Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1391 8 重要
Adjacent
EnGenius Technologies EWS356-FIR Firmware EnGenius TechnologiesのEWS356-FIR FirmwareにおけるOS コマンドインジェクションの脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2024-31976 2026-01-28 12:31 2024-11-27 Show GitHub Exploit DB Packet Storm
1392 9.8 緊急
Network
EnGenius Technologies EWS356-FIT Firmware EnGenius TechnologiesのEWS356-FIT FirmwareにおけるOS コマンドインジェクションの脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2024-36061 2026-01-28 12:31 2024-11-11 Show GitHub Exploit DB Packet Storm
1393 7.5 重要
Network
ジュニパーネットワークス Junos Containerized Routing Protocol Daemon ジュニパーネットワークスのJunos Containerized Routing Protocol Daemonにおける例外的な状態の処理に関する脆弱性 CWE-755
例外的な状態における不適切な処理
CVE-2024-39547 2026-01-28 12:31 2024-10-11 Show GitHub Exploit DB Packet Storm
1394 9.8 緊急
Network
wpwebelite WooCommerce PDF Vouchers WPWeb EliteのWordPress用WooCommerce PDF Vouchersにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2024-39650 2026-01-28 12:31 2024-11-1 Show GitHub Exploit DB Packet Storm
1395 6.8 警告
Network
ヒューレット・パッカード HP Color LaserJet MFP M478-M479 W1A75A Firmware
HP Color LaserJet MFP M478-M479 W1A82A Firmware
HP Color LaserJet MFP&…
ヒューレット・パッカードのHP Color LaserJet MFP M478-M479 W1A75A Firmware等の複数製品における重要な機能に対する認証の欠如に関する脆弱性 CWE-306
重要な機能に対する認証の欠如 解説
CVE-2024-5143 2026-01-28 12:31 2024-05-23 Show GitHub Exploit DB Packet Storm
1396 9.8 緊急
Network
ヒューレット・パッカード HP Smart Universal Printing Driver (SUPD) ヒューレット・パッカードのHP Smart Universal Printing Driver (SUPD)における境界外書き込みに関する脆弱性 CWE-787
境界外書き込み
CVE-2024-9419 2026-01-28 12:31 2024-10-30 Show GitHub Exploit DB Packet Storm
1397 7.4 重要
Network
ジュニパーネットワークス Security Director Policy Enforcer ジュニパーネットワークスのSecurity Director Policy Enforcerにおける重要な機能に対する認証の欠如に関する脆弱性 CWE-306
重要な機能に対する認証の欠如 解説
CVE-2025-11198 2026-01-28 12:31 2025-10-9 Show GitHub Exploit DB Packet Storm
1398 4.8 警告
Network
Centreon Dynamic Service Management CentreonのDynamic Service Managementにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2025-12511 2026-01-28 12:31 2026-01-5 Show GitHub Exploit DB Packet Storm
1399 7.2 重要
Network
Centreon Centreon Open Tickets CentreonのCentreon Open TicketsにおけるSQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2025-12514 2026-01-28 12:30 2025-12-22 Show GitHub Exploit DB Packet Storm
1400 9.8 緊急
Network
txthinking brook ThemeMoveのWordPress用BrookにおけるPHP リモートファイルインクルージョンの脆弱性 CWE-98
PHP リモートファイルインクルージョン
CVE-2025-14430 2026-01-28 12:30 2026-01-8 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 23, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
341 6.1 MEDIUM
Network
- - zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, the proxyUi template engine uses Go's text/template (which performs no HTML escaping) instead of html/… CWE-79
CWE-116
Cross-site Scripting
 Improper Encoding or Escaping of Output
CVE-2026-40302 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
342 4.7 MEDIUM
Network
- - DOMSanitizer is a DOM/SVG/MathML Sanitizer for PHP 7.3+. Prior to version 1.0.10, DOMSanitizer::sanitize() allows <style> elements in SVG content but never inspects their text content. CSS url() refe… CWE-79
Cross-site Scripting
CVE-2026-40301 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
343 - - - next-intl provides internationalization for Next.js. Applications using the `next-intl` middleware prior to version 4.9.1with `localePrefix: 'as-needed'` could construct URLs where path handling and … CWE-601
Open Redirect
CVE-2026-40299 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
344 6.5 MEDIUM
Network
- - OpenFGA is an authorization/permission engine built for developers. In versions 0.1.4 through 1.13.1, when OpenFGA is configured to use preshared-key authentication with the built-in playground enabl… CWE-200
Information Exposure
CVE-2026-40293 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
345 7.5 HIGH
Network
- - WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the 'Member Registration' (Cadastrar Sócio) functi… CWE-79
Cross-site Scripting
CVE-2026-40286 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
346 6.8 MEDIUM
Network
- - WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vulnerability allows an authenticated user to inject malicious JavaScript via the … CWE-79
Cross-site Scripting
CVE-2026-40284 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
347 - - - WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vulnerability allows an authenticated user to inject malicious JavaScript into the… CWE-79
Cross-site Scripting
CVE-2026-40282 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
348 8.1 HIGH
Network
- - HomeBox is a home inventory and organization system. Versions prior to 0.25.0 contain a vulnerability where the defaultGroup ID remained permanently assigned to a user after being invited to a group,… CWE-708
 Incorrect Ownership Assignment
CVE-2026-40196 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
349 5.4 MEDIUM
Network
- - The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. In versions 4.12.0 through 4.17.1, simultaneous requests that trigger a nonce retry may cause the prox… CWE-362
CWE-863
Race Condition
 Incorrect Authorization
CVE-2026-40155 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
350 - - - Claude Code is an agentic coding tool. In versions prior to 2.1.75 on Windows, Claude Code loaded the system-wide default configuration from C:\ProgramData\ClaudeCode\managed-settings.json without va… CWE-426
 Untrusted Search Path
CVE-2026-35603 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm