Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
223421 6.8 警告 stewart howe - CelerBB の login.php における認証を回避される脆弱性 CWE-287
不適切な認証
CVE-2009-0853 2012-12-20 19:10 2009-03-9 Show GitHub Exploit DB Packet Storm
223422 5 警告 stewart howe - CelerBB の showme.php における "予約情報" を取得される脆弱性 CWE-200
情報漏えい
CVE-2009-0852 2012-12-20 19:10 2009-03-9 Show GitHub Exploit DB Packet Storm
223423 6.8 警告 stewart howe - CelerBB における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-0851 2012-12-20 19:10 2009-03-9 Show GitHub Exploit DB Packet Storm
223424 7.8 危険 UMN - MapServer の mapser における任意のファイルの存在を特定される脆弱性 CWE-20
不適切な入力確認
CVE-2009-0843 2012-12-20 19:10 2009-03-31 Show GitHub Exploit DB Packet Storm
223425 4.3 警告 UMN - MapServer の mapserv における任意の無効な .map ファイルを読み取られる脆弱性 CWE-200
情報漏えい
CVE-2009-0842 2012-12-20 19:10 2009-03-31 Show GitHub Exploit DB Packet Storm
223426 10 危険 UMN - MapServer の mapserv におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2009-0841 2012-12-20 19:10 2009-03-31 Show GitHub Exploit DB Packet Storm
223427 10 危険 UMN - MapServer の mapserv におけるヒープベースのバッファアンダーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-0840 2012-12-20 19:10 2009-03-31 Show GitHub Exploit DB Packet Storm
223428 10 危険 UMN - MapServer の mapserv におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-0839 2012-12-20 19:10 2009-03-31 Show GitHub Exploit DB Packet Storm
223429 6 警告 PHP-Fusion - PHP-Fusion 用の Members CV モジュールにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-0831 2012-12-20 19:10 2009-03-5 Show GitHub Exploit DB Packet Storm
223430 7.5 危険 torben sorensen - TinX/cms の system/rss.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-0825 2012-12-20 19:10 2009-03-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 20, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1691 9.1 CRITICAL
Network
digitalbazaar forge Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, `pki.verifyCertificateChain()` does not enforce RFC 5280 basicConstraint… CWE-295
Improper Certificate Validation 
CVE-2026-33896 2026-04-14 10:13 2026-03-28 Show GitHub Exploit DB Packet Storm
1692 9.8 CRITICAL
Network
openfga openfga OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. In versions prior to 1.13.1, under specific conditions, models using c… CWE-20
CWE-345
CWE-1289
 Improper Input Validation 
 Insufficient Verification of Data Authenticity
 Improper Validation of Unsafe Equivalence in Input
CVE-2026-33729 2026-04-14 10:04 2026-03-27 Show GitHub Exploit DB Packet Storm
1693 9.8 CRITICAL
Network
openfga openfga OpenFGA es un motor de autorización/permisos de alto rendimiento y flexible, construido para desarrolladores e inspirado en Google Zanzibar. En versiones anteriores a la 1.13.1, bajo condiciones espe… CWE-20
CWE-345
CWE-1289
 Improper Input Validation 
 Insufficient Verification of Data Authenticity
 Improper Validation of Unsafe Equivalence in Input
CVE-2026-33729 2026-04-14 10:04 2026-03-27 Show GitHub Exploit DB Packet Storm
1694 4.3 MEDIUM
Network
grafana grafana A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API allows users with Editor role to modify protected webhook URLs without the requ… CWE-285
Improper Authorization
CVE-2026-21724 2026-04-14 10:00 2026-03-27 Show GitHub Exploit DB Packet Storm
1695 4.3 MEDIUM
Network
grafana grafana Se ha descubierto una vulnerabilidad en Grafana OSS donde una omisión de autorización en la API de puntos de contacto de aprovisionamiento permite a los usuarios con rol de Editor modificar URLs de w… CWE-285
Improper Authorization
CVE-2026-21724 2026-04-14 10:00 2026-03-27 Show GitHub Exploit DB Packet Storm
1696 7.5 HIGH
Network
libjxl_project libjxl A specially-crafted file can cause libjxl's decoder to write pixel data to uninitialized unallocated memory. Soon after that data from another uninitialized unallocated region is copied to pixel data… CWE-805
CWE-770
 Buffer Access with Incorrect Length Value
 Allocation of Resources Without Limits or Throttling
CVE-2026-1837 2026-04-14 09:51 2026-02-12 Show GitHub Exploit DB Packet Storm
1697 7.5 HIGH
Network
libjxl_project libjxl Un archivo especialmente diseñado puede provocar que el decodificador de libjxl escriba datos de píxeles en memoria no asignada no inicializada. Poco después, datos de otra región no asignada no inic… CWE-805
CWE-770
 Buffer Access with Incorrect Length Value
 Allocation of Resources Without Limits or Throttling
CVE-2026-1837 2026-04-14 09:51 2026-02-12 Show GitHub Exploit DB Packet Storm
1698 2.7 LOW
Network
windmill windmill Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Versions 1.634.6 and below allow non-admin users to obtain Slack OAuth client secrets, whic… CWE-200
NVD-CWE-noinfo
Information Exposure
CVE-2026-26964 2026-04-14 09:50 2026-02-20 Show GitHub Exploit DB Packet Storm
1699 2.7 LOW
Network
windmill windmill Windmill es una plataforma de desarrollo de código abierto para código interno: APIs, trabajos en segundo plano, flujos de trabajo e interfaces de usuario. Las versiones 1.634.6 y anteriores permiten… CWE-200
NVD-CWE-noinfo
Information Exposure
CVE-2026-26964 2026-04-14 09:50 2026-02-20 Show GitHub Exploit DB Packet Storm
1700 6.5 MEDIUM
Network
lfprojects model_context_protocol_servers Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). In mcp-server-git versions prior to 2026.1.14, the git_add tool did not validate that… CWE-22
Path Traversal
CVE-2026-27735 2026-04-14 09:44 2026-02-26 Show GitHub Exploit DB Packet Storm