Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 11, 2026, 12:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
249051 7.5 危険 carboncommunities - CarbonCommunities におけるパスワードを含むデータベースをダウンロードされる脆弱性 - CVE-2007-0096 2012-06-26 15:38 2007-01-5 Show GitHub Exploit DB Packet Storm
249052 7.5 危険 Simple Web Content Management System - Simple Web Content Management System の page.php における SQL インジェクションの脆弱性 - CVE-2007-0093 2012-06-26 15:38 2007-01-5 Show GitHub Exploit DB Packet Storm
249053 7.5 危険 e-smart cart - E-SMARTCART の productdetail.asp における SQL インジェクションの脆弱性 - CVE-2007-0092 2012-06-26 15:38 2007-01-5 Show GitHub Exploit DB Packet Storm
249054 7.5 危険 fermentigrafici - WineGlass におけるパスワードを含むデータベースをダウンロードされる脆弱性 - CVE-2007-0090 2012-06-26 15:38 2007-01-5 Show GitHub Exploit DB Packet Storm
249055 5 警告 battleblog - BattleBlog におけるデータベースをダウンロードされる脆弱性 - CVE-2007-0078 2012-06-26 15:38 2007-01-5 Show GitHub Exploit DB Packet Storm
249056 7.5 危険 2enetworx - Openforum におけるデータベースをダウンロードされる脆弱性 - CVE-2007-0076 2012-06-26 15:38 2007-01-5 Show GitHub Exploit DB Packet Storm
249057 7.5 危険 aspbb - AspBB におけるユーザパスワードを含むデータベースをダウンロードされる脆弱性 - CVE-2007-0075 2012-06-26 15:38 2007-01-5 Show GitHub Exploit DB Packet Storm
249058 9.3 危険 CA Technologies - 複数の CA 製品で使用される Message Queuing Server におけるスタックベースのバッファオーバーフローの脆弱性 - CVE-2007-0060 2012-06-26 15:38 2007-07-25 Show GitHub Exploit DB Packet Storm
249059 6.8 警告 アップル - Apple Quicktime におけるクロスゾーンスクリプティングの脆弱性 - CVE-2007-0059 2012-06-26 15:38 2007-01-4 Show GitHub Exploit DB Packet Storm
249060 5 警告 5e5 - Teamtek Universal FTP Server におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2006-7235 2012-06-26 15:38 2008-12-11 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 11, 2026, 5:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
196321 3.5 LOW
Network
vowelweb ibtana The Ibtana WordPress plugin before 1.1.4.9 does not have authorisation and CSRF checks in the ive_save_general_settings AJAX action, allowing any authenticated users, such as subscriber to call it an… - CVE-2021-25014 2024-11-21 14:54 2022-02-14 Show GitHub Exploit DB Packet Storm
196322 9.8 CRITICAL
Network
strangerstudios paid_memberships_pro The Paid Memberships Pro WordPress plugin before 2.6.7 does not escape the discount_code in one of its REST route (available to unauthenticated users) before using it in a SQL statement, leading to a… CWE-89
SQL Injection
CVE-2021-25114 2024-11-21 14:54 2022-02-8 Show GitHub Exploit DB Packet Storm
196323 7.1 HIGH
Network
ip2location country_blocker The IP2Location Country Blocker WordPress plugin before 2.26.6 does not have CSRF check in the ip2location_country_blocker_save_rules AJAX action, allowing attackers to make a logged in admin block a… CWE-352
 Origin Validation Error
CVE-2021-25108 2024-11-21 14:54 2022-02-8 Show GitHub Exploit DB Packet Storm
196324 5.4 MEDIUM
Network
wpeka wplegalpages The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WPLegalPages WordPress plugin before 2.7.1 does not check for authorisation and has a flawed CSRF logic when saving its s… CWE-79
Cross-site Scripting
CVE-2021-25106 2024-11-21 14:54 2022-02-8 Show GitHub Exploit DB Packet Storm
196325 4.8 MEDIUM
Network
ivorysearch ivory_search The Ivory Search WordPress plugin before 5.4.1 does not escape some of the Form settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html … CWE-79
Cross-site Scripting
CVE-2021-25105 2024-11-21 14:54 2022-02-8 Show GitHub Exploit DB Packet Storm
196326 4.7 MEDIUM
Network
gtranslate translate_wordpress_with_gtranslate The Translate WordPress with GTranslate WordPress plugin before 2.9.7 does not sanitise and escape the body parameter in the url_addon/gtranslate-email.php file before outputting it back in the page,… CWE-79
Cross-site Scripting
CVE-2021-25103 2024-11-21 14:54 2022-02-8 Show GitHub Exploit DB Packet Storm
196327 6.5 MEDIUM
Network
ip2location country_blocker The IP2Location Country Blocker WordPress plugin before 2.26.5 bans can be bypassed by using a specific parameter in the URL CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2021-25096 2024-11-21 14:54 2022-02-8 Show GitHub Exploit DB Packet Storm
196328 7.1 HIGH
Network
ip2location country_blocker The IP2Location Country Blocker WordPress plugin before 2.26.5 does not have authorisation and CSRF checks in the ip2location_country_blocker_save_rules AJAX action, allowing any authenticated users,… - CVE-2021-25095 2024-11-21 14:54 2022-02-8 Show GitHub Exploit DB Packet Storm
196329 4.3 MEDIUM
Network
bracketspace advanced_cron_manager The Advanced Cron Manager WordPress plugin before 2.4.2 and Advanced Cron Manager Pro WordPress plugin before 2.5.3 do not have authorisation checks in some of their AJAX actions, allowing any authen… - CVE-2021-25084 2024-11-21 14:54 2022-02-8 Show GitHub Exploit DB Packet Storm
196330 6.1 MEDIUM
Network
visser store_toolkit_for_woocommerce The Store Toolkit for WooCommerce WordPress plugin before 2.3.2 does not sanitise and escape the tab parameter before outputting it back in an admin page in an error message, leading to a Reflected C… CWE-79
Cross-site Scripting
CVE-2021-25077 2024-11-21 14:54 2022-02-8 Show GitHub Exploit DB Packet Storm