Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 7, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
241351 7.5 危険 bpowerhouse - Mini Blog の index.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-5594 2012-06-26 16:03 2008-12-16 Show GitHub Exploit DB Packet Storm
241352 7.5 危険 bpowerhouse - Mini CMS の index.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-5593 2012-06-26 16:03 2008-12-16 Show GitHub Exploit DB Packet Storm
241353 6.8 警告 check up - Check Up New Generation の findoffice.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-5586 2012-06-26 16:03 2008-12-16 Show GitHub Exploit DB Packet Storm
241354 7.5 危険 adcomplete - Poll Pro のログイン機能における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-5573 2012-06-26 16:03 2008-12-15 Show GitHub Exploit DB Packet Storm
241355 5 警告 dotnetindex - Professional Download Assistant におけるデータベースファイルをダウンロードされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-5572 2012-06-26 16:03 2008-12-15 Show GitHub Exploit DB Packet Storm
241356 7.5 危険 dotnetindex - Professional Download Assistant の admin/login.asp における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-5571 2012-06-26 16:03 2008-12-15 Show GitHub Exploit DB Packet Storm
241357 7.5 危険 Activewebsoftwares - Active eWebquiz の start.asp における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-5631 2012-06-26 16:03 2008-12-17 Show GitHub Exploit DB Packet Storm
241358 7.5 危険 Activewebsoftwares - Active Trade の account.asp における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-5627 2012-06-26 16:03 2008-12-17 Show GitHub Exploit DB Packet Storm
241359 4 警告 dxmsoft - XM Easy Personal FTP Server におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2008-5626 2012-06-26 16:03 2008-12-17 Show GitHub Exploit DB Packet Storm
241360 5 警告 aspapps - ASP AutoDealer におけるデータベースをダウンロードされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-5608 2012-06-26 16:03 2008-12-16 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 7, 2026, 4:22 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
267411 6.1 MEDIUM
Network
never5 download_monitor The download-monitor plugin before 1.7.1 for WordPress has XSS related to add_query_arg. CWE-79
Cross-site Scripting
CVE-2015-9296 2024-11-21 11:40 2019-08-14 Show GitHub Exploit DB Packet Storm
267412 6.1 MEDIUM
Network
bestwebsoft contact_form The contact-form-plugin plugin before 3.96 for WordPress has XSS. CWE-79
Cross-site Scripting
CVE-2015-9295 2024-11-21 11:40 2019-08-14 Show GitHub Exploit DB Packet Storm
267413 6.1 MEDIUM
Network
tipsandtricks-hq all_in_one_wp_security_\&_firewall The all-in-one-wp-security-and-firewall plugin before 3.9.5 for WordPress has XSS in add_query_arg and remove_query_arg function instances. CWE-79
Cross-site Scripting
CVE-2015-9294 2024-11-21 11:40 2019-08-14 Show GitHub Exploit DB Packet Storm
267414 6.1 MEDIUM
Network
tipsandtricks-hq all_in_one_wp_security_\&_firewall The all-in-one-wp-security-and-firewall plugin before 3.9.8 for WordPress has XSS in the unlock request feature. CWE-79
Cross-site Scripting
CVE-2015-9293 2024-11-21 11:40 2019-08-14 Show GitHub Exploit DB Packet Storm
267415 6.1 MEDIUM
Network
ultimatemember ultimate_member The ultimate-member plugin before 1.3.18 for WordPress has XSS via text input. CWE-79
Cross-site Scripting
CVE-2015-9304 2024-11-21 11:40 2019-08-13 Show GitHub Exploit DB Packet Storm
267416 6.1 MEDIUM
Network
simplesharebuttons simple_share_buttons_adder The simple-share-buttons-adder plugin before 6.0.0 for WordPress has XSS. CWE-79
Cross-site Scripting
CVE-2015-9303 2024-11-21 11:40 2019-08-13 Show GitHub Exploit DB Packet Storm
267417 6.1 MEDIUM
Network
smackcoders import_all_pages\
_post_types\
_products\
_orders\
_and_users_as_xml_\&_csv
The wp-ultimate-csv-importer plugin before 3.8.1 for WordPress has XSS. CWE-79
Cross-site Scripting
CVE-2015-9306 2024-11-21 11:40 2019-08-13 Show GitHub Exploit DB Packet Storm
267418 6.1 MEDIUM
Network
flippercode wp_google_map The wp-google-map-plugin plugin before 2.3.7 for WordPress has XSS related to the add_query_arg() and remove_query_arg() functions. CWE-79
Cross-site Scripting
CVE-2015-9305 2024-11-21 11:40 2019-08-13 Show GitHub Exploit DB Packet Storm
267419 8.8 HIGH
Network
6kbbs 6kbbs 6kbbs 7.1 and 8.0 allows CSRF via portalchannel_ajax.php (id or code parameter) or admin.php (fileids parameter). CWE-352
 Origin Validation Error
CVE-2015-9292 2024-11-21 11:40 2019-08-9 Show GitHub Exploit DB Packet Storm
267420 7.5 HIGH
Network
cpanel cpanel cPanel before 11.52.0.13 does not prevent arbitrary file-read operations via get_information_for_applications (CPANEL-1221). CWE-284
Improper Access Control
CVE-2015-9291 2024-11-21 11:40 2019-08-2 Show GitHub Exploit DB Packet Storm