Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
200721 3.5 注意 The phpMyAdmin Project - phpMyAdmin の js/normalization.js の goToFinish1NF 関数におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-2043 2016-02-25 14:52 2016-01-24 Show GitHub Exploit DB Packet Storm
200722 5 警告 The phpMyAdmin Project - phpMyAdmin における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2016-2042 2016-02-25 14:52 2016-01-24 Show GitHub Exploit DB Packet Storm
200723 5 警告 The phpMyAdmin Project - phpMyAdmin の libraries/common.inc.php におけるアクセス制限を回避される脆弱性 CWE-Other
その他
CVE-2016-2041 2016-02-25 14:52 2016-01-24 Show GitHub Exploit DB Packet Storm
200724 3.5 注意 The phpMyAdmin Project - phpMyAdmin におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-2040 2016-02-25 14:52 2016-01-24 Show GitHub Exploit DB Packet Storm
200725 5 警告 The phpMyAdmin Project - phpMyAdmin の libraries/session.inc.php におけるアクセス制限を回避される脆弱性 CWE-200
情報漏えい
CVE-2016-2039 2016-02-25 14:52 2016-01-24 Show GitHub Exploit DB Packet Storm
200726 5 警告 The phpMyAdmin Project - phpMyAdmin における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2016-2038 2016-02-25 14:52 2016-01-23 Show GitHub Exploit DB Packet Storm
200727 4.3 警告 IBM - IBM Security Access Manager for Web および Security Access Manager におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2015-8531 2016-02-25 13:43 2015-12-8 Show GitHub Exploit DB Packet Storm
200728 7.6 危険 オラクル - Oracle Java SE における Install に関する脆弱性 CWE-noinfo
情報不足
CVE-2016-0603 2016-02-25 12:27 2016-02-5 Show GitHub Exploit DB Packet Storm
200729 4.3 警告 OpenJPEG project - OpenJPEG の opj_tgt_reset 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2016-1924 2016-02-25 11:27 2016-01-18 Show GitHub Exploit DB Packet Storm
200730 5 警告 The Go Project - Go の math/big ライブラリ内の Int.Exp Montgomery コードにおける RSA 秘密鍵を取得される脆弱性 CWE-200
情報漏えい
CVE-2015-8618 2016-02-25 11:22 2015-12-7 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 20, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
541 9.8 CRITICAL
Network
- - A vulnerability was identified in OpenAI Codex CLI v0.23.0 and before that enables code execution through malicious MCP (Model Context Protocol) configuration files. The attack is triggered when a us… Update CWE-94
Code Injection
CVE-2025-61260 2026-04-18 00:24 2026-04-15 Show GitHub Exploit DB Packet Storm
542 6.1 MEDIUM
Network
- - Leaflet versions up to and including 1.9.4 are vulnerable to Cross-Site Scripting (XSS) via the bindPopup() method. This method renders user-supplied input as raw HTML without sanitization, allowing … Update CWE-79
Cross-site Scripting
CVE-2025-69993 2026-04-18 00:24 2026-04-15 Show GitHub Exploit DB Packet Storm
543 6.5 MEDIUM
Network
- - A Local File Inclusion (LFI) vulnerability in the NFSen module (nfsen.inc.php) of LibreNMS 22.11.0-23-gd091788f2 allows authenticated attackers to include arbitrary PHP files from the server filesyst… Update CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2026-30480 2026-04-18 00:24 2026-04-15 Show GitHub Exploit DB Packet Storm
544 4.6 MEDIUM
Physics
- - A side-channel vulnerability exists in the implementation of BIP-39 mnemonic processing, as observed in Trezor One v1.13.0 to v1.14.0, Trezor T v1.13.0 to v1.14.0, and Trezor Safe v1.13.0 to v1.14.0 … Update CWE-385
 Covert Timing Channel
CVE-2025-69893 2026-04-18 00:24 2026-04-15 Show GitHub Exploit DB Packet Storm
545 6.8 MEDIUM
Network
- - Rate Limiting for attempting a user login is not being properly enforced, making HCL DevOps Velocity susceptible to brute-force attacks past the unsuccessful login attempt limit.  This vulnerability … Update CWE-307
mproper Restriction of Excessive Authentication Attempts
CVE-2025-31991 2026-04-18 00:18 2026-04-14 Show GitHub Exploit DB Packet Storm
546 4.3 MEDIUM
Network
- - The bson_validate function may return early on specific inputs and incorrectly report success. This behavior could result in skipping validation for BSON data, allowing malformed or invalid UTF-8 seq… Update CWE-20
 Improper Input Validation 
CVE-2026-6231 2026-04-18 00:18 2026-04-14 Show GitHub Exploit DB Packet Storm
547 6.5 MEDIUM
Adjacent
- - A vulnerability exists in the command handling of the IEC 61850 communication stack included in the product revisions listed as affected in this CVE. An attacker with access to IEC 61850 networks cou… Update CWE-1284
 Improper Validation of Specified Quantity in Input
CVE-2025-3756 2026-04-18 00:18 2026-04-14 Show GitHub Exploit DB Packet Storm
548 - - - Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory allocation fails with a `MemoryError` and the decompression instance is re-u… Update CWE-416
CWE-787
 Use After Free
 Out-of-bounds Write
CVE-2026-6100 2026-04-18 00:18 2026-04-14 Show GitHub Exploit DB Packet Storm
549 - - - Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the … Update CWE-77
Command Injection
CVE-2026-4786 2026-04-18 00:18 2026-04-14 Show GitHub Exploit DB Packet Storm
550 7.5 HIGH
Network
- - Crypt::SecretBuffer versions before 0.019 for Perl is suseceptible to timing attacks. For example, if Crypt::SecretBuffer was used to store and compare plaintext passwords, then discrepencies in tim… Update CWE-208
 Information Exposure Through Timing Discrepancy
CVE-2026-5086 2026-04-18 00:18 2026-04-14 Show GitHub Exploit DB Packet Storm