-4394 2012-06-26 16:18 2008-07-9 Show GitHub Exploit DB Packet Storm
247357 4.7 警告 FreeBSD - FreeBSD の freebsd-update における重要なファイルのコピーを読まれる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2009-4358 2012-06-26 16:18 2009-12-3 Show GitHub Exploit DB Packet Storm
247358 7.5 危険 boldfx - Arctic Issue Tracker の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-4350 2012-06-26 16:18 2009-12-17 Show GitHub Exploit DB Packet Storm
247359 4.3 警告 TYPO3 Association
dominic eckart
- TYPO3 の trainincdb 拡張におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4343 2012-06-26 16:18 2009-12-17 Show GitHub Exploit DB Packet Storm
247360 6.8 警告 eocms - eoCMS の js/bbcodepress/bbcode-form.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2009-4319 2012-06-26 16:18 2009-12-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 30, 2026, 4:22 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
200001 9.8 CRITICAL
Network
thimpress learnpress The LearnPress WordPress plugin before 4.1.4 does not sanitise, validate and escape the id parameter before using it in SQL statements when duplicating course/lesson/quiz/question, leading to SQL Inj… - CVE-2021-24951 2024-11-21 14:54 2021-12-13 Show GitHub Exploit DB Packet Storm
200002 9.8 CRITICAL
Network
webnus modern_events_calendar_lite The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the time parameter before using it in a SQL statement in the mec_load_single_page AJAX action, available to … - CVE-2021-24946 2024-11-21 14:54 2021-12-13 Show GitHub Exploit DB Packet Storm
200003 8.0 HIGH
Network
likebtn like_button_rating The Like Button Rating ? LikeBtn WordPress plugin before 2.6.38 does not have any authorisation and CSRF checks in the likebtn_export_votes AJAX action, which could allow any authenticated user, such… CWE-352
 Origin Validation Error
CVE-2021-24945 2024-11-21 14:54 2021-12-13 Show GitHub Exploit DB Packet Storm
200004 6.1 MEDIUM
Network
cm-wp auto_featured_image The Auto Featured Image (Auto Post Thumbnail) WordPress plugin before 3.9.3 does not sanitise and escape the post_id parameter before outputting back in an admin page within a JS block, leading to a … - CVE-2021-24932 2024-11-21 14:54 2021-12-13 Show GitHub Exploit DB Packet Storm
200005 6.1 MEDIUM
Network
webnus modern_events_calendar_lite The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the current_month_divider parameter of its mec_list_load_more AJAX call (available to both unauthenticated a… - CVE-2021-24925 2024-11-21 14:54 2021-12-13 Show GitHub Exploit DB Packet Storm
200006 9.0 CRITICAL
Network
fatcatapps pixel_cat The Pixel Cat WordPress plugin before 2.6.2 does not have CSRF check when saving its settings, and did not sanitise as well as escape some of them, which could allow attacker to make a logged in admi… - CVE-2021-24922 2024-11-21 14:54 2021-12-13 Show GitHub Exploit DB Packet Storm
200007 6.1 MEDIUM
Network
10web photo_gallery The Photo Gallery by 10Web WordPress plugin before 1.5.68 is vulnerable to Reflected Cross-Site Scripting (XSS) issues via the bwg_album_breadcrumb_0 and shortcode_id GET parameters passed to the bwg… - CVE-2021-25041 2024-11-21 14:54 2021-12-7 Show GitHub Exploit DB Packet Storm
200008 9.8 CRITICAL
Network
roundupwp registrations_for_the_events_calendar The Registrations for the Events Calendar WordPress plugin before 2.7.6 does not sanitise and escape the event_id in the rtec_send_unregister_link AJAX action (available to both unauthenticated and a… - CVE-2021-24943 2024-11-21 14:54 2021-12-7 Show GitHub Exploit DB Packet Storm
200009 6.1 MEDIUM
Network
profilepress loginwp The LoginWP (Formerly Peter's Login Redirect) WordPress plugin before 3.0.0.5 does not sanitise and escape the rul_login_url and rul_logout_url parameter before outputting them back in attributes in … - CVE-2021-24939 2024-11-21 14:54 2021-12-7 Show GitHub Exploit DB Packet Storm
200010 6.1 MEDIUM
Network
woocommerce woocommerce_currency_switcher The WOOCS WordPress plugin before 1.3.7.1 does not sanitise and escape the key parameter of the woocs_update_profiles_data AJAX action (available to any authenticated user) before outputting it back … - CVE-2021-24938 2024-11-21 14:54 2021-12-7 Show GitHub Exploit DB Packet Storm