Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
101 7.5 重要
Network
メディアテック nr16
NR17R
NR15
nr17
メディアテックのNR15等の複数製品における到達可能なアサーションに関する脆弱性 CWE-617
到達可能なアサーション
CVE-2026-20405 2026-02-6 10:37 2026-02-2 Show GitHub Exploit DB Packet Storm
102 7.5 重要
Network
メディアテック nr16
NR17R
NR15
nr17
メディアテックのNR15等の複数製品における複数の脆弱性 CWE-754
CWE-770
CVE-2026-20406 2026-02-6 10:37 2026-02-2 Show GitHub Exploit DB Packet Storm
103 9.3 緊急
Local
メディアテック nbiot sdk メディアテックのnbiot sdkにおける境界外書き込みに関する脆弱性 CWE-787
境界外書き込み
CVE-2026-20407 2026-02-6 10:37 2026-02-2 Show GitHub Exploit DB Packet Storm
104 8.8 重要
Adjacent
OpenWrt Project
メディアテック
openwrt
Software Development Kit
メディアテック等の複数ベンダの製品における複数の脆弱性 CWE-122
CWE-787
CVE-2026-20408 2026-02-6 10:37 2026-02-2 Show GitHub Exploit DB Packet Storm
105 7.8 重要
Local
Google Android GoogleのAndroidにおける境界外書き込みに関する脆弱性 CWE-787
境界外書き込み
CVE-2026-20409 2026-02-6 10:37 2026-02-2 Show GitHub Exploit DB Packet Storm
106 6.7 警告
Local
Google Android GoogleのAndroidにおける境界外書き込みに関する脆弱性 CWE-787
境界外書き込み
CVE-2026-20410 2026-02-6 10:37 2026-02-2 Show GitHub Exploit DB Packet Storm
107 7.8 重要
Local
Google Android GoogleのAndroidにおける解放済みメモリの使用に関する脆弱性 CWE-416
解放済みメモリの使用
CVE-2026-20411 2026-02-6 10:37 2026-02-2 Show GitHub Exploit DB Packet Storm
108 7.8 重要
Local
Google Android GoogleのAndroidにおける境界外書き込みに関する脆弱性 CWE-787
境界外書き込み
CVE-2026-20412 2026-02-6 10:36 2026-02-2 Show GitHub Exploit DB Packet Storm
109 6.5 警告
Network
hono hono honoにおける不正な正規表現に関する脆弱性 CWE-185
不正な正規表現
CVE-2026-24398 2026-02-6 10:36 2026-01-27 Show GitHub Exploit DB Packet Storm
110 5.3 警告
Network
hono hono honoにおける複数の脆弱性 CWE-524
CWE-613
CVE-2026-24472 2026-02-6 10:36 2026-01-27 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 17, 2026, 4:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
307221 - gallarific gallarific Gallarific Free Edition 1.1 does not require authentication for (1) photos.php, (2) comments.php, and (3) gallery.php in gadmin/, which allows remote attackers to edit objects via a direct request, d… CWE-287
Improper Authentication
CVE-2008-1469 2011-07-25 13:00 2008-03-25 Show GitHub Exploit DB Packet Storm
307222 - gallarific gallarific More information available at: http://www.securityfocus.com/bid/28163/info CWE-287
Improper Authentication
CVE-2008-1469 2011-07-25 13:00 2008-03-25 Show GitHub Exploit DB Packet Storm
307223 - linpha linpha Multiple cross-site scripting (XSS) vulnerabilities in LinPHA before 1.3.3 allow remote attackers to inject arbitrary web script or HTML via (1) ftp/index.php, (2) viewer.php, (3) functions/other.php… CWE-79
Cross-site Scripting
CVE-2008-1487 2011-07-25 13:00 2008-03-25 Show GitHub Exploit DB Packet Storm
307224 - netbsd netbsd The accept function in NetBSD-current before 20061023, NetBSD 3.0 and 3.0.1 before 20061024, and NetBSD 2.x before 20061029 allows local users to cause a denial of service (socket consumption) via an… CWE-20
 Improper Input Validation 
CVE-2006-6653 2011-07-25 13:00 2006-12-20 Show GitHub Exploit DB Packet Storm
307225 - netbsd netbsd This vulnerability is addressed in the following product updates: NetBSD, NetBSD, current (10/23/2006) NetBSD, NetBSD, 3.0 (10/24/2006) NetBSD, NetBSD, 3.0.1 (10/24/2006) NetBSD, NetBSD, 2.0 (10… CWE-20
 Improper Input Validation 
CVE-2006-6653 2011-07-25 13:00 2006-12-20 Show GitHub Exploit DB Packet Storm
307226 - web-app.net webapp Cross-site scripting (XSS) vulnerability in Web Automated Perl Portal (WebAPP) 0.9.9.4, and 0.9.9.3.4 Network Edition (NE) (aka WebAPP.NET), allows remote attackers to inject arbitrary web script or … CWE-79
Cross-site Scripting
CVE-2006-6687 2011-07-25 13:00 2006-12-22 Show GitHub Exploit DB Packet Storm
307227 - clamav clamav The cabd_find function in cabd.c of the libmspack library (mspack) for Clam AntiVirus (ClamAV) before 0.87.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted CAB fil… CWE-399
 Resource Management Errors
CVE-2005-3501 2011-07-14 13:00 2005-11-5 Show GitHub Exploit DB Packet Storm
307228 - php php The compress.bzip2:// URL wrapper provided by the bz2 extension in PHP before 4.4.7, and 5.x before 5.2.2, does not implement safemode or open_basedir checks, which allows remote attackers to read bz… CWE-264
Permissions, Privileges, and Access Controls
CVE-2007-1461 2011-07-13 13:00 2007-03-15 Show GitHub Exploit DB Packet Storm
307229 - opera opera_browser The FTP protocol implementation in Opera 9.10 allows remote attackers to allows remote servers to force the client to connect to other servers, perform a proxied port scan, or obtain sensitive inform… CWE-200
Information Exposure
CVE-2007-1563 2011-07-8 13:00 2007-03-22 Show GitHub Exploit DB Packet Storm
307230 - wikkawiki wikkawiki The RecentChanges feature in WikkaWiki (Wikka Wiki) before 1.1.6.3 allows remote attackers to obtain the names, and possibly revision notes and dates, of private pages via RSS feeds. CWE-200
Information Exposure
CVE-2007-2552 2011-06-16 13:00 2007-05-9 Show GitHub Exploit DB Packet Storm