Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 8, 2026, 2:12 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
249601 6.9 警告 シマンテック - Symantec LiveUpdate Administrator における権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-0304 2012-06-26 13:49 2012-06-15 Show GitHub Exploit DB Packet Storm
249602 7.5 危険 Simple Web Content Management System - Simple Web Content Management System における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2012-3791 2012-06-26 13:46 2012-06-21 Show GitHub Exploit DB Packet Storm
249603 7.5 危険 Wendy - Drupal 用 Counter モジュールにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2012-2718 2012-06-26 13:44 2012-05-30 Show GitHub Exploit DB Packet Storm
249604 6.8 警告 David Stosik - Drupal 用 Comment Moderation モジュールにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2012-2716 2012-06-26 13:43 2012-05-30 Show GitHub Exploit DB Packet Storm
249605 4.3 警告 OpenStack - OpenStack の EC2 および OS API におけるアクセス制限を回避される脆弱性 CWE-20
不適切な入力確認
CVE-2012-2654 2012-06-26 13:42 2012-06-21 Show GitHub Exploit DB Packet Storm
249606 5 警告 ターボリナックス
レッドハット
- ImageMagick の TIFF タグの取り扱いにおけるサービス運用妨害 (DoS) の脆弱性 - CVE-2005-0759 2012-06-26 12:28 2005-03-23 Show GitHub Exploit DB Packet Storm
249607 7.5 危険 サイバートラスト株式会社
ターボリナックス
レッドハット
- ImageMagick の不正なファイル名の処理によるフォーマットストリングの脆弱性 - CVE-2005-0397 2012-06-26 12:26 2005-03-3 Show GitHub Exploit DB Packet Storm
249608 10 危険 サイバートラスト株式会社
ターボリナックス
レッドハット
- ImageMagick の不正な EXIF ファイルの処理によるバッファオーバーフローの脆弱性 - CVE-2004-0981 2012-06-26 12:23 2004-10-27 Show GitHub Exploit DB Packet Storm
249609 10 危険 xmlsoft.org
アップル
サイバートラスト株式会社
サン・マイクロシステムズ
オラクル
レッドハット
- libxml2 の xmlParseAttValueComplex 関数におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-3529 2012-06-26 11:05 2008-09-1 Show GitHub Exploit DB Packet Storm
249610 2.1 注意 w1.fi - hostapd における重要な情報を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-2389 2012-06-25 16:49 2012-06-21 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 8, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
196181 5.4 MEDIUM
Network
weekly_schedule_project weekly_schedule The "Schedule Name" input in the Weekly Schedule WordPress plugin before 3.4.3 general options did not properly sanitize input, allowing a user to inject javascript code using the <script> HTML tags … - CVE-2021-24309 2024-11-21 14:52 2021-06-1 Show GitHub Exploit DB Packet Storm
196182 7.5 HIGH
Network
apache wicket A DNS proxy and possible amplification attack vulnerability in WebClientInfo of Apache Wicket allows an attacker to trigger arbitrary DNS lookups from the server when the X-Forwarded-For header is no… CWE-200
Information Exposure
CVE-2021-23937 2024-11-21 14:52 2021-05-26 Show GitHub Exploit DB Packet Storm
196183 4.8 MEDIUM
Network
autoptimize autoptimize The Autoptimize WordPress plugin before 2.8.4 was missing proper escaping and sanitisation in some of its settings, allowing high privilege users to set XSS payloads in them, leading to stored Cross-… - CVE-2021-24332 2024-11-21 14:52 2021-05-24 Show GitHub Exploit DB Packet Storm
196184 5.4 MEDIUM
Network
lifterlms lifterlms The 'State' field of the Edit profile page of the LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress plugin before 4.21.1 is not properly sanitised when ou… CWE-79
Cross-site Scripting
CVE-2021-24308 2024-11-21 14:52 2021-05-24 Show GitHub Exploit DB Packet Storm
196185 8.8 HIGH
Network
aioseo all_in_one_seo The All in One SEO – Best WordPress SEO Plugin – Easily Improve Your SEO Rankings before 4.1.0.2 enables authenticated users with "aioseo_tools_settings" privilege (most of the time admin) to execute… CWE-502
 Deserialization of Untrusted Data
CVE-2021-24307 2024-11-21 14:52 2021-05-24 Show GitHub Exploit DB Packet Storm
196186 5.4 MEDIUM
Network
ultimatemember ultimate_member The Ultimate Member – User Profile, User Registration, Login & Membership Plugin WordPress plugin before 2.1.20 did not properly sanitise, validate or encode the query string when generating a link t… CWE-79
Cross-site Scripting
CVE-2021-24306 2024-11-21 14:52 2021-05-24 Show GitHub Exploit DB Packet Storm
196187 6.1 MEDIUM
Network
targetfirst watcheezy The Target First WordPress Plugin v2.0, also previously known as Watcheezy, suffers from a critical unauthenticated stored XSS vulnerability. An attacker could change the licence key value through a … - CVE-2021-24305 2024-11-21 14:52 2021-05-24 Show GitHub Exploit DB Packet Storm
196188 5.4 MEDIUM
Network
neox hana_flv_player The Hana Flv Player WordPress plugin through 3.1.3 is vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) vulnerability within the 'Default Skin' field. - CVE-2021-24302 2024-11-21 14:52 2021-05-24 Show GitHub Exploit DB Packet Storm
196189 5.4 MEDIUM
Network
bluemedicinelabs hotjar_connecticator The Hotjar Connecticator WordPress plugin through 1.1.1 is vulnerable to Stored Cross-Site Scripting (XSS) in the 'hotjar script' textarea. The request did include a CSRF nonce that was properly veri… - CVE-2021-24301 2024-11-21 14:52 2021-05-24 Show GitHub Exploit DB Packet Storm
196190 6.1 MEDIUM
Network
pickplugins product_slider_for_woocommerce The slider import search feature of the PickPlugins Product Slider for WooCommerce WordPress plugin before 1.13.22 did not properly sanitised the keyword GET parameter, leading to reflected Cross-Sit… - CVE-2021-24300 2024-11-21 14:52 2021-05-24 Show GitHub Exploit DB Packet Storm