Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 4, 2026, 2 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
198261 4.3 警告
Network
Yandex - デスクトップ用 Yandex Browser の同期フォームにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2016-8504 2016-11-1 15:50 2016-10-26 Show GitHub Exploit DB Packet Storm
198262 7.3 重要
Network
Yandex - デスクトップ用 Yandex Browser の Yandex Protect のアンチフィッシング警告におけるパスワードを取得される脆弱性 CWE-Other
その他
CVE-2016-8503 2016-11-1 15:50 2016-10-26 Show GitHub Exploit DB Packet Storm
198263 7.3 重要
Network
Yandex - デスクトップ用 Yandex Browser の Yandex Protect のアンチフィッシング警告におけるパスワードを取得される脆弱性 CWE-Other
その他
CVE-2016-8502 2016-11-1 15:50 2016-10-26 Show GitHub Exploit DB Packet Storm
198264 5.3 警告
Network
Yandex - Yandex Browser における WiFi のセキュリティを回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-8501 2016-11-1 15:50 2016-10-26 Show GitHub Exploit DB Packet Storm
198265 5.4 警告
Network
Novell - Novell NetIQ IDM の Identity Applications におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-1598 2016-10-31 18:04 2016-06-23 Show GitHub Exploit DB Packet Storm
198266 6.1 警告
Network
Novell - Novell Identity Manager の NetIQ Designer におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-1592 2016-10-31 18:04 2016-01-24 Show GitHub Exploit DB Packet Storm
198267 6.1 警告
Network
Novell - Novell Identity Manager の NetIQ Designer におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2015-0787 2016-10-31 18:04 2015-01-7 Show GitHub Exploit DB Packet Storm
198268 8.8 重要
Network
マイクロフォーカス株式会社 - Micro Focus Rumba FTP クライアントにおけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2016-5764 2016-10-31 17:46 2016-10-19 Show GitHub Exploit DB Packet Storm
198269 7.5 重要
Network
fedorahosted.org - TGCaptcha2 における反射攻撃を実行される脆弱性 CWE-Other
その他
CVE-2016-1000032 2016-10-31 17:32 2016-03-9 Show GitHub Exploit DB Packet Storm
198270 7.2 重要
Network
Huge-IT - Joomla! 用 Huge-IT Slider におけるクロスサイトスクリプティングの脆弱性 CWE-89
SQLインジェクション
CVE-2016-1000122 2016-10-31 17:09 2016-07-22 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 4, 2026, 4:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
121 7.5 HIGH
Network
- - The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'map_post_type' parameter in all versions up to, and including, 1.13.18. This is due to the `SearchResults` hook … New CWE-89
SQL Injection
CVE-2026-4061 2026-05-2 21:16 2026-05-2 Show GitHub Exploit DB Packet Storm
122 7.5 HIGH
Network
- - The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'sort' parameter in all versions up to, and including, 1.13.18. This is due to insufficient escaping on the user … New CWE-89
SQL Injection
CVE-2026-4060 2026-05-2 21:16 2026-05-2 Show GitHub Exploit DB Packet Storm
123 6.3 MEDIUM
Network
- - A security vulnerability has been detected in 8nite metatrader-4-mcp 1.0.0. This vulnerability affects the function CallToolRequestSchema of the file src/index.ts of the component sync_ea_from_file. … New CWE-22
Path Traversal
CVE-2026-7627 2026-05-2 20:15 2026-05-2 Show GitHub Exploit DB Packet Storm
124 4.7 MEDIUM
Network
- - A vulnerability was determined in itsourcecode Courier Management System 1.0. Affected is an unknown function of the file /edit_user.php. Executing a manipulation of the argument ID can lead to sql i… New CWE-74
CWE-89
Injection
SQL Injection
CVE-2026-7612 2026-05-2 19:16 2026-05-2 Show GitHub Exploit DB Packet Storm
125 3.7 LOW
Network
- - A vulnerability was found in TRENDnet TEW-821DAP up to 1.12B01. This impacts the function platform_do_upgrade_cameo_dev of the file cameo_dev.sh of the component Firmware Update Handler. Performing a… New CWE-345
 Insufficient Verification of Data Authenticity
CVE-2026-7611 2026-05-2 19:16 2026-05-2 Show GitHub Exploit DB Packet Storm
126 3.7 LOW
Network
- - A vulnerability has been found in TRENDnet TEW-821DAP 1.12B01. This affects an unknown function of the file /www/cgi/ssi of the component Firmware Update. Such manipulation leads to cleartext transmi… New CWE-310
CWE-319
Cryptographic Issues
Cleartext Transmission of Sensitive Information
CVE-2026-7610 2026-05-2 19:16 2026-05-2 Show GitHub Exploit DB Packet Storm
127 6.3 MEDIUM
Network
- - A flaw has been found in TRENDnet TEW-821DAP up to 1.12B01. The impacted element is the function tools_diagnostic of the file /tmp/diagnostic of the component Firmware Udpate. This manipulation cause… New CWE-77
CWE-78
Command Injection
OS Command 
CVE-2026-7609 2026-05-2 19:16 2026-05-2 Show GitHub Exploit DB Packet Storm
128 8.1 HIGH
Network
- - School App developed by Zyosoft has an Insecure Direct Object Reference vulnerability, allowing authenticated remote attackers to modify a specific parameter to read and modify other users' data. New CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-7491 2026-05-2 19:16 2026-05-2 Show GitHub Exploit DB Packet Storm
129 7.2 HIGH
Network
- - CTMS and CPAS developed by Sunnet has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution… New CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2026-7490 2026-05-2 19:16 2026-05-2 Show GitHub Exploit DB Packet Storm
130 8.8 HIGH
Network
- - CTMS developed by Sunnet has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents. New CWE-89
SQL Injection
CVE-2026-7489 2026-05-2 19:16 2026-05-2 Show GitHub Exploit DB Packet Storm