Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
216451 5 警告 Franklin Fueling Systems - Franklin Fueling Systems TS-550 evo のファームウェアの cgi-bin/tsaws.cgi における重要な情報を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2013-7247 2014-01-28 17:57 2013-12-18 Show GitHub Exploit DB Packet Storm
216452 6.5 警告 デル - Dell KACE K1000 における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2014-1671 2014-01-28 17:56 2014-01-13 Show GitHub Exploit DB Packet Storm
216453 5 警告 Galen Charlton - Evergreen などの製品で使用される MARC::File::XML モジュールにおける XML 外部エンティティの脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-1626 2014-01-28 17:56 2014-01-21 Show GitHub Exploit DB Packet Storm
216454 7.5 危険 General Electric Company - GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY および Proficy Process Systems with CIMPLICITY におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2014-0751 2014-01-28 17:44 2014-01-21 Show GitHub Exploit DB Packet Storm
216455 7.5 危険 General Electric Company - GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY および Proficy Process Systems with CIMPLICITY におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2014-0750 2014-01-28 17:37 2014-01-21 Show GitHub Exploit DB Packet Storm
216456 5 警告 baseurl.org - yum の yum-cron/yum-cron.py の installUpdates 関数における RMP パッケージの署名の制限を回避される脆弱性 CWE-20
不適切な入力確認
CVE-2014-0022 2014-01-28 17:02 2014-01-14 Show GitHub Exploit DB Packet Storm
216457 5.5 警告 シスコシステムズ - Cisco Secure Access Control System のポータルインターフェースにおけるセッションをハイジャックされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2014-0678 2014-01-28 16:49 2014-01-27 Show GitHub Exploit DB Packet Storm
216458 4.3 警告 シスコシステムズ - Cisco Video Surveillance 5000 HD IP Dome カメラの Web インターフェースにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-0673 2014-01-28 16:32 2014-01-27 Show GitHub Exploit DB Packet Storm
216459 7.5 危険 Josh Fradley - Burden の login.php の "remember me" 機能における認証を回避される脆弱性 CWE-287
不適切な認証
CVE-2013-7137 2014-01-28 16:19 2013-12-18 Show GitHub Exploit DB Packet Storm
216460 4.3 警告 ヤフー株式会社 - FireFox 用 Yahoo! Toolbar プラグインの clickstream.js におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-6853 2014-01-28 16:15 2014-01-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 19, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
21 - - - An example of BashOperator in Airflow documentation suggested a way of passing dag_run.conf in the way that could cause unsanitized user input to be used to escalate privileges of UI user to allow ex… New CWE-77
Command Injection
CVE-2026-30898 2026-04-18 16:16 2026-04-18 Show GitHub Exploit DB Packet Storm
22 - - - Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly tr… New CWE-502
 Deserialization of Untrusted Data
CVE-2026-25917 2026-04-18 16:16 2026-04-18 Show GitHub Exploit DB Packet Storm
23 6.9 MEDIUM
Local
- - In iTerm2 through 3.6.9, displaying a .txt file can cause code execution via DCS 2000p and OSC 135 data, if the working directory contains a malicious file whose name is valid output from the conduct… New CWE-829
 Inclusion of Functionality from Untrusted Control Sphere
CVE-2026-41253 2026-04-18 15:16 2026-04-18 Show GitHub Exploit DB Packet Storm
24 8.8 HIGH
Network
- - The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to arbitrary file upload and remote code execution in all versions up to, and including, 4.1.16 via the `c… New CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2026-6518 2026-04-18 14:16 2026-04-18 Show GitHub Exploit DB Packet Storm
25 6.4 MEDIUM
Network
- - The Flipbox Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Flipbox widget's button URL `custom_attributes` field in all versions up to, and including, 2… New CWE-79
Cross-site Scripting
CVE-2026-6048 2026-04-18 14:16 2026-04-18 Show GitHub Exploit DB Packet Storm
26 6.4 MEDIUM
Network
- - The Page Builder Gutenberg Blocks – CoBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via external iCal feed data in all versions up to, and including, 3.1.16 due to insuffic… New CWE-79
Cross-site Scripting
CVE-2026-4801 2026-04-18 14:16 2026-04-18 Show GitHub Exploit DB Packet Storm
27 7.5 HIGH
Network
- - Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 allows adversaries to circumvent ViewState validation mechanisms and achieve remot… New CWE-321
CWE-502
 Use of Hard-coded Cryptographic Key
 Deserialization of Untrusted Data
CVE-2026-5426 2026-04-18 13:16 2026-04-17 Show GitHub Exploit DB Packet Storm
28 7.5 HIGH
Network
- - libexpat before 2.7.6 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document. New CWE-331
 Insufficient Entropy
CVE-2026-41080 2026-04-18 13:16 2026-04-17 Show GitHub Exploit DB Packet Storm
29 6.5 MEDIUM
Adjacent
- - An issue in the Bluetooth Low Energy (BLE) control interface of the Yamaha SR-B30A sound bar firmware 2.40 (Mobile App: Sound Bar Remote / version: 2.40) allows remote attackers within BLE radio rang… New CWE-284
Improper Access Control
CVE-2026-37100 2026-04-18 13:16 2026-04-17 Show GitHub Exploit DB Packet Storm
30 7.5 HIGH
Network
- - JWT Tokens used by tasks were exposed in logs. This could allow UI users to act as Dag Authors. Users are advised to upgrade to Airflow version that contains fix. Users are recommended to upgrade t… New CWE-532
 Inclusion of Sensitive Information in Log Files
CVE-2026-31987 2026-04-18 13:16 2026-04-16 Show GitHub Exploit DB Packet Storm