Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 30, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
247361 7.5 危険 Drupal
brian miller
- Drupal の Taxonomy Timer モジュールにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-4296 2012-06-26 16:18 2009-12-11 Show GitHub Exploit DB Packet Storm
247362 6.8 警告 barnraiser - AROUNDMe の components/core/connect.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2009-4264 2012-06-26 16:18 2009-12-10 Show GitHub Exploit DB Packet Storm
247363 4.3 警告 Clixint Technologies - Image Hosting Script DPI の images.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4252 2012-06-26 16:18 2009-12-9 Show GitHub Exploit DB Packet Storm
247364 9.3 危険 コーレル株式会社 - Jasc Paint Shop Pro におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-4251 2012-06-26 16:18 2009-12-9 Show GitHub Exploit DB Packet Storm
247365 4.3 警告 korn19
CutePHP
- CutePHP CuteNews および UTF-8 CuteNews におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4250 2012-06-26 16:18 2009-12-9 Show GitHub Exploit DB Packet Storm
247366 2.6 注意 CutePHP - CutePHP CuteNews におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-4249 2012-06-26 16:18 2009-12-9 Show GitHub Exploit DB Packet Storm
247367 7.5 危険 Basic-CMS - SweetRice の as/lib/plugins.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2009-4231 2012-06-26 16:18 2009-12-8 Show GitHub Exploit DB Packet Storm
247368 7.5 危険 Activewebsoftwares - ActiveWebSoftwares Active Bids における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-4229 2012-06-26 16:18 2009-12-8 Show GitHub Exploit DB Packet Storm
247369 6.8 警告 Basic-CMS - SweetRice における PHP リモートファイルインクルージョンの脆弱性 CWE-20
不適切な入力確認
CVE-2009-4224 2012-06-26 16:18 2009-12-7 Show GitHub Exploit DB Packet Storm
247370 7.5 危険 gianni tommasi - KR-Web の adm/krgourl.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2009-4223 2012-06-26 16:18 2009-12-7 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 30, 2026, 4:22 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
199991 6.1 MEDIUM
Network
strangerstudios paid_memberships_pro The Paid Memberships Pro WordPress plugin before 2.6.6 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting - CVE-2021-24979 2024-11-21 14:54 2021-12-27 Show GitHub Exploit DB Packet Storm
199992 5.4 MEDIUM
Network
wpdownloadmanager wordpress_download_manager The WordPress Download Manager WordPress plugin before 3.2.22 does not sanitise and escape Template data before outputting it in various pages (such as admin dashboard and frontend). Due to the lack … - CVE-2021-24969 2024-11-21 14:54 2021-12-27 Show GitHub Exploit DB Packet Storm
199993 6.1 MEDIUM
Network
themehunk contact_form_\&_lead_form_elementor_builder The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.6.4 does not sanitise and escape some lead values, which could allow unauthenticated users to perform Cross-Site Scripting att… - CVE-2021-24967 2024-11-21 14:54 2021-12-27 Show GitHub Exploit DB Packet Storm
199994 7.5 HIGH
Network
wpwax directorist The Directorist WordPress plugin before 7.0.6.2 was vulnerable to Cross-Site Request Forgery to Remote File Upload leading to arbitrary PHP shell uploads in the wp-content/plugins directory. - CVE-2021-24981 2024-11-21 14:54 2021-12-21 Show GitHub Exploit DB Packet Storm
199995 6.1 MEDIUM
Network
adenion blog2social The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.8.7 does not sanitise and escape the b2sShowByDate parameter before outputting it back in an admin page, leading to a Ref… - CVE-2021-24956 2024-11-21 14:54 2021-12-21 Show GitHub Exploit DB Packet Storm
199996 6.1 MEDIUM
Network
icegram icegram The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.0.5 does not sanitise and escape the message_id parameter of the get_message_action_row AJAX action before outputt… - CVE-2021-24941 2024-11-21 14:54 2021-12-21 Show GitHub Exploit DB Packet Storm
199997 4.8 MEDIUM
Network
fatcatapps pixel_cat The Pixel Cat WordPress plugin before 2.6.3 does not escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disal… - CVE-2021-24972 2024-11-21 14:54 2021-12-13 Show GitHub Exploit DB Packet Storm
199998 7.2 HIGH
Network
plugins360 all-in-one_video_gallery The All-in-One Video Gallery WordPress plugin before 2.5.0 does not sanitise and validate the tab parameter before using it in a require statement in the admin dashboard, leading to a Local File Incl… - CVE-2021-24970 2024-11-21 14:54 2021-12-13 Show GitHub Exploit DB Packet Storm
199999 6.1 MEDIUM
Network
profilepress user_registration\
_login_form\
_user_profile_\&_membership
The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not escape the data parameter of the pp_get_forms_by_builder_type AJAX action before outputting it back… - CVE-2021-24955 2024-11-21 14:54 2021-12-13 Show GitHub Exploit DB Packet Storm
200000 6.1 MEDIUM
Network
profilepress user_registration\
_login_form\
_user_profile_\&_membership
The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not sanitise and escape the ppress_cc_data parameter before outputting it back in an attribute of an ad… - CVE-2021-24954 2024-11-21 14:54 2021-12-13 Show GitHub Exploit DB Packet Storm