Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
200001 4.3 警告
Network
F5 Networks - 複数の F5 BIG-IP 製品の Configuration ユーティリティにおけるファイルをアップロードされる脆弱性 CWE-Other
その他
CVE-2015-8021 2016-04-19 11:56 2015-10-28 Show GitHub Exploit DB Packet Storm
200002 8.8 重要
Network
マイクロソフト
アドビシステムズ
Google
- Adobe Flash Player における任意のコードを実行される脆弱性 CWE-Other
その他
CVE-2016-1015 2016-04-19 10:36 2016-04-7 Show GitHub Exploit DB Packet Storm
200003 9.8 緊急
Network
マイクロソフト
アドビシステムズ
Google
- Adobe Flash Player における ASLR 保護メカニズムを回避される脆弱性 CWE-Other
その他
CVE-2016-1006 2016-04-19 10:36 2016-04-7 Show GitHub Exploit DB Packet Storm
200004 5.3 警告
Network
Drupal
Debian
- Drupal の User モジュールの "have you forgotten your password" のリンクにおける重要なユーザ名情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2016-3170 2016-04-18 18:07 2016-02-24 Show GitHub Exploit DB Packet Storm
200005 6.4 警告
Network
Drupal
Debian
- Drupal の System モジュールにおけるサイト管理者の認証をハイジャックされる脆弱性 CWE-Other
その他
CVE-2016-3168 2016-04-18 18:07 2016-02-24 Show GitHub Exploit DB Packet Storm
200006 7.3 重要
Network
Prepopulate project - Drupal 用 Prepopulate モジュールの _prepopulate_request_walk 関数における特定のフィールドの型を変更される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-3188 2016-04-18 17:56 2016-03-2 Show GitHub Exploit DB Packet Storm
200007 7.3 重要
Network
Prepopulate project - Drupal 用 Prepopulate モジュールにおける REQUEST スーパーグローバル変数の配列を変更される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-3187 2016-04-18 17:56 2016-03-2 Show GitHub Exploit DB Packet Storm
200008 7.5 重要
Network
Apache Software Foundation - Apache Jetspeed の User Manager サービスにおけるユーザを追加される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-2171 2016-04-18 17:37 2016-03-28 Show GitHub Exploit DB Packet Storm
200009 9.8 緊急
Network
Apache Software Foundation - Apache OFBiz における任意のコマンドを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2016-2170 2016-04-18 17:37 2016-04-5 Show GitHub Exploit DB Packet Storm
200010 6.5 警告
Network
Apache Software Foundation - Apache Qpid Proton の複数のクラスにおける重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2016-2166 2016-04-18 17:37 2016-03-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 18, 2026, 4:11 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
171 5.0 MEDIUM
Network
- - Weblate is a web based localization tool. In versions prior to 5.17, the ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects. This issue has… New CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-33440 2026-04-18 00:38 2026-04-16 Show GitHub Exploit DB Packet Storm
172 7.4 HIGH
Network
- - OpenProject is an open-source project management application. In versions prior to 17.3.0, 2FA OTP verification in the confirm_otp action of the two_factor_authentication module has no rate limiting,… New CWE-307
mproper Restriction of Excessive Authentication Attempts
CVE-2026-33667 2026-04-18 00:38 2026-04-16 Show GitHub Exploit DB Packet Storm
173 7.7 HIGH
Network
- - Weblate is a web based localization tool. In versions prior to 5.17, the ZIP download feature didn't verify downloaded files, potentially following symlinks outside the repository. This issue has be… New CWE-22
CWE-59
CWE-200
Path Traversal
Link Following
Information Exposure
CVE-2026-34242 2026-04-18 00:38 2026-04-16 Show GitHub Exploit DB Packet Storm
174 8.8 HIGH
Network
- - Weblate is a web based localization tool. In versions prior to 5.17, the user patching API endpoint didn't properly limit the scope of edits. This issue has been fixed in version 5.17. New CWE-269
 Improper Privilege Management
CVE-2026-34393 2026-04-18 00:38 2026-04-16 Show GitHub Exploit DB Packet Storm
175 4.1 MEDIUM
Network
- - Weblate is a web based localization tool. In versions prior to 5.17, the webhook add-on did not utilize existing SSRF protections. This issue has been fixed in version 5.17. If developers are unable … New CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-39845 2026-04-18 00:38 2026-04-16 Show GitHub Exploit DB Packet Storm
176 5.0 MEDIUM
Network
- - Weblate is a web based localization tool. In versions prior to 5.17, repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses s… New CWE-22
Path Traversal
CVE-2026-40256 2026-04-18 00:38 2026-04-16 Show GitHub Exploit DB Packet Storm
177 5.0 MEDIUM
Network
- - Weblate is a web based localization tool. In versions prior to 5.17, a user with the project.edit permission (granted by the per-project "Administration" role) can configure machine translation servi… New CWE-200
CWE-918
Information Exposure
Server-Side Request Forgery (SSRF) 
CVE-2026-34244 2026-04-18 00:38 2026-04-16 Show GitHub Exploit DB Packet Storm
178 7.8 HIGH
Local
- - Barracuda RMM versions prior to 2025.2.2 contain a privilege escalation vulnerability that allows local attackers to gain SYSTEM-level privileges by exploiting overly permissive filesystem ACLs on th… New CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2026-22676 2026-04-18 00:38 2026-04-16 Show GitHub Exploit DB Packet Storm
179 - - - Pega Platform versions 8.1.0 through 25.1.1 are affected by an HTML Injection vulnerability in a user interface component. Requires a high privileged user with a developer role. New CWE-80
Basic XSS
CVE-2026-1564 2026-04-18 00:38 2026-04-16 Show GitHub Exploit DB Packet Storm
180 - - - Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-Site Scripting vulnerability in a user interface component. Requires a high privileged user with a developer role. New CWE-79
Cross-site Scripting
CVE-2026-1711 2026-04-18 00:38 2026-04-16 Show GitHub Exploit DB Packet Storm