Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2081 7.5 重要
Network
Spree Commerce Spree Spree CommerceのSpreeにおけるユーザ制御の鍵による認証回避に関する脆弱性 CWE-639
ユーザ制御の鍵による認証回避
CVE-2026-22589 2026-01-23 14:18 2026-01-10 Show GitHub Exploit DB Packet Storm
2082 7.1 重要
Local
PNG Development Group libpng PNG Development Groupのlibpngにおける境界外読み取りに関する脆弱性 CWE-125
境界外読み取り
CVE-2026-22695 2026-01-23 14:18 2026-01-12 Show GitHub Exploit DB Packet Storm
2083 8.8 重要
Network
appsmith appsmith appsmithにおける同一生成元ポリシー違反に関する脆弱性 CWE-346
同一生成元ポリシー違反
CVE-2026-22794 2026-01-23 14:18 2026-01-12 Show GitHub Exploit DB Packet Storm
2084 8.8 重要
Network
emlog emlog emlogにおける危険なタイプのファイルの無制限アップロードに関する脆弱性 CWE-434
危険なタイプのファイルの無制限アップロード
CVE-2026-22799 2026-01-23 14:18 2026-01-12 Show GitHub Exploit DB Packet Storm
2085 4.5 警告
Network
thm PILOS (Platform for Interactive Live-Online Seminars) Technischen Hochschule MittelhessenのPILOS (Platform for Interactive Live-Online Seminars)におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2026-22800 2026-01-23 14:18 2026-01-12 Show GitHub Exploit DB Packet Storm
2086 7.8 重要
Local
PNG Development Group libpng PNG Development Groupのlibpngにおける複数の脆弱性 CWE-125
CWE-125
CWE-190
CVE-2026-22801 2026-01-23 14:18 2026-01-12 Show GitHub Exploit DB Packet Storm
2087 7.5 重要
Network
Svelte project kit Svelte projectのkitにおける複数の脆弱性 CWE-770
CWE-789
CVE-2026-22803 2026-01-23 14:18 2026-01-15 Show GitHub Exploit DB Packet Storm
2088 7.5 重要
Network
Deno Land Deno Deno Land Inc.のDenoにおける暗号化処理の不備に関する脆弱性 CWE-325
暗号化処理の不備
CVE-2026-22863 2026-01-23 14:18 2026-01-15 Show GitHub Exploit DB Packet Storm
2089 9.8 緊急
Network
Deno Land Deno Deno Land Inc.のDenoにおけるコマンドインジェクションの脆弱性 CWE-77
コマンドインジェクション
CVE-2026-22864 2026-01-23 14:17 2026-01-15 Show GitHub Exploit DB Packet Storm
2090 7.5 重要
Network
Datadog guarddog Datadogのguarddogにおける高圧縮データの処理 (データ増幅)に関する脆弱性 CWE-409
高圧縮データの不適切な処理 (データ増幅)
CVE-2026-22870 2026-01-23 14:17 2026-01-13 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 26, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
283371 - apple safari Apple QuickTime Java extensions (QTJava.dll), as used in Safari and other browsers, and when Java is enabled, allows remote attackers to execute arbitrary code via parameters to the toQTPointer metho… NVD-CWE-Other
CVE-2007-2175 2018-10-17 01:42 2007-04-25 Show GitHub Exploit DB Packet Storm
283372 - raiden_professional_servers raidenftpd Multiple unspecified vulnerabilities in IXceedCompression in XceddZipLib (RaidenFTPD.dll) in RaidenFTPD 2.4 allow remote attackers to cause a denial of service (crash) via unspecified vectors involvi… NVD-CWE-Other
CVE-2007-2179 2018-10-17 01:42 2007-04-25 Show GitHub Exploit DB Packet Storm
283373 - nullsoft winamp Buffer overflow in Nullsoft Winamp 5.3 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted WMV file. NVD-CWE-Other
CVE-2007-2180 2018-10-17 01:42 2007-04-25 Show GitHub Exploit DB Packet Storm
283374 - brettle_development neatupload Race condition in the NeatUpload ASP.NET component 1.2.11 through 1.2.16, 1.1.18 through 1.1.23, and trunk.379 through trunk.445 allows remote attackers to obtain other clients' HTTP responses via mu… NVD-CWE-Other
CVE-2007-2197 2018-10-17 01:42 2007-04-25 Show GitHub Exploit DB Packet Storm
283375 - cjg_explorer_pro
joomla
nx
phpsitebackup
cjg_explorer_pro
joomla
n_x_wcms
phpsitebackup
PHP remote file inclusion vulnerability in lib/pcltar.lib.php (aka pcltar.php) in the PclTar module 1.3 and 1.3.1 for Vincent Blavet PhpConcept Library, as used in multiple products including (1) Joo… CWE-94
Code Injection
CVE-2007-2199 2018-10-17 01:42 2007-04-25 Show GitHub Exploit DB Packet Storm
283376 - post_revolution post_revolution Multiple PHP remote file inclusion vulnerabilities in Post Revolution 6.6 and 7.0 RC2 allow remote attackers to execute arbitrary PHP code via a URL in the dir parameter to (1) common.php or (2) them… NVD-CWE-Other
CVE-2007-2201 2018-10-17 01:42 2007-04-25 Show GitHub Exploit DB Packet Storm
283377 - acvsws acvsws_php5 PHP remote file inclusion vulnerability in inc_ACVS/SOAP/Transport.php in Accueil et Conseil en Visites et Sejours Web Services (ACVSWS) PHP5 (ACVSWS_PHP5) 1.0 allows remote attackers to execute arbi… NVD-CWE-Other
CVE-2007-2202 2018-10-17 01:42 2007-04-25 Show GitHub Exploit DB Packet Storm
283378 - big_blue guestbook Cross-site scripting (XSS) vulnerability in Big Blue Guestbook allows remote attackers to inject arbitrary web script or HTML via the message field in the guestbook entry submission form. NVD-CWE-Other
CVE-2007-2203 2018-10-17 01:42 2007-04-25 Show GitHub Exploit DB Packet Storm
283379 - lan_management_system lan_management_system PHP remote file inclusion vulnerability in modules/rtmessageadd.php in LAN Management System (LMS) 1.5.3, and possibly 1.5.4, allows remote attackers to execute arbitrary PHP code via a URL in the _L… NVD-CWE-Other
CVE-2007-2205 2018-10-17 01:42 2007-04-25 Show GitHub Exploit DB Packet Storm
283380 - ripe_website_manager ripe_website_manager SQL injection vulnerability in contact/index.php in Ripe Website Manager 0.8.4 and earlier allows remote attackers to execute arbitrary SQL commands via the ripeformpost parameter. NVD-CWE-Other
CVE-2007-2207 2018-10-17 01:42 2007-04-25 Show GitHub Exploit DB Packet Storm