Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 28, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
214521 5.4 警告 inzeratyzdarma - Android 用 Ads Free. Cz advert アプリケーションにおけるサーバになりすまされる脆弱性 CWE-310
暗号の問題
CVE-2014-7668 2014-12-17 09:57 2014-09-3 Show GitHub Exploit DB Packet Storm
214522 5.4 警告 enyetech - Android 用 Coca-Cola FM Honduras アプリケーションにおけるサーバになりすまされる脆弱性 CWE-310
暗号の問題
CVE-2014-7667 2014-12-17 09:57 2014-09-3 Show GitHub Exploit DB Packet Storm
214523 5.4 警告 pocketmags - Android 用 American Waterfowler アプリケーションにおけるサーバになりすまされる脆弱性 CWE-310
暗号の問題
CVE-2014-7666 2014-12-17 09:57 2014-09-3 Show GitHub Exploit DB Packet Storm
214524 5.4 警告 bilingual magic ball relajo project - Android 用 Bilingual Magic Ball Relajo アプリケーションにおけるサーバになりすまされる脆弱性 CWE-310
暗号の問題
CVE-2014-7664 2014-12-17 09:57 2014-09-3 Show GitHub Exploit DB Packet Storm
214525 5.4 警告 go-nitty-gritty - Android 用 Right to the Nitty Gritty アプリケーションにおけるサーバになりすまされる脆弱性 CWE-310
暗号の問題
CVE-2014-7663 2014-12-17 09:57 2014-09-3 Show GitHub Exploit DB Packet Storm
214526 5.4 警告 masquito2013 - Android 用 Masquito Blogger アプリケーションにおけるサーバになりすまされる脆弱性 CWE-310
暗号の問題
CVE-2014-7661 2014-12-17 09:57 2014-09-3 Show GitHub Exploit DB Packet Storm
214527 5.4 警告 Magzter Inc. - Android 用 Gent Magazine アプリケーションにおけるサーバになりすまされる脆弱性 CWE-310
暗号の問題
CVE-2014-7660 2014-12-17 09:57 2014-09-3 Show GitHub Exploit DB Packet Storm
214528 5.4 警告 expeditersonline - Android 用 ExpeditersOnline.com Forum アプリケーションにおけるサーバになりすまされる脆弱性 CWE-310
暗号の問題
CVE-2014-7659 2014-12-17 09:57 2014-09-3 Show GitHub Exploit DB Packet Storm
214529 5.4 警告 Magzter Inc. - Android 用 Indian Management アプリケーションにおけるサーバになりすまされる脆弱性 CWE-310
暗号の問題
CVE-2014-7656 2014-12-17 09:57 2014-09-3 Show GitHub Exploit DB Packet Storm
214530 5.4 警告 verkehrsmuseum-dresden - Android 用 Dresden Transport Museum アプリケーションにおけるサーバになりすまされる脆弱性 CWE-310
暗号の問題
CVE-2014-7655 2014-12-17 09:57 2014-09-3 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 28, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
2421 8.8 HIGH
Network
- - Schlix CMS 2.2.6-6 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary PHP code by uploading malicious extension packages through the block manager… CWE-94
Code Injection
CVE-2021-47964 2026-05-19 02:26 2026-05-16 Show GitHub Exploit DB Packet Storm
2422 7.5 HIGH
Network
- - Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.2, Vvveb CMS does not validate the sign of the quantity parameter on the cart-ad… CWE-1284
 Improper Validation of Specified Quantity in Input
CVE-2026-44826 2026-05-19 02:26 2026-05-16 Show GitHub Exploit DB Packet Storm
2423 - - - Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3, This vulnerability is fixed in 1.0.8.3. CWE-79
Cross-site Scripting
CVE-2026-45616 2026-05-19 02:26 2026-05-16 Show GitHub Exploit DB Packet Storm
2424 8.1 HIGH
Network
- - Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3, the backend admin/auth-token endpoint allows an authenticated administrator t… CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-46407 2026-05-19 02:26 2026-05-16 Show GitHub Exploit DB Packet Storm
2425 7.6 HIGH
Network
- - Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3, the checkout endpoint accepts a user-controlled cart_id and uses it to enter … CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-46408 2026-05-19 02:26 2026-05-16 Show GitHub Exploit DB Packet Storm
2426 6.4 MEDIUM
Network
- - Composr CMS 10.0.34 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through the banner management interface. Attackers wi… CWE-79
Cross-site Scripting
CVE-2020-37237 2026-05-19 02:26 2026-05-17 Show GitHub Exploit DB Packet Storm
2427 6.4 MEDIUM
Network
- - CMS Made Simple 2.2.15 contains a stored cross-site scripting vulnerability that allows authenticated users with Content Manager access to inject malicious scripts through SVG file uploads. Attackers… CWE-79
Cross-site Scripting
CVE-2020-37238 2026-05-19 02:26 2026-05-17 Show GitHub Exploit DB Packet Storm
2428 5.3 MEDIUM
Network
- - bloofoxCMS 0.5.2.1 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by tricking logged-in users into visiting malicious pages. Attackers can… CWE-352
 Origin Validation Error
CVE-2020-37241 2026-05-19 02:26 2026-05-17 Show GitHub Exploit DB Packet Storm
2429 5.4 MEDIUM
Network
- - CouchCMS 2.2.1 contains a cross-site scripting vulnerability that allows authenticated attackers to execute arbitrary JavaScript by uploading malicious SVG files through the file upload functionality… CWE-79
Cross-site Scripting
CVE-2021-47955 2026-05-19 02:26 2026-05-17 Show GitHub Exploit DB Packet Storm
2430 8.8 HIGH
Network
- - TextPattern CMS 4.9.0-dev contains a remote code execution vulnerability that allows authenticated attackers to upload arbitrary PHP files by exploiting the plugin upload functionality. Attackers can… CWE-352
 Origin Validation Error
CVE-2021-47976 2026-05-19 02:26 2026-05-17 Show GitHub Exploit DB Packet Storm