Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
991 5.4 警告
Network
HasThemes WC Builder HasThemesのWordPress用WC Builderにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-29926 2026-01-30 14:14 2024-03-27 Show GitHub Exploit DB Packet Storm
992 9.8 緊急
Network
HzManyun Education and Training System HzManyunのEducation and Training Systemにおける複数の脆弱性 CWE-284
CWE-434
CWE-434
CVE-2025-1555 2026-01-30 14:14 2025-02-21 Show GitHub Exploit DB Packet Storm
993 9.8 緊急
Network
HzManyun Education and Training System HzManyunのEducation and Training Systemにおける複数の脆弱性 CWE-77
CWE-78
CWE-78
CVE-2025-1676 2026-01-30 14:14 2025-02-25 Show GitHub Exploit DB Packet Storm
994 9.1 緊急
Network
RosarioSIS Student Information System Academia ERPのStudent Information Systemにおけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2025-25948 2026-01-30 14:14 2025-03-3 Show GitHub Exploit DB Packet Storm
995 5.4 警告
Network
RosarioSIS Student Information System Academia ERPのStudent Information Systemにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2025-25949 2026-01-30 14:14 2025-03-3 Show GitHub Exploit DB Packet Storm
996 6.5 警告
Network
デル Data Protection Advisor デルのData Protection Advisorにおけるテンプレートエンジンで使用される特殊な要素の不適切な無効化に関する脆弱性 CWE-1336
テンプレートエンジンで使用される特殊な要素の不適切な無効化
CVE-2025-46699 2026-01-30 14:14 2026-01-23 Show GitHub Exploit DB Packet Storm
997 9.8 緊急
Network
ThemeMove MaxCoach ThemeMoveのWordPress用MaxCoachにおけるPHP リモートファイルインクルージョンの脆弱性 CWE-98
PHP リモートファイルインクルージョン
CVE-2025-58206 2026-01-30 14:14 2025-09-5 Show GitHub Exploit DB Packet Storm
998 9.8 緊急
Network
ThemeMove Makeaholic ThemeMoveのWordPress用Makeaholicにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2025-58210 2026-01-30 14:13 2025-09-3 Show GitHub Exploit DB Packet Storm
999 7.5 重要
Network
DwyerOmega Isensix Advanced Remote Monitoring System (ARMS) Firmware DwyerOmegaのIsensix Advanced Remote Monitoring System (ARMS) FirmwareにおけるSQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2025-59379 2026-01-30 14:13 2026-01-6 Show GitHub Exploit DB Packet Storm
1000 9.8 緊急
Network
H3C H3C Magic BA1500L Firmware
H3C MC102-G Firmware
H3CのH3C Magic BA1500L Firmware等の複数製品における不適切なデフォルトパーミッションに関する脆弱性 CWE-276
不適切なデフォルトパーミッション
CVE-2025-60262 2026-01-30 14:13 2026-01-6 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 24, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
304701 - francisco_burzi php-nuke Multiple SQL injection vulnerabilities in the Web_Links module for PHP-Nuke 5.x through 6.5 allows remote attackers to steal sensitive information via numeric fields, as demonstrated using (1) the vi… NVD-CWE-Other
CVE-2003-0279 2017-07-11 10:29 2003-06-16 Show GitHub Exploit DB Packet Storm
304702 - youngzsoft cmailserver Multiple buffer overflows in the SMTP Service for ESMTP CMailServer 4.0.2003.03.27 allow remote attackers to execute arbitrary code via long (1) MAIL FROM or (2) RCPT TO commands. NVD-CWE-Other
CVE-2003-0280 2017-07-11 10:29 2003-06-16 Show GitHub Exploit DB Packet Storm
304703 - firebirdsql firebird Buffer overflow in Firebird 1.0.2 and other versions before 1.5, and possibly other products that use the InterBase codebase, allows local users to execute arbitrary code via a long INTERBASE environ… NVD-CWE-Other
CVE-2003-0281 2017-07-11 10:29 2003-06-16 Show GitHub Exploit DB Packet Storm
304704 - phorum phorum Cross-site scripting (XSS) vulnerability in Phorum before 3.4.3 allows remote attackers to inject arbitrary web script and HTML tags via a message with a "<<" before a tag name in the (1) subject, (2… NVD-CWE-Other
CVE-2003-0283 2017-07-11 10:29 2003-06-16 Show GitHub Exploit DB Packet Storm
304705 - ibm aix IBM AIX 5.2 and earlier distributes Sendmail with a configuration file (sendmail.cf) with the (1) promiscuous_relay, (2) accept_unresolvable_domains, and (3) accept_unqualified_senders features enabl… NVD-CWE-Other
CVE-2003-0285 2017-07-11 10:29 2003-06-16 Show GitHub Exploit DB Packet Storm
304706 - snitz_communications snitz_forums_2000 SQL injection vulnerability in register.asp in Snitz Forums 2000 before 3.4.03, and possibly 3.4.07 and earlier, allows remote attackers to execute arbitrary stored procedures via the Email variable. CWE-89
SQL Injection
CVE-2003-0286 2017-07-11 10:29 2003-06-16 Show GitHub Exploit DB Packet Storm
304707 - six_apart movable_type Cross-site scripting (XSS) vulnerability in Movable Type before 2.6, and possibly other versions including 2.63, allows remote attackers to insert arbitrary web script or HTML via the Name textbox, p… NVD-CWE-Other
CVE-2003-0287 2017-07-11 10:29 2003-06-16 Show GitHub Exploit DB Packet Storm
304708 - hiroaki_shirouzu ip_messenger Buffer overflow in the file & folder transfer mechanism for IP Messenger for Win 2.00 through 2.02 allows remote attackers to execute arbitrary code via file with a long filename, which triggers the … NVD-CWE-Other
CVE-2003-0288 2017-07-11 10:29 2003-06-16 Show GitHub Exploit DB Packet Storm
304709 - cdrtools cdrecord Format string vulnerability in scsiopen.c of the cdrecord program in cdrtools 2.0 allows local users to gain privileges via format string specifiers in the dev parameter. NVD-CWE-Other
CVE-2003-0289 2017-07-11 10:29 2003-06-16 Show GitHub Exploit DB Packet Storm
304710 - etype eserv Memory leak in eServ 2.9x allows remote attackers to cause a denial of service (memory exhaustion) via a large number of connections, whose memory is not freed when the connection is terminated. NVD-CWE-Other
CVE-2003-0290 2017-07-11 10:29 2003-06-16 Show GitHub Exploit DB Packet Storm