Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 12, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
241921 3.5 注意 Digium - Asterisk Open Source の SIP チャネルドライバにおけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2009-0871 2012-06-26 16:10 2009-02-6 Show GitHub Exploit DB Packet Storm
241922 8.8 危険 GeoVision - LIVEX_~1.OCX の GeoVision LiveX ActiveX コントロールにおけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2009-0865 2012-06-26 16:10 2009-03-10 Show GitHub Exploit DB Packet Storm
241923 4.3 警告 denorastats - phpDenora におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-0861 2012-06-26 16:10 2009-03-10 Show GitHub Exploit DB Packet Storm
241924 6.9 警告 dash - dash における任意のコードを実行される脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2009-0854 2012-06-26 16:10 2009-03-11 Show GitHub Exploit DB Packet Storm
241925 10 危険 Foxit Software Inc - Foxit Reader におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-0837 2012-06-26 16:10 2009-03-10 Show GitHub Exploit DB Packet Storm
241926 10 危険 Foxit Software Inc - Foxit Reader における任意のプログラムを実行される脆弱性 CWE-119
バッファエラー
CVE-2009-0836 2012-06-26 16:10 2009-03-10 Show GitHub Exploit DB Packet Storm
241927 7.5 危険 PHP-Fusion
ausimods
- PHP-Fusion の E-Cart モジュールの items.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-0832 2012-06-26 16:10 2009-03-5 Show GitHub Exploit DB Packet Storm
241928 4.3 警告 andrew freed - QuoteBook におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-0830 2012-06-26 16:10 2009-03-5 Show GitHub Exploit DB Packet Storm
241929 7.5 危険 andrew freed - QuoteBook における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-0829 2012-06-26 16:10 2009-03-5 Show GitHub Exploit DB Packet Storm
241930 5 警告 freedville - QuoteBook におけるユーザの資格情報を含むデータベースファイルをダウンロードされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2009-0828 2012-06-26 16:10 2009-03-5 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 12, 2026, 5:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
268431 9.8 CRITICAL
Network
sizmic plugmatter_optin_feature_box The plugmatter-optin-feature-box-lite plugin before 2.0.14 for WordPress has SQL injection via the wp-admin/admin-ajax.php?action=pmfb_mailchimp pmfb_tid parameter. CWE-89
SQL Injection
CVE-2015-9451 2024-11-21 11:40 2019-10-8 Show GitHub Exploit DB Packet Storm
268432 9.8 CRITICAL
Network
sizmic plugmatter_optin_feature_box The plugmatter-optin-feature-box-lite plugin before 2.0.14 for WordPress has SQL injection via the wp-admin/admin-ajax.php?action=pmfb_cc pmfb_tid parameter. CWE-89
SQL Injection
CVE-2015-9450 2024-11-21 11:40 2019-10-8 Show GitHub Exploit DB Packet Storm
268433 8.8 HIGH
Network
pressified sendpress The sendpress plugin before 1.2 for WordPress has SQL Injection via the wp-admin/admin.php?page=sp-queue listid parameter. CWE-89
SQL Injection
CVE-2015-9448 2024-11-21 11:40 2019-09-26 Show GitHub Exploit DB Packet Storm
268434 6.5 MEDIUM
Network
unitegallery unite_gallery_lite The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin.php galleryid or id parameters. CWE-352
 Origin Validation Error
CVE-2015-9447 2024-11-21 11:40 2019-09-26 Show GitHub Exploit DB Packet Storm
268435 8.8 HIGH
Network
unitegallery unite_gallery_lite The unite-gallery-lite plugin before 1.5 for WordPress has SQL injection via data[galleryID] to wp-admin/admin-ajax.php. CWE-89
SQL Injection
CVE-2015-9446 2024-11-21 11:40 2019-09-26 Show GitHub Exploit DB Packet Storm
268436 8.8 HIGH
Network
unitegallery unite_gallery_lite The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin-ajax.php in a unitegallery_ajax_action operation. CWE-352
 Origin Validation Error
CVE-2015-9445 2024-11-21 11:40 2019-09-26 Show GitHub Exploit DB Packet Storm
268437 6.1 MEDIUM
Network
altosresearch altos-connect The altos-connect plugin 1.3.0 for WordPress has XSS via the wp-content/plugins/altos-connect/jquery-validate/demo/demo/captcha/index.php/ PATH_SELF. CWE-79
Cross-site Scripting
CVE-2015-9444 2024-11-21 11:40 2019-09-26 Show GitHub Exploit DB Packet Storm
268438 6.5 MEDIUM
Network
wp_accurate_form_data_project wp_accurate_form_data The accurate-form-data-real-time-form-validation plugin 1.2 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=Accu_Data_WP. CWE-352
 Origin Validation Error
CVE-2015-9443 2024-11-21 11:40 2019-09-26 Show GitHub Exploit DB Packet Storm
268439 6.5 MEDIUM
Network
avenirsoft directdownload The avenirsoft-directdownload plugin 1.0 for WordPress has CSRF with resultant XSS via wp-admin/admin.php?page=avenir_plugin. CWE-352
 Origin Validation Error
CVE-2015-9442 2024-11-21 11:40 2019-09-26 Show GitHub Exploit DB Packet Storm
268440 6.5 MEDIUM
Network
bookmarkify_project bookmarkify The bookmarkify plugin 2.9.2 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=bookmarkify.php. CWE-352
 Origin Validation Error
CVE-2015-9441 2024-11-21 11:40 2019-09-26 Show GitHub Exploit DB Packet Storm