Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 30, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
217251 4.3 警告 WP Ninjas, LLC. - WordPress 用 Ninja Forms プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2015-2220 2015-03-6 14:16 2015-02-12 Show GitHub Exploit DB Packet Storm
217252 7.5 危険 WP Ninjas, LLC. - WordPress 用 Ninja Forms プラグインにおける脆弱性 CWE-noinfo
情報不足
CVE-2014-9688 2015-03-6 14:16 2014-12-2 Show GitHub Exploit DB Packet Storm
217253 6.4 警告 Apache Software Foundation
アップル
サイバートラスト株式会社
ヒューレット・パッカード
VMware
レッドハット
- Apache Tomcat の JULI ロギングコンポーネントにおけるウェブアプリケーションのパーミッションに関する脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2007-5342 2015-03-5 18:27 2007-12-27 Show GitHub Exploit DB Packet Storm
217254 3.5 注意 Apache Software Foundation
アップル
サイバートラスト株式会社
ヒューレット・パッカード
サン・マイクロシステムズ
VMware
レッドハット
- Apache Tomcat の WebDAV servlet における情報漏えいの脆弱性 CWE-22
パス・トラバーサル
CVE-2007-5461 2015-03-5 18:27 2007-10-15 Show GitHub Exploit DB Packet Storm
217255 4.3 警告 トレンドマイクロ
Apache Software Foundation
アップル
サイバートラスト株式会社
VMware
レッドハット
- Apache Tomcat において不正な Cookie を送信される脆弱性 CWE-200
情報漏えい
CVE-2007-5333 2015-03-5 18:27 2008-02-12 Show GitHub Exploit DB Packet Storm
217256 4.3 警告 アップル
VMware
Apache Software Foundation
ヒューレット・パッカード
- Apache Tomcat における SSL リクエストに関する脆弱性 CWE-DesignError
CVE-2007-6286 2015-03-5 18:26 2008-02-11 Show GitHub Exploit DB Packet Storm
217257 5 警告 Apache Software Foundation - Apache ActiveMQ のデフォルト設定におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2012-6551 2015-03-5 18:26 2012-11-2 Show GitHub Exploit DB Packet Storm
217258 5 警告 PowerDNS - PowerDNS Recursor におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2014-3614 2015-03-5 18:26 2014-09-10 Show GitHub Exploit DB Packet Storm
217259 4.4 警告 ヒューレット・パッカード
Apache Software Foundation
- Apache Tomcat におけるアクセス制限を回避される脆弱性 CWE-20
不適切な入力確認
CVE-2011-2526 2015-03-5 18:18 2011-07-11 Show GitHub Exploit DB Packet Storm
217260 5 警告 ヒューレット・パッカード
Apache Software Foundation
- Apache Tomcat で使用される Apache Commons の jsvc における読み取り権限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2011-2729 2015-03-5 18:16 2011-08-3 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 30, 2026, 4:22 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
2261 6.2 MEDIUM
Local
- - Joomla! Component Easy Shop 1.2.3 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by supplying base64-encoded file paths. Attackers can sen… CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2019-25760 2026-06-23 05:16 2026-06-20 Show GitHub Exploit DB Packet Storm
2262 8.2 HIGH
Network
- - Joomla Component vRestaurant 1.9.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the keysearch par… CWE-89
SQL Injection
CVE-2019-25754 2026-06-23 05:16 2026-06-20 Show GitHub Exploit DB Packet Storm
2263 8.2 HIGH
Network
- - Joomla JHotelReservation 6.0.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the rooms parameter. … CWE-89
SQL Injection
CVE-2019-25748 2026-06-23 05:16 2026-06-20 Show GitHub Exploit DB Packet Storm
2264 8.2 HIGH
Network
- - Joomla Component JoomRecipe 1.0.3 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the category parameter. At… CWE-89
SQL Injection
CVE-2017-20278 2026-06-23 05:16 2026-06-20 Show GitHub Exploit DB Packet Storm
2265 8.2 HIGH
Network
- - Joomla Ultimate Property Listing 1.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the sf_select… CWE-89
SQL Injection
CVE-2017-20272 2026-06-23 05:16 2026-06-20 Show GitHub Exploit DB Packet Storm
2266 8.2 HIGH
Network
- - Joomla SP Movie Database 1.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the searchword paramete… CWE-89
SQL Injection
CVE-2017-20266 2026-06-23 05:16 2026-06-20 Show GitHub Exploit DB Packet Storm
2267 8.2 HIGH
Network
- - Joomla! Component Price Alert 3.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the product_id p… CWE-89
SQL Injection
CVE-2017-20260 2026-06-23 05:16 2026-06-20 Show GitHub Exploit DB Packet Storm
2268 8.2 HIGH
Network
- - Joomla! Component User Bench 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the userid paramete… CWE-89
SQL Injection
CVE-2017-20254 2026-06-23 05:16 2026-06-20 Show GitHub Exploit DB Packet Storm
2269 - - - Impact A security issue has been identified in Chef 360 that could allow unauthorized access to protected API endpoints under specific conditions. This issue is due to improper handling of URL-encod… CWE-23
 Relative Path Traversal
CVE-2026-8100 2026-06-23 04:49 2026-06-19 Show GitHub Exploit DB Packet Storm
2270 - - - A static credential embedded in Chef 360 prior to v1.7.0 permitted unauthenticated access to internal message queues.  Queue messages contained tenant-specific identifiers.  The credential has been r… CWE-523
 Unprotected Transport of Credentials
CVE-2026-8668 2026-06-23 04:49 2026-06-19 Show GitHub Exploit DB Packet Storm