Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
219171 6.8 警告 シスコシステムズ - Cisco Unified Communications Manager の Enterprise License Manager におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2013-3472 2013-09-2 12:31 2013-08-28 Show GitHub Exploit DB Packet Storm
219172 4.3 警告 シスコシステムズ - Cisco Identity Services Engine の captive portal アプリケーションにおける平文のユーザ名およびパスワードを破られる脆弱性 CWE-255
証明書・パスワード管理
CVE-2013-3471 2013-09-2 12:27 2013-08-28 Show GitHub Exploit DB Packet Storm
219173 7.8 危険 シスコシステムズ - Cisco Unified IP Phone 8945 のソフトウェアにおけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2013-3468 2013-09-2 12:21 2013-08-28 Show GitHub Exploit DB Packet Storm
219174 9.3 危険 シスコシステムズ - Cisco Secure Access Control Server の EAP-FAST 認証モジュールにおける任意のコマンドを実行される脆弱性 CWE-287
不適切な認証
CVE-2013-3466 2013-09-2 12:11 2013-08-28 Show GitHub Exploit DB Packet Storm
219175 7.5 危険 Adam Zaninovich - Ruby 用 sounder gem の lib/sounder/sound.rb における任意のコマンドを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2013-5647 2013-09-2 11:04 2013-08-9 Show GitHub Exploit DB Packet Storm
219176 3.5 注意 Roundcube.net - Roundcube Webmail におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-5646 2013-09-2 09:58 2013-08-4 Show GitHub Exploit DB Packet Storm
219177 4.3 警告 Roundcube.net - Roundcube Webmail におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-5645 2013-09-2 09:51 2013-08-1 Show GitHub Exploit DB Packet Storm
219178 7.5 危険 The Cacti Group - Cacti の cacti/host.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2013-5589 2013-08-30 16:46 2013-08-24 Show GitHub Exploit DB Packet Storm
219179 4.3 警告 The Cacti Group - Cacti におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2013-5588 2013-08-30 16:44 2013-08-24 Show GitHub Exploit DB Packet Storm
219180 7.8 危険 FreeBSD - FreeBSD のカーネルの SCTP の実装におけるカーネルスタックメモリから重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2013-5209 2013-08-30 16:42 2012-08-22 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 19, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
321 7.7 HIGH
Network
- - Weblate is a web based localization tool. In versions prior to 5.17, the ZIP download feature didn't verify downloaded files, potentially following symlinks outside the repository. This issue has be… New CWE-22
CWE-59
CWE-200
Path Traversal
Link Following
Information Exposure
CVE-2026-34242 2026-04-18 00:38 2026-04-16 Show GitHub Exploit DB Packet Storm
322 5.0 MEDIUM
Network
- - Weblate is a web based localization tool. In versions prior to 5.17, a user with the project.edit permission (granted by the per-project "Administration" role) can configure machine translation servi… New CWE-200
CWE-918
Information Exposure
Server-Side Request Forgery (SSRF) 
CVE-2026-34244 2026-04-18 00:38 2026-04-16 Show GitHub Exploit DB Packet Storm
323 8.8 HIGH
Network
- - Weblate is a web based localization tool. In versions prior to 5.17, the user patching API endpoint didn't properly limit the scope of edits. This issue has been fixed in version 5.17. New CWE-269
 Improper Privilege Management
CVE-2026-34393 2026-04-18 00:38 2026-04-16 Show GitHub Exploit DB Packet Storm
324 4.1 MEDIUM
Network
- - Weblate is a web based localization tool. In versions prior to 5.17, the webhook add-on did not utilize existing SSRF protections. This issue has been fixed in version 5.17. If developers are unable … New CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-39845 2026-04-18 00:38 2026-04-16 Show GitHub Exploit DB Packet Storm
325 5.0 MEDIUM
Network
- - Weblate is a web based localization tool. In versions prior to 5.17, repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses s… New CWE-22
Path Traversal
CVE-2026-40256 2026-04-18 00:38 2026-04-16 Show GitHub Exploit DB Packet Storm
326 7.8 HIGH
Local
- - Barracuda RMM versions prior to 2025.2.2 contain a privilege escalation vulnerability that allows local attackers to gain SYSTEM-level privileges by exploiting overly permissive filesystem ACLs on th… New CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2026-22676 2026-04-18 00:38 2026-04-16 Show GitHub Exploit DB Packet Storm
327 9.4 CRITICAL
Network
- - Dgraph is an open source distributed GraphQL database. Versions 25.3.1 and prior contain an unauthenticated credential disclosure vulnerability where the /debug/pprof/cmdline endpoint is registered o… New CWE-200
CWE-215
Information Exposure
 Insertion of Sensitive Information Into Debugging Code
CVE-2026-40173 2026-04-18 00:38 2026-04-16 Show GitHub Exploit DB Packet Storm
328 - - - Pega Platform versions 8.1.0 through 25.1.1 are affected by an HTML Injection vulnerability in a user interface component. Requires a high privileged user with a developer role. New CWE-80
Basic XSS
CVE-2026-1564 2026-04-18 00:38 2026-04-16 Show GitHub Exploit DB Packet Storm
329 - - - Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-Site Scripting vulnerability in a user interface component. Requires a high privileged user with a developer role. New CWE-79
Cross-site Scripting
CVE-2026-1711 2026-04-18 00:38 2026-04-16 Show GitHub Exploit DB Packet Storm
330 6.8 MEDIUM
Network
- - ProcessWire CMS version 3.0.255 and prior contain a server-side request forgery vulnerability in the admin panel's 'Add Module From URL' feature that allows authenticated administrators to supply arb… New CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-40500 2026-04-18 00:38 2026-04-16 Show GitHub Exploit DB Packet Storm