Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 5, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
190201 8.8 重要
Network
dasinfomedia - WordPress 用 Mojoomla WPAMS Apartment Management System における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2017-14847 2017-10-19 16:53 2017-09-26 Show GitHub Exploit DB Packet Storm
190202 8.8 重要
Network
dasinfomedia - WordPress 用 Mojoomla Hospital Management System における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2017-14846 2017-10-19 16:53 2017-09-26 Show GitHub Exploit DB Packet Storm
190203 8.8 重要
Network
dasinfomedia - WordPress 用 Mojoomla WPCHURCH Church Management System における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2017-14845 2017-10-19 16:53 2017-09-26 Show GitHub Exploit DB Packet Storm
190204 8.8 重要
Network
dasinfomedia - Mojoomla WPGYM WordPress Gym Management System における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2017-14844 2017-10-19 16:53 2017-09-26 Show GitHub Exploit DB Packet Storm
190205 8.8 重要
Network
dasinfomedia - WordPress 用 Mojoomla School Management System における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2017-14843 2017-10-19 16:53 2017-09-26 Show GitHub Exploit DB Packet Storm
190206 8.8 重要
Network
dasinfomedia - WordPress 用 Mojoomla SMSmaster Multipurpose SMS Gateway における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2017-14842 2017-10-19 16:53 2017-09-26 Show GitHub Exploit DB Packet Storm
190207 6.5 警告
Network
dasinfomedia - Mojoomla Annual Maintenance Contract Management System における危険なタイプのファイルの無制限アップロードに関する脆弱性 CWE-434
危険なタイプのファイルの無制限アップロード
CVE-2017-14841 2017-10-19 16:53 2017-09-26 Show GitHub Exploit DB Packet Storm
190208 6.1 警告
Network
Mahara - Mahara におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2017-9551 2017-10-19 16:38 2017-09-11 Show GitHub Exploit DB Packet Storm
190209 8.1 重要
Network
pulp project - pulp-consumer-client における証明書検証に関する脆弱性 CWE-295
不正な証明書検証
CVE-2015-5263 2017-10-19 16:28 2015-09-5 Show GitHub Exploit DB Packet Storm
190210 6.1 警告
Network
ヒューレット・パッカード・エンタープライズ - HP UCMDB Configuration Manager におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2017-14352 2017-10-19 16:17 2017-09-28 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 5, 2026, 4:11 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
341 6.4 MEDIUM
Network
- - GigToDo 1.3 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript and HTML code through the proposal description field. Attackers… New CWE-79
Cross-site Scripting
CVE-2019-25739 2026-06-5 00:00 2026-06-4 Show GitHub Exploit DB Packet Storm
342 6.5 MEDIUM
Network
- - Joomla com_jsjobs 1.2.6 contains an arbitrary file deletion vulnerability that allows authenticated attackers to delete files by manipulating custom userfield parameters. Attackers can send POST requ… New CWE-22
Path Traversal
CVE-2019-25740 2026-06-5 00:00 2026-06-4 Show GitHub Exploit DB Packet Storm
343 9.8 CRITICAL
Network
- - Mobatek MobaXterm 12.1 contains a structured exception handling (SEH) based buffer overflow vulnerability in the username field of session files that allows remote attackers to execute arbitrary code… New CWE-120
Classic Buffer Overflow
CVE-2019-25741 2026-06-5 00:00 2026-06-4 Show GitHub Exploit DB Packet Storm
344 6.4 MEDIUM
Network
- - WordPress Theme Zoner Real Estate 4.1.1 contains a persistent cross-site scripting vulnerability that allows authenticated agents to inject malicious scripts through the Address input field when crea… New CWE-79
Cross-site Scripting
CVE-2019-25742 2026-06-5 00:00 2026-06-4 Show GitHub Exploit DB Packet Storm
345 6.4 MEDIUM
Network
- - WordPress Soliloquy Lite 2.5.6 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by inserting script tags in the post title fiel… New CWE-79
Cross-site Scripting
CVE-2019-25743 2026-06-5 00:00 2026-06-4 Show GitHub Exploit DB Packet Storm
346 6.4 MEDIUM
Network
- - WordPress Popup Builder 3.49 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by breaking out of option tags in the post_title … New CWE-79
Cross-site Scripting
CVE-2019-25744 2026-06-5 00:00 2026-06-4 Show GitHub Exploit DB Packet Storm
347 8.2 HIGH
Network
- - WordPress Plugin Google Review Slider 6.1 contains a time-based blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through th… New CWE-89
SQL Injection
CVE-2019-25745 2026-06-5 00:00 2026-06-4 Show GitHub Exploit DB Packet Storm
348 7.3 HIGH
Network
- - A vulnerability was detected in SourceCodester Pizzafy E-Commerce System 1.0. Affected by this vulnerability is the function Login of the file /admin/admin_class_novo.php of the component Administrat… New CWE-74
CWE-89
Injection
SQL Injection
CVE-2026-10704 2026-06-4 23:58 2026-06-3 Show GitHub Exploit DB Packet Storm
349 7.3 HIGH
Network
- - A vulnerability was identified in DedeCMS 5.7.88. The impacted element is the function dede_htmlspecialchars of the file /plus/flink.php. The manipulation of the argument msg leads to sql injection. … New CWE-74
CWE-89
Injection
SQL Injection
CVE-2026-10607 2026-06-4 23:56 2026-06-3 Show GitHub Exploit DB Packet Storm
350 7.3 HIGH
Network
- - A security flaw has been discovered in DedeCMS 5.7.88. This affects the function RemoveXSS of the file /plus/carbuyaction.php. The manipulation of the argument postname/des results in sql injection. … New CWE-74
CWE-89
Injection
SQL Injection
CVE-2026-10608 2026-06-4 23:56 2026-06-3 Show GitHub Exploit DB Packet Storm