Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 11, 2026, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
242111 7.5 危険 exoscripts - Exocrew ExoPHPDesk の admin.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6917 2012-06-26 16:10 2009-08-7 Show GitHub Exploit DB Packet Storm
242112 6.8 警告 brewblogger - BB の includes/authentication.inc.php の authenticateUser 関数における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6911 2012-06-26 16:10 2009-08-6 Show GitHub Exploit DB Packet Storm
242113 6.8 警告 2532gigs - 2532designs 2532|Gigs Stable の checkuser.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6907 2012-06-26 16:10 2009-08-6 Show GitHub Exploit DB Packet Storm
242114 4.3 警告 babbleboard - BabbleBoard の index.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-6906 2012-06-26 16:10 2009-08-6 Show GitHub Exploit DB Packet Storm
242115 6 警告 babbleboard - BabbleBoard の index.php におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2008-6905 2012-06-26 16:10 2009-08-6 Show GitHub Exploit DB Packet Storm
242116 6.8 警告 2532gigs - 2532designs 2532|Gigs の upload_flyer.php における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2008-6902 2012-06-26 16:10 2009-08-5 Show GitHub Exploit DB Packet Storm
242117 5.1 警告 2532gigs - 2532designs 2532|Gigs におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-6901 2012-06-26 16:10 2009-08-5 Show GitHub Exploit DB Packet Storm
242118 6.5 警告 availscript - AvailScript Article Script の addpen.php の "ペンネーム / 作成名を追加" 機能における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2008-6900 2012-06-26 16:10 2009-08-5 Show GitHub Exploit DB Packet Storm
242119 9 危険 freeSSHd - freeSSHd におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-6899 2012-06-26 16:10 2009-08-5 Show GitHub Exploit DB Packet Storm
242120 9.3 危険 andres garcia - Andres Garcia Getleft の Getleft.exe におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-6897 2012-06-26 16:10 2009-08-5 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 11, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
268181 6.1 MEDIUM
Network
sandhillsdev
easydigitaldownloads
easy_digital_downloads
simple_shipping
The Easy Digital Downloads (EDD) Simple Shipping extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.… CWE-79
Cross-site Scripting
CVE-2015-9527 2024-11-21 11:40 2019-10-24 Show GitHub Exploit DB Packet Storm
268182 6.1 MEDIUM
Network
sandhillsdev
easydigitaldownloads
easy_digital_downloads
reviews
The Easy Digital Downloads (EDD) Reviews extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x befo… CWE-79
Cross-site Scripting
CVE-2015-9526 2024-11-21 11:40 2019-10-24 Show GitHub Exploit DB Packet Storm
268183 6.1 MEDIUM
Network
sandhillsdev
easydigitaldownloads
easy_digital_downloads
recurring_payments
The Easy Digital Downloads (EDD) Recurring Payments extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and… CWE-79
Cross-site Scripting
CVE-2015-9525 2024-11-21 11:40 2019-10-24 Show GitHub Exploit DB Packet Storm
268184 6.1 MEDIUM
Network
artificial_intelligence_project artificial_intelligence The Artificial Intelligence theme before 1.2.4 for WordPress has XSS because Genericons HTML files are unnecessarily placed under the web root. CWE-79
Cross-site Scripting
CVE-2015-9501 2024-11-21 11:40 2019-10-23 Show GitHub Exploit DB Packet Storm
268185 6.1 MEDIUM
Network
exquisite_ultimate_newspaper_project exquisite_ultimate_newspaper The Exquisite Ultimate Newspaper theme 1.3.3 for WordPress has XSS via the anchor identifier to assets/js/jquery.foundation.plugins.js. CWE-79
Cross-site Scripting
CVE-2015-9500 2024-11-21 11:40 2019-10-23 Show GitHub Exploit DB Packet Storm
268186 9.8 CRITICAL
Network
themepunch showbiz_pro The Showbiz Pro plugin through 1.7.1 for WordPress has PHP code execution by uploading a .php file within a ZIP archive. CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2015-9499 2024-11-21 11:40 2019-10-23 Show GitHub Exploit DB Packet Storm
268187 8.8 HIGH
Network
wpserveur wps_hide_login The wps-hide-login plugin before 1.1 for WordPress has CSRF that affects saving an option value. CWE-352
 Origin Validation Error
CVE-2015-9498 2024-11-21 11:40 2019-10-23 Show GitHub Exploit DB Packet Storm
268188 8.8 HIGH
Network
ad_inserter_project ad_inserter The ad-inserter plugin before 1.5.3 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=ad-inserter.php. CWE-352
 Origin Validation Error
CVE-2015-9497 2024-11-21 11:40 2019-10-23 Show GitHub Exploit DB Packet Storm
268189 8.8 HIGH
Network
freshmail freshmail-newsletter The freshmail-newsletter plugin before 1.6 for WordPress has shortcode.php SQL Injection via the 'FM_form id=' substring. CWE-89
SQL Injection
CVE-2015-9496 2024-11-21 11:40 2019-10-23 Show GitHub Exploit DB Packet Storm
268190 6.1 MEDIUM
Network
syndication_links_project syndication_links The syndication-links plugin before 1.0.3 for WordPress has XSS via the genericons/example.html anchor identifier. CWE-79
Cross-site Scripting
CVE-2015-9495 2024-11-21 11:40 2019-10-23 Show GitHub Exploit DB Packet Storm