Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
200061 9.8 緊急
Network
アドビシステムズ
Google
- Adobe Flash Player における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2016-1022 2016-04-15 18:16 2016-04-7 Show GitHub Exploit DB Packet Storm
200062 5.7 警告
Network
Canonical
JasPer Project
- JasPer の jas_iccprof_createfrombuf 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2016-2116 2016-04-15 18:06 2016-03-3 Show GitHub Exploit DB Packet Storm
200063 7.6 重要
Network
Canonical
JasPer Project
- JasPer の jas_iccattrval_destroy 関数におけるメモリ二重解放の脆弱性 CWE-Other
その他
CVE-2016-1577 2016-04-15 18:06 2016-03-3 Show GitHub Exploit DB Packet Storm
200064 6.1 警告
Network
シスコシステムズ - Cisco Unity Connection におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-1377 2016-04-15 16:07 2016-04-12 Show GitHub Exploit DB Packet Storm
200065 6.1 警告
Network
シスコシステムズ - Cisco IP Interoperability and Collaboration System におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-1375 2016-04-15 16:07 2016-04-7 Show GitHub Exploit DB Packet Storm
200066 5.3 警告
Network
Lenovo - 複数の LenovoEMC 製品の管理インターフェースにおける重要なデバイス情報を取得される脆弱性 CWE-Other
その他
CVE-2015-8108 2016-04-15 14:58 2015-11-11 Show GitHub Exploit DB Packet Storm
200067 7.8 重要
Local
Lenovo - Lenovo Fingerprint Manager および Touch Fingerprint における権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-2393 2016-04-15 14:58 2016-03-22 Show GitHub Exploit DB Packet Storm
200068 9.1 緊急
Network
PostgreSQL.org - PostgreSQL の pageinspect エクステンションの brin_page_type および brin_metapage_info 機能におけるアクセス制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-3065 2016-04-15 14:32 2016-03-31 Show GitHub Exploit DB Packet Storm
200069 7.5 重要
Network
PostgreSQL.org - PostgreSQL におけるアクセス制限を回避される脆弱性 CWE-Other
その他
CVE-2016-2193 2016-04-15 14:31 2016-03-31 Show GitHub Exploit DB Packet Storm
200070 9.8 緊急
Network
アドビシステムズ
Google
- Adobe Flash Player におけるアクセス制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2016-1030 2016-04-15 14:27 2016-04-7 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 19, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
521 - - - Improper neutralization of argument delimiters in a command ('argument injection') vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Hijacking a Privileged Thread of Execut… Update CWE-88
Argument Injection
CVE-2026-2449 2026-04-18 00:24 2026-04-14 Show GitHub Exploit DB Packet Storm
522 - - - .NET misconfiguration: use of impersonation vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Hijacking a Privileged Thread of Execution.This issue affects upKeeper Instant… Update CWE-520
 .NET Misconfiguration: Use of Impersonation
CVE-2026-2450 2026-04-18 00:24 2026-04-14 Show GitHub Exploit DB Packet Storm
523 - - - A vulnerability in the AdminServer component of OpenEdge on all supported platforms grants its authenticated users OS-level access to the server through the adopted authority of the AdminServer proce… Update CWE-552
 Files or Directories Accessible to External Parties
CVE-2025-7389 2026-04-18 00:24 2026-04-14 Show GitHub Exploit DB Packet Storm
524 - - - The OECH1 prefix encoding is intended to obfuscate values across the OpenEdge platform.  It has been identified as cryptographically weak and unsuitable for stored encodings and enterprise applicatio… Update CWE-257
 Storing Passwords in a Recoverable Format
CVE-2025-8095 2026-04-18 00:24 2026-04-14 Show GitHub Exploit DB Packet Storm
525 9.8 CRITICAL
Network
- - An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to execute arbitrary code and escalate privileges via the CSV registration field Update CWE-1236
 Improper Neutralization of Formula Elements in a CSV File
CVE-2026-31049 2026-04-18 00:24 2026-04-14 Show GitHub Exploit DB Packet Storm
526 9.8 CRITICAL
Network
- - A vulnerability was identified in OpenAI Codex CLI v0.23.0 and before that enables code execution through malicious MCP (Model Context Protocol) configuration files. The attack is triggered when a us… Update CWE-94
Code Injection
CVE-2025-61260 2026-04-18 00:24 2026-04-15 Show GitHub Exploit DB Packet Storm
527 6.1 MEDIUM
Network
- - Leaflet versions up to and including 1.9.4 are vulnerable to Cross-Site Scripting (XSS) via the bindPopup() method. This method renders user-supplied input as raw HTML without sanitization, allowing … Update CWE-79
Cross-site Scripting
CVE-2025-69993 2026-04-18 00:24 2026-04-15 Show GitHub Exploit DB Packet Storm
528 6.5 MEDIUM
Network
- - A Local File Inclusion (LFI) vulnerability in the NFSen module (nfsen.inc.php) of LibreNMS 22.11.0-23-gd091788f2 allows authenticated attackers to include arbitrary PHP files from the server filesyst… Update CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2026-30480 2026-04-18 00:24 2026-04-15 Show GitHub Exploit DB Packet Storm
529 4.6 MEDIUM
Physics
- - A side-channel vulnerability exists in the implementation of BIP-39 mnemonic processing, as observed in Trezor One v1.13.0 to v1.14.0, Trezor T v1.13.0 to v1.14.0, and Trezor Safe v1.13.0 to v1.14.0 … Update CWE-385
 Covert Timing Channel
CVE-2025-69893 2026-04-18 00:24 2026-04-15 Show GitHub Exploit DB Packet Storm
530 6.8 MEDIUM
Network
- - Rate Limiting for attempting a user login is not being properly enforced, making HCL DevOps Velocity susceptible to brute-force attacks past the unsuccessful login attempt limit.  This vulnerability … Update CWE-307
mproper Restriction of Excessive Authentication Attempts
CVE-2025-31991 2026-04-18 00:18 2026-04-14 Show GitHub Exploit DB Packet Storm