Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1521 5.5 警告
Local
Debian
Linux
Debian GNU/Linux
Linux Kernel
Debian等の複数ベンダの製品における到達可能なアサーションに関する脆弱性 CWE-617
到達可能なアサーション
CVE-2025-38503 2026-01-27 17:36 2025-08-16 Show GitHub Exploit DB Packet Storm
1522 5.5 警告
Local
Debian
Linux
Debian GNU/Linux
Linux Kernel
Debian等の複数ベンダの製品における不特定の脆弱性 CWE-noinfo
情報不足
CVE-2025-38514 2026-01-27 17:36 2025-08-16 Show GitHub Exploit DB Packet Storm
1523 7.1 重要
Local
Linux Linux Kernel LinuxのLinux Kernelにおける誤った領域へのリソースの漏えいに関する脆弱性 CWE-668
誤った領域へのリソースの漏えい
CVE-2025-38521 2026-01-27 17:36 2025-08-16 Show GitHub Exploit DB Packet Storm
1524 5.5 警告
Local
Debian
Linux
Debian GNU/Linux
Linux Kernel
Debian等の複数ベンダの製品における不特定の脆弱性 CWE-noinfo
情報不足
CVE-2025-38540 2026-01-27 17:36 2025-08-16 Show GitHub Exploit DB Packet Storm
1525 5.5 警告
Local
Debian
Linux
Debian GNU/Linux
Linux Kernel
Debian等の複数ベンダの製品における不特定の脆弱性 CWE-noinfo
情報不足
CVE-2025-38560 2026-01-27 17:36 2025-08-19 Show GitHub Exploit DB Packet Storm
1526 7.1 重要
Local
Debian
Linux
Debian GNU/Linux
Linux Kernel
Debian等の複数ベンダの製品における誤った領域へのリソースの漏えいに関する脆弱性 CWE-668
誤った領域へのリソースの漏えい
CVE-2025-38670 2026-01-27 17:36 2025-08-22 Show GitHub Exploit DB Packet Storm
1527 5.5 警告
Local
Debian
Linux
Debian GNU/Linux
Linux Kernel
Debian等の複数ベンダの製品におけるNULL ポインタデリファレンスに関する脆弱性 CWE-476
NULL ポインタデリファレンス
CVE-2025-38694 2026-01-27 17:36 2025-09-4 Show GitHub Exploit DB Packet Storm
1528 4.3 警告
Network
ThemeGoods Grand Restaurant WordPress ThemeGoodsのWordPress用Grand Restaurant WordPressにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2025-39351 2026-01-27 17:35 2025-05-19 Show GitHub Exploit DB Packet Storm
1529 8.2 重要
Network
ThemeGoods Grand Restaurant WordPress ThemeGoodsのWordPress用Grand Restaurant WordPressにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2025-39352 2026-01-27 17:35 2025-05-19 Show GitHub Exploit DB Packet Storm
1530 5.3 警告
Network
ThemeGoods Grand Restaurant WordPress ThemeGoodsのWordPress用Grand Restaurant WordPressにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2025-39353 2026-01-27 17:35 2025-05-19 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 22, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
283381 - google toolbar The Custom Button Installer dialog in Google Toolbar 4 and 5 beta presents certain domain names in the (1) "Downloaded from" and (2) "Privacy considerations" sections without verifying domain names, … CWE-200
Information Exposure
CVE-2007-6536 2018-10-16 06:55 2007-12-28 Show GitHub Exploit DB Packet Storm
283382 - winuae winuae Stack-based buffer overflow in the zfile_gunzip function in zfile.c in WinUAE 1.4.4 and earlier allows user-assisted remote attackers to execute arbitrary code via a long filename in a gzipped archiv… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2007-6537 2018-10-16 06:55 2007-12-28 Show GitHub Exploit DB Packet Storm
283383 - mrbs mrbs SQL injection vulnerability in ing/blocks/mrbs/code/web/view_entry.php in the MRBS plugin for Moodle allows remote attackers to execute arbitrary SQL commands via the id parameter. CWE-89
SQL Injection
CVE-2007-6538 2018-10-16 06:55 2007-12-28 Show GitHub Exploit DB Packet Storm
283384 - idevspot isupport PHP local file inclusion vulnerability in index.php in IDevspot iSupport 1.8 allows remote attackers to include local files via the include_file parameter. CWE-94
Code Injection
CVE-2007-6539 2018-10-16 06:55 2007-12-28 Show GitHub Exploit DB Packet Storm
283385 - neuron news SQL injection vulnerability in neuron news 1.0 allows remote attackers to execute arbitrary SQL commands via the q parameter to the default URI in patch/. CWE-89
SQL Injection
CVE-2007-6540 2018-10-16 06:55 2007-12-28 Show GitHub Exploit DB Packet Storm
283386 - neuron_news neuron_news Multiple cross-site scripting (XSS) vulnerabilities in neuron news 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the topic parameter in a viewtopic action, or the (2) news… CWE-79
Cross-site Scripting
CVE-2007-6541 2018-10-16 06:55 2007-12-28 Show GitHub Exploit DB Packet Storm
283387 - runcms runcms Multiple SQL injection vulnerabilities in RunCMS before 1.6.1 allow remote attackers to execute arbitrary SQL commands via the lid parameter to (1) brokenfile.php, (2) visit.php, or (3) ratefile.php … CWE-89
SQL Injection
CVE-2007-6544 2018-10-16 06:55 2007-12-28 Show GitHub Exploit DB Packet Storm
283388 - runcms runcms Multiple cross-site scripting (XSS) vulnerabilities in RunCMS before 1.6.1 allow remote attackers to inject arbitrary web script or HTML via (1) the subject parameter to modules/news/submit.php; (2) … CWE-79
Cross-site Scripting
CVE-2007-6545 2018-10-16 06:55 2007-12-28 Show GitHub Exploit DB Packet Storm
283389 - runcms runcms RunCMS before 1.6.1 uses a predictable session id, which makes it easier for remote attackers to hijack sessions via a modified id. NVD-CWE-Other
CVE-2007-6546 2018-10-16 06:55 2007-12-28 Show GitHub Exploit DB Packet Storm
283390 - runcms runcms RunCMS before 1.6.1 does not require entry of the old password during a password change, which allows context-dependent attackers to change passwords upon obtaining temporary access to a session. NVD-CWE-Other
CVE-2007-6547 2018-10-16 06:55 2007-12-28 Show GitHub Exploit DB Packet Storm