Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1511 7.2 重要
Network
BiggiDroid Simple PHP CMS BiggiDroidのSimple PHP CMSにおける複数の脆弱性 CWE-284
CWE-434
CWE-434
CVE-2025-15495 2026-01-27 17:36 2026-01-9 Show GitHub Exploit DB Packet Storm
1512 9.8 緊急
Network
guchengwuyue yshopmall guchengwuyueのyshopmallにおける複数の脆弱性 CWE-74
CWE-89
CWE-89
CVE-2025-15496 2026-01-27 17:36 2026-01-9 Show GitHub Exploit DB Packet Storm
1513 9.8 緊急
Network
Sangfor Technologies OSM Sangfor TechnologiesのOSMにおける複数の脆弱性 CWE-77
CWE-78
CWE-78
CVE-2025-15501 2026-01-27 17:36 2026-01-9 Show GitHub Exploit DB Packet Storm
1514 9.8 緊急
Network
Sangfor Technologies OSM Sangfor TechnologiesのOSMにおける複数の脆弱性 CWE-77
CWE-78
CWE-78
CVE-2025-15502 2026-01-27 17:36 2026-01-10 Show GitHub Exploit DB Packet Storm
1515 9.8 緊急
Network
Sangfor Technologies OSM Sangfor TechnologiesのOSMにおける複数の脆弱性 CWE-284
CWE-434
CWE-434
CVE-2025-15503 2026-01-27 17:36 2026-01-10 Show GitHub Exploit DB Packet Storm
1516 5.5 警告
Local
lief project lief lief projectのliefにおける複数の脆弱性 CWE-404
CWE-476
CWE-476
CVE-2025-15504 2026-01-27 17:36 2026-01-10 Show GitHub Exploit DB Packet Storm
1517 7.8 重要
Local
サムスン android サムスンのAndroidにおける不特定の脆弱性 CWE-noinfo
情報不足
CVE-2025-20936 2026-01-27 17:36 2025-04-8 Show GitHub Exploit DB Packet Storm
1518 7.1 重要
Local
Debian
Linux
Debian GNU/Linux
Linux Kernel
Debian等の複数ベンダの製品における不特定の脆弱性 CWE-noinfo
情報不足
CVE-2025-21950 2026-01-27 17:36 2025-04-1 Show GitHub Exploit DB Packet Storm
1519 7.1 重要
Local
Linux Linux Kernel LinuxのLinux Kernelにおける不特定の脆弱性 CWE-noinfo
情報不足
CVE-2025-21973 2026-01-27 17:36 2025-04-1 Show GitHub Exploit DB Packet Storm
1520 7.1 重要
Network
デル Dell Unisphere for PowerMax
Dell Unisphere for PowerMax Virtual Appliance
デルのDell Unisphere for PowerMax等の複数製品におけるXML 外部エンティティの脆弱性 CWE-611
XML 外部エンティティ参照の不適切な制限
CVE-2025-36589 2026-01-27 17:36 2026-01-6 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 26, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
282711 - simpliciti locked_browser Simpliciti Locked Browser does not properly limit a user's actions to ones within the intended Internet Explorer environment, which allows local users to perform unauthorized actions by visiting a we… NVD-CWE-Other
CVE-2006-4092 2018-10-18 06:33 2006-08-11 Show GitHub Exploit DB Packet Storm
282712 - isc bind BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via a flood of recursive queries, which cause an INSIST failure when the response is receiv… NVD-CWE-Other
CVE-2006-4096 2018-10-18 06:33 2006-09-6 Show GitHub Exploit DB Packet Storm
282713 - jason_alexander phnntp PHP remote file inclusion vulnerability in article-raw.php in Jason Alexander phNNTP 1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the file_newsportal parameter. NVD-CWE-Other
CVE-2006-4103 2018-10-18 06:33 2006-08-15 Show GitHub Exploit DB Packet Storm
282714 - fill_threads_database fill_threads_database Cross-site scripting (XSS) vulnerability in Fill Threads Database (FTD) 3.7.3 allows remote attackers to inject arbitrary web script or HTML via the (1) search field or (2) an e-mail message. NVD-CWE-Other
CVE-2006-4105 2018-10-18 06:33 2006-08-15 Show GitHub Exploit DB Packet Storm
282715 - blursoft blur6ex Cross-site scripting (XSS) vulnerability in blursoft blur6ex 0.3 allows remote attackers to inject arbitrary web script or HTML via a comment title. NVD-CWE-Other
CVE-2006-4106 2018-10-18 06:33 2006-08-15 Show GitHub Exploit DB Packet Storm
282716 - apache http_server Apache 2.2.2, when running on Windows, allows remote attackers to read source code of CGI programs via a request that contains uppercase (or alternate case) characters that bypass the case-sensitive … NVD-CWE-Other
CVE-2006-4110 2018-10-18 06:33 2006-08-15 Show GitHub Exploit DB Packet Storm
282717 - phpmyring phpmyring SQL injection vulnerability in view_com.php in Nicolas Grandjean PHPMyRing 4.2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the idsite parameter. NVD-CWE-Other
CVE-2006-4114 2018-10-18 06:33 2006-08-15 Show GitHub Exploit DB Packet Storm
282718 - e-zest_solutions pgmarket PHP remote file inclusion vulnerability in common.inc.php in PgMarket 2.2.3, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the CFG[libdir] parameter. NVD-CWE-Other
CVE-2006-4115 2018-10-18 06:33 2006-08-15 Show GitHub Exploit DB Packet Storm
282719 - e-zest_solutions pgmarket Successful exploitation requires that "register_globals" is enabled. NVD-CWE-Other
CVE-2006-4115 2018-10-18 06:33 2006-08-15 Show GitHub Exploit DB Packet Storm
282720 - lhaz lhaz Multiple stack-based buffer overflows in Lhaz before 1.32 allow user-assisted attackers to execute arbitrary code via a long filename in (1) an LHZ archive, when saving the filename during extraction… NVD-CWE-Other
CVE-2006-4116 2018-10-18 06:33 2006-08-15 Show GitHub Exploit DB Packet Storm