Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
216981 5 警告 virtuastore - VirtuaStore の administrador.asp における絶対パストラバーサルの脆弱性 - CVE-2006-3488 2013-12-26 15:44 2006-07-10 Show GitHub Exploit DB Packet Storm
216982 4.6 警告 アドビシステムズ - Mac OS X 上で稼働する Adobe Reader および Acrobat における権限を取得される脆弱性 - CVE-2006-3452 2013-12-26 15:44 2006-07-12 Show GitHub Exploit DB Packet Storm
216983 5 警告 アップル - Apple Safari におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2006-3372 2013-12-26 15:44 2006-07-6 Show GitHub Exploit DB Packet Storm
216984 5 警告 bb-news - Blueboy における重要な情報を取得される脆弱性 - CVE-2006-3370 2013-12-26 15:44 2006-07-6 Show GitHub Exploit DB Packet Storm
216985 5.4 警告 アップル - Mac OS X 上で稼働する Apple Safari におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2006-3224 2013-12-26 15:44 2006-06-26 Show GitHub Exploit DB Packet Storm
216986 6.4 警告 hogstorps - Hogstorps hogstorp Guestbook の admin/redigera/redigera2.asp における任意のポストを編集される脆弱性 - CVE-2006-2773 2013-12-26 15:44 2006-06-2 Show GitHub Exploit DB Packet Storm
216987 6.4 警告 hogstorps - Hogstorps hogstorp guestbook の admin/radera/tabort.asp における任意のポストを削除される脆弱性 - CVE-2006-2771 2013-12-26 15:44 2006-06-2 Show GitHub Exploit DB Packet Storm
216988 5.1 警告 dgnews - DGNews の admin/upprocess.php における任意のコードを実行される脆弱性 - CVE-2006-2695 2013-12-26 15:44 2006-05-31 Show GitHub Exploit DB Packet Storm
216989 7.8 危険 eva-web - EVA-Web の不特定のスクリプトにおける Web サーバの絶対パスを取得される脆弱性 - CVE-2006-2690 2013-12-26 15:44 2006-05-31 Show GitHub Exploit DB Packet Storm
216990 4 警告 Laurent Destailleur - AWStats における任意のコードを実行される脆弱性 - CVE-2006-2644 2013-12-26 15:44 2006-05-30 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 16, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
51 4.9 MEDIUM
Network
kamailio kamailio Kamailio is an open source implementation of a SIP Signaling Server. Prior to 6.0.5 and 5.8.7, an out-of-bounds read in the auth module of Kamailio (formerly OpenSER and SER) allows remote attackers … New CWE-125
Out-of-bounds Read
CVE-2026-39864 2026-04-16 01:06 2026-04-9 Show GitHub Exploit DB Packet Storm
52 6.5 MEDIUM
Network
openclaw openclaw OpenClaw before 2026.3.22 contains an information disclosure vulnerability that allows attackers with operator.read scope to expose credentials embedded in channel baseUrl and httpUrl fields. Attacke… New CWE-312
 Cleartext Storage of Sensitive Information
CVE-2026-35644 2026-04-16 01:03 2026-04-10 Show GitHub Exploit DB Packet Storm
53 7.5 HIGH
Network
kamailio kamailio Kamailio is an open source implementation of a SIP Signaling Server. Prior to 6.1.1, 6.0.6, and 5.8.8, an out-of-bounds access in the core of Kamailio (formerly OpenSER and SER) allows remote attacke… New CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2026-39863 2026-04-16 00:58 2026-04-9 Show GitHub Exploit DB Packet Storm
54 4.3 MEDIUM
Network
apache openmeetings Improper Handling of Insufficient Privileges vulnerability in Apache OpenMeetings. Any registered user can query web service with their credentials and get files/sub-folders of any folder by ID (met… New CWE-274
 Improper Handling of Insufficient Privileges
CVE-2026-33005 2026-04-16 00:27 2026-04-10 Show GitHub Exploit DB Packet Storm
55 7.5 HIGH
Network
apache openmeetings Use of Hard-coded Cryptographic Key vulnerability in Apache OpenMeetings. The remember-me cookie encryption key is set to default value in openmeetings.properties and not being auto-rotated. In case… New CWE-321
 Use of Hard-coded Cryptographic Key
CVE-2026-33266 2026-04-16 00:21 2026-04-10 Show GitHub Exploit DB Packet Storm
56 7.5 HIGH
Network
apache openmeetings Use of GET Request Method With Sensitive Query Strings vulnerability in Apache OpenMeetings. The REST login endpoint uses HTTP GET method with username and password passed as query parameters. Pleas… New CWE-598
Information Exposure Through Query Strings in GET Request 
CVE-2026-34020 2026-04-16 00:21 2026-04-10 Show GitHub Exploit DB Packet Storm
57 9.1 CRITICAL
Network
- - V2Board 1.6.1 through 1.7.4 and Xboard through 0.1.9 expose authentication tokens in HTTP response bodies of the loginWithMailLink endpoint when the login_with_mail_link_enable feature is active. Una… New CWE-201
 Insertion of Sensitive Information Into Sent Data
CVE-2026-39912 2026-04-16 00:00 2026-04-10 Show GitHub Exploit DB Packet Storm
58 6.1 MEDIUM
Network
- - WordPress adivaha Travel Plugin 2.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the isMobile parameter. A… New CWE-79
Cross-site Scripting
CVE-2023-54358 2026-04-16 00:00 2026-04-10 Show GitHub Exploit DB Packet Storm
59 8.2 HIGH
Network
- - WordPress adivaha Travel Plugin 2.3 contains a time-based blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'pid… New CWE-89
SQL Injection
CVE-2023-54359 2026-04-16 00:00 2026-04-10 Show GitHub Exploit DB Packet Storm
60 6.1 MEDIUM
Network
- - Joomla JLex Review 6.0.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the review_id URL parameter. Attackers can craft mal… New CWE-79
Cross-site Scripting
CVE-2023-54360 2026-04-16 00:00 2026-04-10 Show GitHub Exploit DB Packet Storm