Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
222861 7.5 危険 santostefano giovanni - ToyLog の read.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-3750 2012-12-20 19:28 2009-10-22 Show GitHub Exploit DB Packet Storm
222862 5 警告 ウェブセンス - Websense Personal Email Manager および Email Security の Web Administrator サービスにおけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2009-3749 2012-12-20 19:28 2009-10-22 Show GitHub Exploit DB Packet Storm
222863 4.3 警告 ウェブセンス - Websense Personal Email Manager および Email Security の Web Administrator におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-3748 2012-12-20 19:28 2009-10-22 Show GitHub Exploit DB Packet Storm
222864 4.3 警告 tbmnet - TBmnetCMS の index.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-3747 2012-12-20 19:28 2009-10-22 Show GitHub Exploit DB Packet Storm
222865 10 危険 riorey - RioRey RIOS における権限を取得される脆弱性 CWE-255
証明書・パスワード管理
CVE-2009-3710 2012-12-20 19:28 2009-10-16 Show GitHub Exploit DB Packet Storm
222866 5 警告 zoiper - ZoIPer におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2009-3704 2012-12-20 19:28 2009-10-16 Show GitHub Exploit DB Packet Storm
222867 7.5 危険 php-calendar project - PHP-Calendar における絶対パストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2009-3702 2012-12-20 19:28 2009-12-22 Show GitHub Exploit DB Packet Storm
222868 5 警告 squidguard - squidGuard の sgLog.c におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-3700 2012-12-20 19:28 2009-10-28 Show GitHub Exploit DB Packet Storm
222869 7.5 危険 The phpMyAdmin Project - phpMyAdmin の PDF スキーマジェネレータ機能における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-3697 2012-12-20 19:28 2009-10-13 Show GitHub Exploit DB Packet Storm
222870 4.3 警告 The phpMyAdmin Project - phpMyAdmin におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-3696 2012-12-20 19:28 2009-10-13 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 25, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1761 - - - Allocation of resources without limits or throttling vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpg on all (pg modules).This issue affects BC-JAVA: before 1.84. Unbounded PGP AEAD ch… CWE-400
CWE-770
 Uncontrolled Resource Consumption
 Allocation of Resources Without Limits or Throttling
CVE-2026-3505 2026-04-18 00:38 2026-04-15 Show GitHub Exploit DB Packet Storm
1762 - - - : Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all (pkix modules). PKIX draft CompositeVerifier accepts empty signature seque… CWE-327
 Use of a Broken or Risky Cryptographic Algorithm
CVE-2026-5588 2026-04-18 00:38 2026-04-15 Show GitHub Exploit DB Packet Storm
1763 5.5 MEDIUM
Local
- - Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Versions 2.0.5 and below contain an authorization bypass vulnerability in the VerifyTimestampResponse function. VerifyTimest… CWE-295
Improper Certificate Validation 
CVE-2026-39984 2026-04-18 00:38 2026-04-15 Show GitHub Exploit DB Packet Storm
1764 7.1 HIGH
Network
- - Zarf is an Airgap Native Packager Manager for Kubernetes. Versions 0.23.0 through 0.74.1 contain an arbitrary file write vulnerability in the zarf package inspect sbom and zarf package inspect docume… CWE-22
Path Traversal
CVE-2026-40090 2026-04-18 00:38 2026-04-15 Show GitHub Exploit DB Packet Storm
1765 - - - immich is a high performance self-hosted photo and video management solution. Versions prior to 2.7.3 contain an open redirect vulnerability in the shared album functionality, where the album name is… CWE-79
CWE-601
Cross-site Scripting
Open Redirect
CVE-2026-40096 2026-04-18 00:38 2026-04-15 Show GitHub Exploit DB Packet Storm
1766 9.1 CRITICAL
Network
- - @fastify/express v4.0.4 and earlier contains a path handling bug in the onRegister function that causes middleware paths to be doubled when inherited by child plugins. When a child plugin is register… CWE-436
 Interpretation Conflict
CVE-2026-33807 2026-04-18 00:38 2026-04-15 Show GitHub Exploit DB Packet Storm
1767 - - - Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules). Non-constant time comparisons risk private key leakage in FrodoKEM. This issue affects BC… CWE-385
 Covert Timing Channel
CVE-2026-5598 2026-04-18 00:38 2026-04-15 Show GitHub Exploit DB Packet Storm
1768 7.5 HIGH
Network
- - An issue in the file handling logic of the component download.php of SAC-NFe v2.0.02 allows attackers to execute a directory traversal and read arbitrary files from the system via a crafted GET reque… CWE-22
Path Traversal
CVE-2026-30996 2026-04-18 00:38 2026-04-16 Show GitHub Exploit DB Packet Storm
1769 7.4 HIGH
Network
- - Git for Windows is the Windows port of Git. Versions prior to 2.53.0.windows.3 do not have protections that prevent attackers from obtaining a user's NTLM hash. The NTLM hash can be obtained by trick… CWE-200
Information Exposure
CVE-2026-32631 2026-04-18 00:38 2026-04-16 Show GitHub Exploit DB Packet Storm
1770 3.1 LOW
Network
- - Weblate is a web based localization tool. In versions prior to 5.17, the tasks API didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't hav… CWE-284
Improper Access Control
CVE-2026-33212 2026-04-18 00:38 2026-04-16 Show GitHub Exploit DB Packet Storm