Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
223611 5 警告 WeBid Support - WeBid auction script における SQL クエリログを取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-7118 2012-12-20 19:10 2009-08-28 Show GitHub Exploit DB Packet Storm
223612 5 警告 WeBid Support - WeBid auction script の eledicss.php における任意のカスケードスタイルシートファイル (CSS) を変更される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-7117 2012-12-20 19:10 2009-08-28 Show GitHub Exploit DB Packet Storm
223613 7.5 危険 WeBid Support - WeBid auction script の admin panel における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-7116 2012-12-20 19:10 2009-08-28 Show GitHub Exploit DB Packet Storm
223614 4.3 警告 phpcart - Carmosa phpCart におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-7108 2012-12-20 19:10 2009-08-28 Show GitHub Exploit DB Packet Storm
223615 5 警告 ソフォス - Microsoft Exchange 用の Sophos PureMessage におけるスキャン保護のリモート回避をされる脆弱性 CWE-Other
その他
CVE-2008-7106 2012-12-20 19:10 2009-08-27 Show GitHub Exploit DB Packet Storm
223616 5 警告 ソフォス - Microsoft Exchange 用の Sophos PureMessage におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2008-7105 2012-12-20 19:10 2009-08-27 Show GitHub Exploit DB Packet Storm
223617 5 警告 ソフォス - Microsoft Exchange 用の PureMessage におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2008-7104 2012-12-20 19:10 2009-08-27 Show GitHub Exploit DB Packet Storm
223618 6.8 警告 qsoft-inc - Qsoft K-Rate Premium の Manage Templates 機能における任意の PHP コードを実行される脆弱性 CWE-noinfo
情報不足
CVE-2008-7099 2012-12-20 19:10 2009-08-27 Show GitHub Exploit DB Packet Storm
223619 4.3 警告 qsoft-inc - Qsoft K-Rate Premium におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-7098 2012-12-20 19:10 2009-08-27 Show GitHub Exploit DB Packet Storm
223620 7.5 危険 qsoft-inc - Qsoft K-Rate Premium における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-7097 2012-12-20 19:10 2009-08-27 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 25, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
2671 8.1 HIGH
Network
dynaconf dynaconf dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolv… CWE-94
CWE-1336
CWE-78
Code Injection
 Improper Neutralization of Special Elements Used in a Template Engine
OS Command 
CVE-2026-33154 2026-04-15 03:23 2026-03-21 Show GitHub Exploit DB Packet Storm
2672 8.1 HIGH
Network
dynaconf dynaconf dynaconf es una herramienta de gestión de configuración para Python. Antes de la versión 3.2.13, Dynaconf es vulnerable a la Inyección de Plantilla del Lado del Servidor (SSTI) debido a la evaluación… CWE-94
CWE-1336
CWE-78
Code Injection
 Improper Neutralization of Special Elements Used in a Template Engine
OS Command 
CVE-2026-33154 2026-04-15 03:23 2026-03-21 Show GitHub Exploit DB Packet Storm
2673 7.5 HIGH
Network
socket socket.io-parser Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. Prior to versions 3.3.5, 3.4.4, and 4.2.6, a specially crafted Socket.IO packet can make the server wait f… CWE-20
CWE-754
NVD-CWE-noinfo
 Improper Input Validation 
 Improper Check for Unusual or Exceptional Conditions
CVE-2026-33151 2026-04-15 03:22 2026-03-21 Show GitHub Exploit DB Packet Storm
2674 7.5 HIGH
Network
socket socket.io-parser Socket.IO es un framework de comunicación de código abierto, en tiempo real, bidireccional y basado en eventos. Antes de las versiones 3.3.5, 3.4.4 y 4.2.6, un paquete de Socket.IO especialmente dise… CWE-20
CWE-754
NVD-CWE-noinfo
 Improper Input Validation 
 Improper Check for Unusual or Exceptional Conditions
CVE-2026-33151 2026-04-15 03:22 2026-03-21 Show GitHub Exploit DB Packet Storm
2675 7.8 HIGH
Local
gpac gpac GPAC is an open-source multimedia framework. Prior to commit 86b0e36, a heap-based buffer overflow (write) vulnerability was discovered in GPAC MP4Box. The vulnerability exists in the gf_xml_parse_bi… CWE-787
 Out-of-bounds Write
CVE-2026-33144 2026-04-15 03:21 2026-03-21 Show GitHub Exploit DB Packet Storm
2676 7.8 HIGH
Local
gpac gpac GPAC es un framework multimedia de código abierto. Antes del commit 86b0e36, se descubrió una vulnerabilidad de desbordamiento de búfer basado en montículo (escritura) en GPAC MP4Box. La vulnerabilid… CWE-787
 Out-of-bounds Write
CVE-2026-33144 2026-04-15 03:21 2026-03-21 Show GitHub Exploit DB Packet Storm
2677 4.0 MEDIUM
Network
- - Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in magepeopleteam Bus Ticket Booking with Seat Reservation bus-ticket-booking-with-seat-reservation allows Ret… CWE-497
 Exposure of Sensitive System Information to an Unauthorized Control Sphere
CVE-2026-39572 2026-04-15 03:17 2026-04-8 Show GitHub Exploit DB Packet Storm
2678 5.3 MEDIUM
Network
- - Insertion of Sensitive Information Into Sent Data vulnerability in AA Web Servant 12 Step Meeting List 12-step-meeting-list allows Retrieve Embedded Sensitive Data.This issue affects 12 Step Meeting … CWE-201
 Insertion of Sensitive Information Into Sent Data
CVE-2026-39570 2026-04-15 03:17 2026-04-8 Show GitHub Exploit DB Packet Storm
2679 4.0 MEDIUM
Network
- - Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Designinvento DirectoryPress directorypress allows Retrieve Embedded Sensitive Data.This issue affects Dire… CWE-497
 Exposure of Sensitive System Information to an Unauthorized Control Sphere
CVE-2026-39566 2026-04-15 03:17 2026-04-8 Show GitHub Exploit DB Packet Storm
2680 5.4 MEDIUM
Network
adobe experience_manager Adobe Experience Manager versions FP11.4 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts in… CWE-79
Cross-site Scripting
CVE-2025-49547 2026-04-15 03:16 2025-07-9 Show GitHub Exploit DB Packet Storm