Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2031 2.3
Local
デル secure connect gateway デルのsecure connect gatewayにおけるSQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2024-51539 2026-01-23 14:20 2025-02-25 Show GitHub Exploit DB Packet Storm
2032 7.5 重要
Network
LlamaIndex LlamaIndex LlamaIndexにおける制限またはスロットリング無しのリソースの割り当てに関する脆弱性 CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2024-58339 2026-01-23 14:20 2026-01-12 Show GitHub Exploit DB Packet Storm
2033 7.5 重要
Network
langchain langchain langchainにおける非効率的な正規表現の複雑さに関する脆弱性 CWE-1333
非効率的な正規表現の複雑さ
CVE-2024-58340 2026-01-23 14:20 2026-01-12 Show GitHub Exploit DB Packet Storm
2034 5.4 警告
Network
GitLab.org GitLab GitLab.orgのGitLabにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2025-11224 2026-01-23 14:20 2026-01-14 Show GitHub Exploit DB Packet Storm
2035 8.8 重要
Network
ヒューレット・パッカード
ヒューレット・パッカード・エンタープライズ
OMEN Gaming Hub
HP System Event Utility
ヒューレット・パッカードのOMEN Gaming Hub等の複数製品におけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2025-11531 2026-01-23 14:20 2025-12-9 Show GitHub Exploit DB Packet Storm
2036 6.5 警告
Network
rymcu forest rymcuのforestにおける複数の脆弱性 CWE-862
CWE-862
CWE-863
CVE-2025-12924 2026-01-23 14:20 2025-11-10 Show GitHub Exploit DB Packet Storm
2037 9.8 緊急
Network
rymcu forest rymcuのforestにおける複数の脆弱性 CWE-862
CWE-862
CWE-863
CVE-2025-12925 2026-01-23 14:20 2025-11-10 Show GitHub Exploit DB Packet Storm
2038 7.8 重要
Local
SUPERAntiSpyware SUPERAntiSpyware SUPERAntiSpywareにおける危険なメソッドや機能の公開に関する脆弱性 CWE-749
危険なメソッドや機能の公開
CVE-2025-14491 2026-01-23 14:20 2025-12-23 Show GitHub Exploit DB Packet Storm
2039 7.8 重要
Local
huggingface transformers huggingfaceのtransformersにおける信頼できないデータのデシリアライゼーションに関する脆弱性 CWE-502
信頼性のないデータのデシリアライゼーション
CVE-2025-14920 2026-01-23 14:20 2025-12-23 Show GitHub Exploit DB Packet Storm
2040 7.8 重要
Local
huggingface transformers huggingfaceのtransformersにおける信頼できないデータのデシリアライゼーションに関する脆弱性 CWE-502
信頼性のないデータのデシリアライゼーション
CVE-2025-14921 2026-01-23 14:19 2025-12-23 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 26, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
283411 - bibtex mase Multiple PHP remote file inclusion vulnerabilities in bibtex mase beta 2.0 allow remote attackers to execute arbitrary PHP code via a URL in the bibtexrootrel parameter to (1) unavailable.php, (2) so… CWE-94
Code Injection
CVE-2007-2260 2018-10-17 01:42 2007-04-26 Show GitHub Exploit DB Packet Storm
283412 - realink c-arbre PHP remote file inclusion vulnerability in espaces/communiques/annotations.php in C-Arbre 0.6PR7 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter… NVD-CWE-Other
CVE-2007-2261 2018-10-17 01:42 2007-04-26 Show GitHub Exploit DB Packet Storm
283413 - sinato jmuffin Multiple PHP remote file inclusion vulnerabilities in html/php/detail.php in Sinato jmuffin allow remote attackers to execute arbitrary PHP code via a URL in the (1) relPath and (2) folder parameters… CWE-94
Code Injection
CVE-2007-2262 2018-10-17 01:42 2007-04-26 Show GitHub Exploit DB Packet Storm
283414 - realnetworks realone_player
realplayer
realplayer_enterprise
Heap-based buffer overflow in RealNetworks RealPlayer 10.0, 10.1, and possibly 10.5, RealOne Player, and RealPlayer Enterprise allows remote attackers to execute arbitrary code via an SWF (Flash) fil… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2007-2263 2018-10-17 01:42 2007-11-1 Show GitHub Exploit DB Packet Storm
283415 - realnetworks realone_player
realplayer
realplayer_enterprise
Heap-based buffer overflow in RealNetworks RealPlayer 8, 10, 10.1, and possibly 10.5; RealOne Player 1 and 2; and RealPlayer Enterprise allows remote attackers to execute arbitrary code via a RAM (.r… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2007-2264 2018-10-17 01:42 2007-11-1 Show GitHub Exploit DB Packet Storm
283416 - phpee ya_book Cross-site scripting (XSS) vulnerability in YA Book 0.98-alpha allows remote attackers to inject arbitrary web script or HTML via the City field in a sign action in index.php. NVD-CWE-Other
CVE-2007-2265 2018-10-17 01:42 2007-04-26 Show GitHub Exploit DB Packet Storm
283417 - progress webspeed_messenger Progress Webspeed Messenger allows remote attackers to read, create, modify, and execute arbitrary files by invoking webutil/_cpyfile.p in the WService parameter to (1) cgiip.exe or (2) wsisa.dll in … NVD-CWE-Other
CVE-2007-2266 2018-10-17 01:42 2007-04-26 Show GitHub Exploit DB Packet Storm
283418 - plogger plogger Session fixation vulnerability in Plogger allows remote attackers to hijack web sessions by setting the PHPSESSID parameter. CWE-287
Improper Authentication
CVE-2007-2277 2018-10-17 01:42 2007-04-26 Show GitHub Exploit DB Packet Storm
283419 - dcp-portal dcp-portal Multiple PHP remote file inclusion vulnerabilities in DCP-Portal 6.1.1 allow remote attackers to execute arbitrary PHP code via a URL in (1) the path parameter to library/adodb/adodb.inc.php, (2) the… NVD-CWE-Other
CVE-2007-2278 2018-10-17 01:42 2007-04-26 Show GitHub Exploit DB Packet Storm
283420 - symantec veritas_storage_foundation The Scheduler Service (VxSchedService.exe) in Symantec Storage Foundation for Windows 5.0 allows remote attackers to bypass authentication and execute arbitrary code via certain requests to the servi… CWE-264
Permissions, Privileges, and Access Controls
CVE-2007-2279 2018-10-17 01:42 2007-06-5 Show GitHub Exploit DB Packet Storm