Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
194511 7.8 重要
Local
Google - メディアサーバにおける権限を昇格される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2017-0387 2017-01-26 15:54 2017-01-3 Show GitHub Exploit DB Packet Storm
194512 5.5 警告
Local
Google - メディアサーバの ih264d デコーダにおける情報を公開される脆弱性 CWE-200
情報漏えい
CVE-2016-6773 2017-01-26 15:52 2016-12-5 Show GitHub Exploit DB Packet Storm
194513 4.3 警告
Network
Google - Google Chrome の Blink における no-referrer ポリシーを回避される脆弱性 CWE-19
データ処理
CVE-2016-9650 2017-01-26 14:43 2016-12-1 Show GitHub Exploit DB Packet Storm
194514 4.3 警告
Network
Google - Google Chrome の Blink における Content Security Policy を回避される脆弱性 CWE-19
データ処理
CVE-2016-5225 2017-01-26 14:43 2016-12-1 Show GitHub Exploit DB Packet Storm
194515 6.5 警告
Network
Google - Google Chrome における Omnibox のコンテンツを偽装される脆弱性 CWE-20
不適切な入力確認
CVE-2016-5222 2017-01-26 14:43 2016-12-1 Show GitHub Exploit DB Packet Storm
194516 6.5 警告
Network
Google - Google Chrome の PDFium におけるローカルファイルを読まれる脆弱性 CWE-200
情報漏えい
CVE-2016-5220 2017-01-26 14:43 2016-12-1 Show GitHub Exploit DB Packet Storm
194517 6.3 警告
Network
Google - Google Chrome の V8 におけるヒープを破損される脆弱性 CWE-416
解放済みメモリの使用
CVE-2016-5219 2017-01-26 14:43 2016-12-1 Show GitHub Exploit DB Packet Storm
194518 6.5 警告
Network
Google - Google Chrome の拡張機能 API における Omnibox のコンテンツを一時的に偽造される脆弱性 CWE-20
不適切な入力確認
CVE-2016-5218 2017-01-26 14:43 2016-12-1 Show GitHub Exploit DB Packet Storm
194519 6.5 警告
Network
Google - Google Chrome の拡張機能 API におけるサイトの隔離を回避される脆弱性 CWE-284
不適切なアクセス制御
CVE-2016-5217 2017-01-26 14:43 2016-12-1 Show GitHub Exploit DB Packet Storm
194520 8.8 重要
Network
Google - Google Chrome の PDFium の TIFF 画像の構文解析におけるヒープバッファオーバーフローの脆弱性 CWE-787
境界外書き込み
CVE-2016-5210 2017-01-26 14:43 2016-12-1 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 20, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
61 6.1 MEDIUM
Network
- - The Hostel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shortcode_id' parameter in all versions up to, and including, 1.1.6 due to insufficient input sanitization and… New CWE-79
Cross-site Scripting
CVE-2026-1838 2026-04-18 11:16 2026-04-18 Show GitHub Exploit DB Packet Storm
62 6.4 MEDIUM
Network
- - The Youzify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'checkin_place_id' parameter in all versions up to, and including, 1.3.6 due to insufficient input sanitization a… New CWE-79
Cross-site Scripting
CVE-2026-1559 2026-04-18 11:16 2026-04-18 Show GitHub Exploit DB Packet Storm
63 9.0 CRITICAL
Local
- - NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. In versions prior to 0.24, Syscall 15 (MemoryMapRange) allows Ring 3 user-mode processes to map arbitrary virtual address … New CWE-269
 Improper Privilege Management
CVE-2026-40572 2026-04-18 10:16 2026-04-18 Show GitHub Exploit DB Packet Storm
64 8.8 HIGH
Network
- - Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can access the user-management endpoints `/settings/users` and use t… New CWE-863
 Incorrect Authorization
CVE-2026-40350 2026-04-18 10:16 2026-04-18 Show GitHub Exploit DB Packet Storm
65 9.3 CRITICAL
Local
- - NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. In versions prior to 0.24, Syscall 12 (JumpToUser) accepts an arbitrary entry point address from user-space registers with… New CWE-20
CWE-269
 Improper Input Validation 
 Improper Privilege Management
CVE-2026-40317 2026-04-18 10:16 2026-04-18 Show GitHub Exploit DB Packet Storm
66 7.5 HIGH
Network
- - SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the SecureDrop Workstation. In versions 0.17.4 and below, a compromised SecureDrop Se… New CWE-36
CWE-73
 Absolute Path Traversal
 External Control of File Name or Path
CVE-2026-35465 2026-04-18 10:16 2026-04-18 Show GitHub Exploit DB Packet Storm
67 4.8 MEDIUM
Network
- - ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the User Editor (UserEditor.php) renders stored usernames directly into an HTML input value attribute without applyin… New CWE-79
CWE-116
Cross-site Scripting
 Improper Encoding or Escaping of Output
CVE-2026-40593 2026-04-18 09:16 2026-04-18 Show GitHub Exploit DB Packet Storm
68 - - - ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the /api/public/user/login endpoint validates only the username and password before returning the user's API key, byp… New CWE-288
CWE-305
Authentication Bypass Using an Alternate Path or Channel
 Authentication Bypass by Primary Weakness
CVE-2026-40582 2026-04-18 09:16 2026-04-18 Show GitHub Exploit DB Packet Storm
69 8.1 HIGH
Network
- - ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the family record deletion endpoint (SelectDelete.php) performs permanent, irreversible deletion of family records an… New CWE-352
CWE-862
 Origin Validation Error
 Missing Authorization
CVE-2026-40581 2026-04-18 09:16 2026-04-18 Show GitHub Exploit DB Packet Storm
70 5.3 MEDIUM
Network
- - ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the public API login endpoint (/api/public/user/login) returns distinguishable HTTP response codes based on whether a… New CWE-204
CWE-307
 Response Discrepancy Information Exposure
mproper Restriction of Excessive Authentication Attempts
CVE-2026-40485 2026-04-18 09:16 2026-04-18 Show GitHub Exploit DB Packet Storm