Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
209091 6.8 警告 Mikiurl Wordpress Eklentisi project - WordPress 用 Mikiurl Wordpress Eklentisi プラグインにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2014-9337 2014-12-24 14:34 2014-12-9 Show GitHub Exploit DB Packet Storm
209092 6.8 警告 iTwitter project - WordPress 用 iTwitter プラグインにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2014-9336 2014-12-24 14:34 2014-12-9 Show GitHub Exploit DB Packet Storm
209093 6.8 警告 DandyID Services project - WordPress 用 DandyID Services プラグインにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2014-9335 2014-12-24 14:34 2014-12-9 Show GitHub Exploit DB Packet Storm
209094 6.5 警告 Sergey Romanenko - Morfy CMS の install.php における config.php に任意の PHP コード を挿入される脆弱性 CWE-94
コード・インジェクション
CVE-2014-9185 2014-12-24 11:58 2014-12-3 Show GitHub Exploit DB Packet Storm
209095 4.3 警告 Huawei - Huawei P7-L10 スマートフォンの PackageInstaller モジュールにおける元のウェブサイトになりすまされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-9135 2014-12-24 11:49 2014-11-20 Show GitHub Exploit DB Packet Storm
209096 5.8 警告 株式会社 T-MEDIAホールディングス - Android 版 TSUTAYAアプリにおける任意の Java のメソッドが実行される脆弱性 CWE-DesignError
CVE-2014-7241 2014-12-22 17:51 2014-12-18 Show GitHub Exploit DB Packet Storm
209097 2.6 注意 リックソフト株式会社 - WBS ガントチャート for JIRA におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-7268 2014-12-22 17:50 2014-12-18 Show GitHub Exploit DB Packet Storm
209098 4 警告 リックソフト株式会社 - WBS ガントチャート for JIRA におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-7267 2014-12-22 17:49 2014-12-18 Show GitHub Exploit DB Packet Storm
209099 5 警告 Revive Adserver - Revive Adserver の lib/pear/XML/RPC.php の XML_RPC_cd 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2014-8875 2014-12-22 17:48 2014-08-8 Show GitHub Exploit DB Packet Storm
209100 4.3 警告 Revive Adserver - Revive Adserver の lib/max/Admin/UI/Field/PublisherIdField.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-8793 2014-12-22 17:44 2014-11-20 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 23, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
251771 - - - matrix-js-sdk is the Matrix Client-Server SDK for JavaScript and TypeScript. In matrix-js-sdk versions versions 9.11.0 through 34.7.0, the method `MatrixClient.sendSharedHistoryKeys` is vulnerable to… CWE-287
CWE-200
Improper Authentication
Information Exposure
CVE-2024-47080 2024-10-17 01:38 2024-10-16 Show GitHub Exploit DB Packet Storm
251772 - - - RCE (Remote Code Execution) exists in ZoneMinder through 1.36.33 as an attacker can create a new .php log file in language folder, while executing a crafted payload and escalate privileges allowing e… - CVE-2023-31493 2024-10-17 01:38 2024-10-16 Show GitHub Exploit DB Packet Storm
251773 5.3 MEDIUM
Local
- - A flaw was found in PyO3. This vulnerability causes a use-after-free issue, potentially leading to memory corruption or crashes via unsound borrowing from weak Python references. - CVE-2024-9979 2024-10-17 01:38 2024-10-15 Show GitHub Exploit DB Packet Storm
251774 - - - A vulnerability, which was classified as critical, was found in MitraStar GPT-2541GNAC BR_g5.6_1.11(WVK.0)b26. Affected is an unknown function of the file /cgi-bin/settings-firewall.cgi of the compon… CWE-78
OS Command 
CVE-2024-9977 2024-10-17 01:38 2024-10-15 Show GitHub Exploit DB Packet Storm
251775 - - - Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to SQL Injection in /admin//search-result.php via the searchkey parameter. - CVE-2024-48283 2024-10-17 01:38 2024-10-15 Show GitHub Exploit DB Packet Storm
251776 - - - A SQL Injection vulnerability was found in /password-recovery.php of PHPGurukul User Registration & Login and User Management System 3.2, which allows remote attackers to execute arbitrary SQL comman… - CVE-2024-48282 2024-10-17 01:38 2024-10-15 Show GitHub Exploit DB Packet Storm
251777 - - - A SQL Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Management System 3.2, which allows remote attackers to execute arbitrary SQL command vi… - CVE-2024-48280 2024-10-17 01:38 2024-10-15 Show GitHub Exploit DB Packet Storm
251778 - - - A HTML Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Management System 3.2. This vulnerability allows remote attackers to execute arbitrary … - CVE-2024-48279 2024-10-17 01:38 2024-10-15 Show GitHub Exploit DB Packet Storm
251779 - - - Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to Cross Site Request Forgery (CSRF) via /edit-profile.php. - CVE-2024-48278 2024-10-17 01:38 2024-10-15 Show GitHub Exploit DB Packet Storm
251780 - - - In multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio… - CVE-2024-40654 2024-10-17 01:35 2024-09-11 Show GitHub Exploit DB Packet Storm