Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
223551 7.5 危険 TYPO3 Association - TYPO3 の認証ライブラリにおけるセッションをハイジャックされる脆弱性 CWE-287
不適切な認証
CVE-2009-0256 2012-12-20 19:10 2009-01-22 Show GitHub Exploit DB Packet Storm
223552 5 警告 TYPO3 Association - TYPO3 の System エクステンションインストールツールにおける鍵を破られる脆弱性 CWE-310
暗号の問題
CVE-2009-0255 2012-12-20 19:10 2009-01-22 Show GitHub Exploit DB Packet Storm
223553 6.5 警告 ryneezy - Ryneezy phoSheezy の admin.php における任意の PHP コードを挿入される脆弱性 CWE-94
コード・インジェクション
CVE-2009-0251 2012-12-20 19:10 2009-01-22 Show GitHub Exploit DB Packet Storm
223554 5 警告 ryneezy - Ryneezy phoSheezy における管理者のパスワードハッシュを含むファイルをダウンロードされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2009-0250 2012-12-20 19:10 2009-01-22 Show GitHub Exploit DB Packet Storm
223555 3.5 注意 tigris - WebSVN の listing.php における制限されたプロジェクトに対するチェンジログを読まれる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2009-0240 2012-12-20 19:10 2009-01-20 Show GitHub Exploit DB Packet Storm
223556 9.3 危険 vuplayer - VUPlayer におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-0182 2012-12-20 19:10 2009-01-20 Show GitHub Exploit DB Packet Storm
223557 9.3 危険 vuplayer - VUPlayer におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-0181 2012-12-20 19:10 2009-01-20 Show GitHub Exploit DB Packet Storm
223558 9.3 危険 vuplayer - VUPlayer におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-0174 2012-12-20 19:10 2009-01-20 Show GitHub Exploit DB Packet Storm
223559 9.3 危険 share2 - AAA EasyGrid ActiveX の EasyGrid.ocx における任意のファイルを作成される脆弱性 CWE-Other
その他
CVE-2009-0134 2012-12-20 19:10 2009-01-16 Show GitHub Exploit DB Packet Storm
223560 7.5 危険 riotpix - RiotPix の read.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2009-0110 2012-12-20 19:10 2009-01-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 19, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1671 6.1 MEDIUM
Network
xinliangcoder php_api_doc XinLiangCoder php_api_doc through commit 1ce5bbf contains a reflected cross-site scripting vulnerability in list_method.php that allows remote attackers to execute arbitrary JavaScript in a victim's … CWE-79
Cross-site Scripting
CVE-2026-32844 2026-04-14 10:19 2026-03-21 Show GitHub Exploit DB Packet Storm
1672 6.1 MEDIUM
Network
xinliangcoder php_api_doc XinLiangCoder php_api_doc a través del commit 1ce5bbf contiene una vulnerabilidad de cross-site scripting reflejado en list_method.php que permite a atacantes remotos ejecutar JavaScript arbitrario e… CWE-79
Cross-site Scripting
CVE-2026-32844 2026-04-14 10:19 2026-03-21 Show GitHub Exploit DB Packet Storm
1673 9.1 CRITICAL
Network
qnap media_streaming_add-on A buffer overflow vulnerability has been reported to affect Media Streaming Add-On. The remote attackers can then exploit the vulnerability to modify memory or crash processes. We have already fixed… CWE-121
Stack-based Buffer Overflow
CVE-2025-59383 2026-04-14 10:17 2026-03-21 Show GitHub Exploit DB Packet Storm
1674 9.1 CRITICAL
Network
qnap media_streaming_add-on Se ha informado de una vulnerabilidad de desbordamiento de búfer que afecta a Media Streaming Add-On. Los atacantes remotos pueden entonces explotar la vulnerabilidad para modificar la memoria o bloq… CWE-121
Stack-based Buffer Overflow
CVE-2025-59383 2026-04-14 10:17 2026-03-21 Show GitHub Exploit DB Packet Storm
1675 7.5 HIGH
Network
digitalbazaar forge Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, Ed25519 signature verification accepts forged non-canonical signatures w… CWE-347
 Improper Verification of Cryptographic Signature
CVE-2026-33895 2026-04-14 10:14 2026-03-28 Show GitHub Exploit DB Packet Storm
1676 9.1 CRITICAL
Network
digitalbazaar forge Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, `pki.verifyCertificateChain()` does not enforce RFC 5280 basicConstraint… CWE-295
Improper Certificate Validation 
CVE-2026-33896 2026-04-14 10:13 2026-03-28 Show GitHub Exploit DB Packet Storm
1677 9.8 CRITICAL
Network
openfga openfga OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. In versions prior to 1.13.1, under specific conditions, models using c… CWE-20
CWE-345
CWE-1289
 Improper Input Validation 
 Insufficient Verification of Data Authenticity
 Improper Validation of Unsafe Equivalence in Input
CVE-2026-33729 2026-04-14 10:04 2026-03-27 Show GitHub Exploit DB Packet Storm
1678 9.8 CRITICAL
Network
openfga openfga OpenFGA es un motor de autorización/permisos de alto rendimiento y flexible, construido para desarrolladores e inspirado en Google Zanzibar. En versiones anteriores a la 1.13.1, bajo condiciones espe… CWE-20
CWE-345
CWE-1289
 Improper Input Validation 
 Insufficient Verification of Data Authenticity
 Improper Validation of Unsafe Equivalence in Input
CVE-2026-33729 2026-04-14 10:04 2026-03-27 Show GitHub Exploit DB Packet Storm
1679 4.3 MEDIUM
Network
grafana grafana A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API allows users with Editor role to modify protected webhook URLs without the requ… CWE-285
Improper Authorization
CVE-2026-21724 2026-04-14 10:00 2026-03-27 Show GitHub Exploit DB Packet Storm
1680 4.3 MEDIUM
Network
grafana grafana Se ha descubierto una vulnerabilidad en Grafana OSS donde una omisión de autorización en la API de puntos de contacto de aprovisionamiento permite a los usuarios con rol de Editor modificar URLs de w… CWE-285
Improper Authorization
CVE-2026-21724 2026-04-14 10:00 2026-03-27 Show GitHub Exploit DB Packet Storm