Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 11, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
205161 7.8 重要
Local
Google - Android One デバイス上で稼動する Android の MediaTek ドライバにおける権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-3770 2016-07-19 13:54 2016-07-6 Show GitHub Exploit DB Packet Storm
205162 7.8 重要
Local
Google - Android の DexClassLoader の libdex/OptInvocation.cpp におけるバッファオーバーフローの脆弱性 CWE-119
CWE-264
CVE-2016-3758 2016-07-19 13:41 2016-07-6 Show GitHub Exploit DB Packet Storm
205163 7.8 重要
Local
Google - Android のメディアサーバの media/libmediaplayerservice/nuplayer/GenericSource.cpp における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2016-2508 2016-07-19 12:12 2016-07-6 Show GitHub Exploit DB Packet Storm
205164 7.8 重要
Local
Google - Android のメディアサーバの libstagefright における整数オーバーフローの脆弱性 CWE-119
CWE-189
CVE-2016-2507 2016-07-19 11:59 2016-07-6 Show GitHub Exploit DB Packet Storm
205165 7.8 重要
Local
Google - Android のメディアサーバの libstagefright の mpeg2ts/ATSParser.cpp における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2016-2505 2016-07-19 11:52 2016-07-6 Show GitHub Exploit DB Packet Storm
205166 7.8 重要
Local
Google - Nexus 5 および 7 (2013) デバイス上で稼動する Android の Qualcomm コンポーネントにおけるアクセス制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2015-8890 2016-07-19 11:52 2016-07-6 Show GitHub Exploit DB Packet Storm
205167 7.8 重要
Local
Google
Linux
- Nexus 5X および 6P デバイス上で稼動する Android で使用される Linux kernel の arch/arm64/include/asm/pgtable.h における権限を取得される脆弱性 CWE-Other
その他
CVE-2014-9803 2016-07-19 11:52 2016-07-6 Show GitHub Exploit DB Packet Storm
205168 7.8 重要
Local
Google - Nexus 5 および 7 (2013) デバイス上で稼動する Android の Qualcomm コンポーネントの lib/libfdt/fdt.c における整数オーバーフローの脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-9802 2016-07-19 11:52 2016-07-6 Show GitHub Exploit DB Packet Storm
205169 7.8 重要
Local
Google - Nexus 5 および 7 (2013) デバイス上で稼動する Android の Qualcomm コンポーネントの makefile における権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-9799 2016-07-19 11:52 2016-07-6 Show GitHub Exploit DB Packet Storm
205170 9.8 緊急
Network
マイクロソフト
アドビシステムズ
Google
- Adobe Flash Player におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2016-4249 2016-07-15 17:53 2016-07-12 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 11, 2026, 5:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
971 3.5 LOW
Network
- - The Custom Block Builder WordPress plugin before 4.3.0 does not consistently check the unfiltered_html capability across all paths that write to its block template code fields, allowing administrato… New CWE-79
Cross-site Scripting
CVE-2026-8981 2026-06-9 22:51 2026-06-9 Show GitHub Exploit DB Packet Storm
972 - - - SQL injection in the ‘two_steps_auth_code’ parameter processed by the ‘twoStepsAuthVerification’ function within the ‘/user-login’ endpoint. The two-factor authentication (2FA) functionality can be a… New CWE-89
SQL Injection
CVE-2026-10731 2026-06-9 22:51 2026-06-9 Show GitHub Exploit DB Packet Storm
973 8.2 HIGH
Network
- - Simply Poll 1.4.1 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through the 'pollid' POST pa… New CWE-89
SQL Injection
CVE-2016-20062 2026-06-9 22:51 2026-06-9 Show GitHub Exploit DB Packet Storm
974 7.1 HIGH
Network
- - Single Personal Message 1.0.3 contains an SQL injection vulnerability that allows authenticated users to execute arbitrary SQL queries by injecting malicious code through the message parameter. Attac… New CWE-89
SQL Injection
CVE-2016-20063 2026-06-9 22:51 2026-06-9 Show GitHub Exploit DB Packet Storm
975 6.2 MEDIUM
Local
- - WP Vault 0.8.6.6 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting an unescaped parameter in the include functionality. Attacke… New CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2016-20064 2026-06-9 22:51 2026-06-9 Show GitHub Exploit DB Packet Storm
976 8.2 HIGH
Network
- - Product Catalog 8 1.2 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the selec… New CWE-89
SQL Injection
CVE-2016-20065 2026-06-9 22:51 2026-06-9 Show GitHub Exploit DB Packet Storm
977 8.2 HIGH
Network
- - WordPress Car Park Booking Plugin version 13 October 17 contains a time-based SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code th… New CWE-89
SQL Injection
CVE-2017-20243 2026-06-9 22:51 2026-06-9 Show GitHub Exploit DB Packet Storm
978 8.2 HIGH
Network
- - Wow Forms WordPress Plugin version 2.1 contains an SQL injection vulnerability that allows unauthenticated attackers to read arbitrary database information by exploiting an unescaped POST parameter. … New CWE-89
SQL Injection
CVE-2017-20244 2026-06-9 22:51 2026-06-9 Show GitHub Exploit DB Packet Storm
979 8.2 HIGH
Network
- - Wow Viral Signups 2.1 WordPress plugin contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by exploiting the unescaped 'idsignup' POST parame… New CWE-89
SQL Injection
CVE-2017-20245 2026-06-9 22:51 2026-06-9 Show GitHub Exploit DB Packet Storm
980 8.2 HIGH
Network
- - KittyCatfish 2.2 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to read database contents by exploiting an unescaped GET parameter. Attackers can i… New CWE-89
SQL Injection
CVE-2017-20246 2026-06-9 22:51 2026-06-9 Show GitHub Exploit DB Packet Storm