Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 27, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
189101 4.8 警告
Network
Weblizar - WordPress 用 responsive-coming-soon-page プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2018-5662 2018-02-6 11:51 2018-01-17 Show GitHub Exploit DB Packet Storm
189102 4.8 警告
Network
Weblizar - WordPress 用 responsive-coming-soon-page プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2018-5661 2018-02-6 11:51 2018-01-17 Show GitHub Exploit DB Packet Storm
189103 4.8 警告
Network
Weblizar - WordPress 用 responsive-coming-soon-page プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2018-5660 2018-02-6 11:51 2018-01-17 Show GitHub Exploit DB Packet Storm
189104 4.8 警告
Network
Weblizar - WordPress 用 responsive-coming-soon-page プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2018-5659 2018-02-6 11:51 2018-01-17 Show GitHub Exploit DB Packet Storm
189105 4.8 警告
Network
Weblizar - WordPress 用 responsive-coming-soon-page プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2018-5657 2018-02-6 11:51 2018-01-17 Show GitHub Exploit DB Packet Storm
189106 8.8 重要
Network
wpdevelop - WordPress 用 booking-calendar プラグインにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2018-5673 2018-02-6 10:31 2018-01-14 Show GitHub Exploit DB Packet Storm
189107 4.8 警告
Network
wpdevelop - WordPress 用 booking-calendar プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2018-5672 2018-02-6 10:31 2018-01-14 Show GitHub Exploit DB Packet Storm
189108 4.8 警告
Network
wpdevelop - WordPress 用 booking-calendar プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2018-5671 2018-02-6 10:31 2018-01-14 Show GitHub Exploit DB Packet Storm
189109 4.8 警告
Network
wpdevelop - WordPress 用 booking-calendar プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2018-5670 2018-02-6 10:31 2018-01-14 Show GitHub Exploit DB Packet Storm
189110 8.8 重要
Network
OpenCV team - Opencv における整数オーバーフローの脆弱性 CWE-190
整数オーバーフローまたはラップアラウンド
CVE-2017-1000450 2018-02-5 19:26 2017-09-29 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 27, 2026, 4:35 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1961 9.1 CRITICAL
Network
- - Crypt::OpenSSL::PKCS12 versions before 1.96 for Perl permits a heap OOB read in print_attribute UTF8STRING path. print_attribute() copies a UTF8STRING ASN.1 attribute value into a heap buffer sized … CWE-125
Out-of-bounds Read
CVE-2026-9265 2026-06-23 03:45 2026-06-20 Show GitHub Exploit DB Packet Storm
1962 9.1 CRITICAL
Network
- - Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections. Net::Statsite::Client is a client for the statsite protocol, which is a variant of statsd. Newlines are not removed fr… CWE-93
CWE-150
CRLF Injection
 Improper Neutralization of Escape, Meta, or Control Sequences
CVE-2026-11373 2026-06-23 03:45 2026-06-22 Show GitHub Exploit DB Packet Storm
1963 7.8 HIGH
Local
- - Vembu StoreGrid 4.0 contains an unquoted service path vulnerability in the RemoteBackup and RemoteBackup_webServer services that allows local attackers to escalate privileges. Attackers can place a m… CWE-428
 Unquoted Search Path or Element
CVE-2016-20086 2026-06-23 03:40 2026-06-20 Show GitHub Exploit DB Packet Storm
1964 9.8 CRITICAL
Network
- - WooCommerce 7.1.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary PHP code by injecting shell commands through the product-type parameter. Attackers can send… CWE-94
Code Injection
CVE-2022-50972 2026-06-23 03:40 2026-06-20 Show GitHub Exploit DB Packet Storm
1965 6.5 MEDIUM
Network
- - Capgo before 12.128.2 contains an authorization bypass vulnerability in the /build/status and /build/logs endpoints that allows attackers to access build jobs belonging to different applications by s… CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-56229 2026-06-23 03:40 2026-06-21 Show GitHub Exploit DB Packet Storm
1966 7.2 HIGH
Network
- - Craft CMS (composer package craftcms/cms) versions >= 5.5.0 and <= 5.9.13 contain a remote code execution vulnerability in the FieldsController::actionRenderCardPreview() method, which passes the fie… CWE-94
Code Injection
CVE-2026-56382 2026-06-23 03:40 2026-06-21 Show GitHub Exploit DB Packet Storm
1967 9.6 CRITICAL
Network
- - SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject arbitrary HTML and JavaScript. Attackers can achieve… CWE-79
Cross-site Scripting
CVE-2026-56395 2026-06-23 03:40 2026-06-21 Show GitHub Exploit DB Packet Storm
1968 7.1 HIGH
Network
- - Joomla! Component vBizz 1.0.7 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the payid parameter. Att… CWE-89
SQL Injection
CVE-2019-25759 2026-06-23 03:39 2026-06-20 Show GitHub Exploit DB Packet Storm
1969 6.5 MEDIUM
Network
- - The WP Hotel Booking WordPress plugin before 2.3.1 does not enforce capability checks in several of its AJAX handlers, allowing authenticated users with Subscriber-level access to read other users' b… - CVE-2026-9822 2026-06-23 03:38 2026-06-19 Show GitHub Exploit DB Packet Storm
1970 9.8 CRITICAL
Network
- - WordPress Ultimate Addons for Beaver Builder 1.2.4.1 contains an authentication bypass vulnerability that allows attackers to gain unauthorized access by exploiting the social media login form functi… CWE-288
Authentication Bypass Using an Alternate Path or Channel
CVE-2019-25763 2026-06-23 03:38 2026-06-20 Show GitHub Exploit DB Packet Storm