Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 26, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
224861 6.8 警告 FFmpeg - FFmpeg の libavcodec/takdec.c の tak_decode_frame 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2014-2097 2014-03-4 15:54 2014-02-1 Show GitHub Exploit DB Packet Storm
224862 4.3 警告 MODX - MODX Revolution の manager/templates/default/header.tpl におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-2080 2014-03-4 15:45 2014-01-21 Show GitHub Exploit DB Packet Storm
224863 3.5 注意 CloudBees - CloudBees Jenkins の java/hudson/model/Cause.java におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-2067 2014-03-4 15:37 2014-02-14 Show GitHub Exploit DB Packet Storm
224864 4 警告 CloudBees - CloudBees Jenkins の CLI ジョブ作成におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2014-2059 2014-03-4 15:37 2014-02-14 Show GitHub Exploit DB Packet Storm
224865 4.3 警告 BuddyPress.org - WordPress 用 BuddyPress プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-1888 2014-03-4 15:13 2014-02-5 Show GitHub Exploit DB Packet Storm
224866 4.3 警告 OTRS プロジェクト - Open Ticket Request System におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-1695 2014-03-4 15:08 2014-02-25 Show GitHub Exploit DB Packet Storm
224867 4.3 警告 Open Web Analytics - Open Web Analytics のログインページにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-1456 2014-03-4 15:04 2014-02-1 Show GitHub Exploit DB Packet Storm
224868 7.5 危険 SimpleHRM - SimpleHRM の flexycms/modules/user/user_manager.php のログインページにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2013-2498 2014-03-4 14:58 2013-04-12 Show GitHub Exploit DB Packet Storm
224869 4.3 警告 CMS Made Simple - CMS Made Simple の lib/filemanager/ImageManager/editorFrame.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-2092 2014-03-4 14:46 2014-02-20 Show GitHub Exploit DB Packet Storm
224870 3.5 注意 CMS Made Simple - CMS Made Simple にクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-0334 2014-03-4 14:43 2014-02-28 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 27, 2026, 4:35 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1971 5.3 MEDIUM
Network
- - The Pie Register WordPress plugin before 3.8.4.10 does not use sufficiently random values when generating its account verification tokens, allowing unauthenticated attackers to predict a valid token… - CVE-2026-10530 2026-06-23 03:38 2026-06-22 Show GitHub Exploit DB Packet Storm
1972 6.1 MEDIUM
Network
- - The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which c… - CVE-2026-4110 2026-06-23 03:38 2026-06-22 Show GitHub Exploit DB Packet Storm
1973 7.1 HIGH
Network
- - The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which c… CWE-79
Cross-site Scripting
CVE-2026-4259 2026-06-23 03:38 2026-06-22 Show GitHub Exploit DB Packet Storm
1974 7.1 HIGH
Network
- - The Transbank Webpay WordPress plugin before 1.14.0 does not sanitize and escape logs to be displayed, allowing unauthenticated users to perform Stored XSS attacks against logged in administrator CWE-79
Cross-site Scripting
CVE-2026-6858 2026-06-23 03:38 2026-06-22 Show GitHub Exploit DB Packet Storm
1975 5.3 MEDIUM
Network
- - The Motors WordPress plugin before 1.4.110 does not have proper authorisation and CSRF checks on one of its AJAX actions, allowing unauthenticated attackers to modify arbitrary post metadata, such a… CWE-862
 Missing Authorization
CVE-2026-7859 2026-06-23 03:38 2026-06-22 Show GitHub Exploit DB Packet Storm
1976 8.8 HIGH
Network
- - The Vitepos WordPress plugin before 3.4.2 does not properly restrict the roles that can be assigned when creating new users via one of its REST API endpoints, allowing authenticated users with a cus… CWE-269
 Improper Privilege Management
CVE-2026-8157 2026-06-23 03:38 2026-06-22 Show GitHub Exploit DB Packet Storm
1977 8.2 HIGH
Network
- - Joomla! Component JB Visa 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the visatype parameter… CWE-89
SQL Injection
CVE-2017-20255 2026-06-23 03:37 2026-06-20 Show GitHub Exploit DB Packet Storm
1978 8.2 HIGH
Network
- - Joomla! Component Bargain Product VM3 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the produc… CWE-89
SQL Injection
CVE-2017-20261 2026-06-23 03:37 2026-06-20 Show GitHub Exploit DB Packet Storm
1979 8.2 HIGH
Network
- - Joomla! Component Calendar Planner 1.0.1 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL commands through the category_id parameter. Attackers can send GET… CWE-89
SQL Injection
CVE-2017-20267 2026-06-23 03:37 2026-06-20 Show GitHub Exploit DB Packet Storm
1980 8.2 HIGH
Network
- - Joomla Event Registration Pro Calendar 4.1.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id … CWE-89
SQL Injection
CVE-2017-20273 2026-06-23 03:37 2026-06-20 Show GitHub Exploit DB Packet Storm