Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 30, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
216091 9.3 危険 マイクロソフト - 複数の Microsoft Windows 製品における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2015-1698 2015-05-14 10:24 2015-05-12 Show GitHub Exploit DB Packet Storm
216092 9.3 危険 マイクロソフト - 複数の Microsoft Windows 製品における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2015-1697 2015-05-14 10:24 2015-05-12 Show GitHub Exploit DB Packet Storm
216093 9.3 危険 マイクロソフト - 複数の Microsoft Windows 製品における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2015-1696 2015-05-14 10:24 2015-05-12 Show GitHub Exploit DB Packet Storm
216094 9.3 危険 マイクロソフト - 複数の Microsoft Windows 製品における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2015-1695 2015-05-14 10:24 2015-05-12 Show GitHub Exploit DB Packet Storm
216095 9.3 危険 マイクロソフト - 複数の Microsoft Windows 製品における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2015-1675 2015-05-14 10:24 2015-05-12 Show GitHub Exploit DB Packet Storm
216096 6.1 警告 Linux - Linux Kernel の drivers/media/usb/ttusb-dec/ttusbdecfe.c 内の ttusbdecfe_dvbs_diseqc_send_master_cmd 関数におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2014-8884 2015-05-13 18:00 2014-11-21 Show GitHub Exploit DB Packet Storm
216097 4.9 警告 Linux - Intel プロセッサ上で稼動する Linux Kernel の KVM サブシステムの arch/x86/kvm/vmx.c における任意のプロセスを強制終了される脆弱性 CWE-399
リソース管理の問題
CVE-2014-3690 2015-05-13 18:00 2014-10-24 Show GitHub Exploit DB Packet Storm
216098 5 警告 FreeType Project - FreeType の bdf/bdflib.c におけるヒープポインタ値を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-9675 2015-05-13 17:55 2014-11-7 Show GitHub Exploit DB Packet Storm
216099 4.9 警告 Xen プロジェクト - Xen の "REP MOVS" インストラクション用アクセラレーションサポートにおけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2014-8867 2015-05-13 17:55 2014-11-27 Show GitHub Exploit DB Packet Storm
216100 7.5 危険 FreeType Project - FreeType の base/ftobjs.c 内の Mac_Read_POST_Resource 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2014-9674 2015-05-13 17:54 2014-11-26 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 30, 2026, 4:22 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
2331 7.1 HIGH
Network
- - Joomla! Component vBizz 1.0.7 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the payid parameter. Att… CWE-89
SQL Injection
CVE-2019-25759 2026-06-23 03:39 2026-06-20 Show GitHub Exploit DB Packet Storm
2332 6.5 MEDIUM
Network
- - The WP Hotel Booking WordPress plugin before 2.3.1 does not enforce capability checks in several of its AJAX handlers, allowing authenticated users with Subscriber-level access to read other users' b… - CVE-2026-9822 2026-06-23 03:38 2026-06-19 Show GitHub Exploit DB Packet Storm
2333 9.8 CRITICAL
Network
- - WordPress Ultimate Addons for Beaver Builder 1.2.4.1 contains an authentication bypass vulnerability that allows attackers to gain unauthorized access by exploiting the social media login form functi… CWE-288
Authentication Bypass Using an Alternate Path or Channel
CVE-2019-25763 2026-06-23 03:38 2026-06-20 Show GitHub Exploit DB Packet Storm
2334 5.3 MEDIUM
Network
- - The Pie Register WordPress plugin before 3.8.4.10 does not use sufficiently random values when generating its account verification tokens, allowing unauthenticated attackers to predict a valid token… - CVE-2026-10530 2026-06-23 03:38 2026-06-22 Show GitHub Exploit DB Packet Storm
2335 6.1 MEDIUM
Network
- - The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which c… - CVE-2026-4110 2026-06-23 03:38 2026-06-22 Show GitHub Exploit DB Packet Storm
2336 7.1 HIGH
Network
- - The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which c… CWE-79
Cross-site Scripting
CVE-2026-4259 2026-06-23 03:38 2026-06-22 Show GitHub Exploit DB Packet Storm
2337 7.1 HIGH
Network
- - The Transbank Webpay WordPress plugin before 1.14.0 does not sanitize and escape logs to be displayed, allowing unauthenticated users to perform Stored XSS attacks against logged in administrator CWE-79
Cross-site Scripting
CVE-2026-6858 2026-06-23 03:38 2026-06-22 Show GitHub Exploit DB Packet Storm
2338 5.3 MEDIUM
Network
- - The Motors WordPress plugin before 1.4.110 does not have proper authorisation and CSRF checks on one of its AJAX actions, allowing unauthenticated attackers to modify arbitrary post metadata, such a… CWE-862
 Missing Authorization
CVE-2026-7859 2026-06-23 03:38 2026-06-22 Show GitHub Exploit DB Packet Storm
2339 8.8 HIGH
Network
- - The Vitepos WordPress plugin before 3.4.2 does not properly restrict the roles that can be assigned when creating new users via one of its REST API endpoints, allowing authenticated users with a cus… CWE-269
 Improper Privilege Management
CVE-2026-8157 2026-06-23 03:38 2026-06-22 Show GitHub Exploit DB Packet Storm
2340 8.2 HIGH
Network
- - Joomla! Component JB Visa 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the visatype parameter… CWE-89
SQL Injection
CVE-2017-20255 2026-06-23 03:37 2026-06-20 Show GitHub Exploit DB Packet Storm