Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":July 1, 2026, 12:08 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228801 3.5 注意 AlienWP - Drupal 用 Hatch テーマにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-4138 2013-09-11 16:42 2013-07-10 Show GitHub Exploit DB Packet Storm
228802 7.2 危険 ソフォス - Sophos Web Appliance の /opt/cma/bin/clear_keys.pl の close_connections 関数における権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-4984 2013-09-11 14:45 2013-09-9 Show GitHub Exploit DB Packet Storm
228803 7.5 危険 VMware - VMware ESX および ESXi におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2013-3657 2013-09-11 14:02 2013-09-6 Show GitHub Exploit DB Packet Storm
228804 6.4 警告 VMware - VMware ESX および ESXi におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2013-3658 2013-09-11 13:54 2013-09-6 Show GitHub Exploit DB Packet Storm
228805 4.3 警告 VideoWhisper.com - WordPress 用 VideoWhisper Live Streaming Integration プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-5714 2013-09-11 13:51 2013-08-23 Show GitHub Exploit DB Packet Storm
228806 5 警告 Digium - 複数の Asterisk 製品の SIP チャネルドライバにおけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2013-5642 2013-09-11 13:50 2013-08-27 Show GitHub Exploit DB Packet Storm
228807 5 警告 Digium - Asterisk Open Source および Certified Asterisk の SIP チャネルドライバにおけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2013-5641 2013-09-11 13:49 2013-08-27 Show GitHub Exploit DB Packet Storm
228808 5 警告 Strata Technologies - Twilight CMS で使用される DeWeS Web サーバにおけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2013-4900 2013-09-11 13:46 2013-08-21 Show GitHub Exploit DB Packet Storm
228809 4.3 警告 Strata Technologies - Twilight CMS におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-4899 2013-09-11 13:45 2013-08-21 Show GitHub Exploit DB Packet Storm
228810 2.6 注意 サイボウズ - サイボウズ Office におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-4703 2013-09-11 13:32 2013-09-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:July 1, 2026, 4:27 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1961 7.2 HIGH
Network
- - The Kargo Takip plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.2 via the 'api_url' parameter. This makes it possible for unauthenticated att… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-12095 2026-06-25 22:26 2026-06-24 Show GitHub Exploit DB Packet Storm
1962 4.3 MEDIUM
Network
- - The Assistio plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the assistio_plugin_delete_assistio_settings()… CWE-862
 Missing Authorization
CVE-2026-8614 2026-06-25 22:26 2026-06-24 Show GitHub Exploit DB Packet Storm
1963 4.3 MEDIUM
Network
- - The Advance Nav Menu Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.3. This is due to the plugin not properly verifying that a user is auth… CWE-862
 Missing Authorization
CVE-2026-8688 2026-06-25 22:26 2026-06-24 Show GitHub Exploit DB Packet Storm
1964 5.3 MEDIUM
Network
- - The RentMy Real-Time Rental Management Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.4.1. This is due to the plugin not properly verifyin… CWE-862
 Missing Authorization
CVE-2026-8690 2026-06-25 22:26 2026-06-24 Show GitHub Exploit DB Packet Storm
1965 8.8 HIGH
Network
- - The Welcome Software Publishing plugin for WordPress is vulnerable to Arbitrary Options Update in all versions up to and including 0.0.31. This is due to a missing capability check in the nc_setOptio… CWE-862
 Missing Authorization
CVE-2026-4297 2026-06-25 22:26 2026-06-24 Show GitHub Exploit DB Packet Storm
1966 4.3 MEDIUM
Network
- - The MP Customize Login Page plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in all versions up to and including 1.0. This is due to a completely broken nonce validation in the… CWE-352
 Origin Validation Error
CVE-2026-6292 2026-06-25 22:26 2026-06-24 Show GitHub Exploit DB Packet Storm
1967 6.1 MEDIUM
Network
- - The EntreDroppers plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all versions up to, and including, 1.1.2 due to insufficient input sanitization and ou… CWE-79
Cross-site Scripting
CVE-2026-8628 2026-06-25 22:26 2026-06-24 Show GitHub Exploit DB Packet Storm
1968 7.5 HIGH
Network
- - The ClearSale Total plugin for WordPress is vulnerable to SQL Injection via the `pagseguro[metodo]` POST parameter of the `clearsale_total_push` AJAX action in all versions up to, and including, 3.4.… CWE-89
SQL Injection
CVE-2026-8705 2026-06-25 22:26 2026-06-24 Show GitHub Exploit DB Packet Storm
1969 6.1 MEDIUM
Network
- - The Osiris Signature Banner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.5. This is due to missing or incorrect nonce validation on a funct… CWE-352
 Origin Validation Error
CVE-2026-8905 2026-06-25 22:26 2026-06-24 Show GitHub Exploit DB Packet Storm
1970 4.3 MEDIUM
Network
- - The Generate Security.txt plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.0.12. This is due to the plugin not properly verifying that a user is auth… CWE-862
 Missing Authorization
CVE-2026-9616 2026-06-25 22:26 2026-06-24 Show GitHub Exploit DB Packet Storm