Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
223731 7.5 危険 PHPNUKE - PHP-Nuke 用の Sarkilar モジュールにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6779 2012-12-20 19:10 2009-05-1 Show GitHub Exploit DB Packet Storm
223732 7.5 危険 scripts-for-sites - SFS EZ Auction の viewfaqs.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6778 2012-12-20 19:10 2009-05-1 Show GitHub Exploit DB Packet Storm
223733 7.5 危険 scripts-for-sites - SFS EZ Hot or Not の viewcomments.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6776 2012-12-20 19:10 2009-05-1 Show GitHub Exploit DB Packet Storm
223734 6.8 警告 shopsystem-forum - K&S Shopsoftware の admin/editor/images.php における任意の PHP コードを実行される脆弱性 CWE-Other
その他
CVE-2008-6768 2012-12-20 19:10 2009-04-29 Show GitHub Exploit DB Packet Storm
223735 10 危険 WordPress.org - WordPress の wp-admin/upgrade.php におけるアプリケーションをアップグレードされる脆弱性 CWE-noinfo
情報不足
CVE-2008-6767 2012-12-20 19:10 2009-04-28 Show GitHub Exploit DB Packet Storm
223736 5 警告 viart - ViArt Shop の cart_save.php におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2008-6766 2012-12-20 19:10 2009-04-28 Show GitHub Exploit DB Packet Storm
223737 5 警告 viart - ViArt Shop における任意のショッピングカートの中身にアクセスされる脆弱性 CWE-noinfo
情報不足
CVE-2008-6765 2012-12-20 19:10 2009-04-28 Show GitHub Exploit DB Packet Storm
223738 4.3 警告 WordPress.org - WordPress の wp-admin/upgrade.php におけるオープンリダイレクトの脆弱性 CWE-59
リンク解釈の問題
CVE-2008-6762 2012-12-20 19:10 2009-04-28 Show GitHub Exploit DB Packet Storm
223739 4.3 警告 viart - ViArt Shop における重要な情報を取得される脆弱性 CWE-59
リンク解釈の問題
CVE-2008-6760 2012-12-20 19:10 2009-04-28 Show GitHub Exploit DB Packet Storm
223740 4.3 警告 viart - ViArt Shop における重要な情報を取得される脆弱性 CWE-59
リンク解釈の問題
CVE-2008-6759 2012-12-20 19:10 2009-04-28 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 21, 2026, 4:10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1161 8.6 HIGH
Network
adobe coldfusion ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file syste… CWE-22
Path Traversal
CVE-2026-27305 2026-04-16 23:42 2026-04-15 Show GitHub Exploit DB Packet Storm
1162 9.1 CRITICAL
Network
- - oma is a package manager for AOSC OS. Prior to 1.25.2, oma-topics is responsible for fetching metadata for testing repositories (topics) named "Topic Manifests" ({mirror}/debs/manifest/topics.json) f… CWE-93
CRLF Injection
CVE-2026-39958 2026-04-16 23:42 2026-04-10 Show GitHub Exploit DB Packet Storm
1163 3.1 LOW
Network
- - Flux notification-controller is the event forwarder and notification dispatcher for the GitOps Toolkit controllers. Prior to 1.8.3, the gcr Receiver type in Flux notification-controller does not vali… CWE-287
CWE-345
Improper Authentication
 Insufficient Verification of Data Authenticity
CVE-2026-40109 2026-04-16 23:42 2026-04-10 Show GitHub Exploit DB Packet Storm
1164 8.4 HIGH
Adjacent
adobe coldfusion ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Attacker r… CWE-20
 Improper Input Validation 
CVE-2026-27306 2026-04-16 23:41 2026-04-15 Show GitHub Exploit DB Packet Storm
1165 2.4 LOW
Adjacent
adobe coldfusion ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. A high-privileged attacker could e… CWE-400
 Uncontrolled Resource Consumption
CVE-2026-27307 2026-04-16 23:41 2026-04-15 Show GitHub Exploit DB Packet Storm
1166 2.4 LOW
Adjacent
adobe coldfusion ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. A high-privileged attacker could e… CWE-400
 Uncontrolled Resource Consumption
CVE-2026-27308 2026-04-16 23:40 2026-04-15 Show GitHub Exploit DB Packet Storm
1167 7.7 HIGH
Network
adobe coldfusion ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature… CWE-22
Path Traversal
CVE-2026-34619 2026-04-16 23:28 2026-04-15 Show GitHub Exploit DB Packet Storm
1168 5.4 MEDIUM
Network
openclaw openclaw OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in Google Chat group policy enforcement that relies on mutable space display names. Attackers can rebind group policies by cha… CWE-807
 Reliance on Untrusted Inputs in a Security Decision
CVE-2026-35617 2026-04-16 23:19 2026-04-10 Show GitHub Exploit DB Packet Storm
1169 6.5 MEDIUM
Network
openclaw openclaw OpenClaw before 2026.3.25 contains a missing rate limiting vulnerability in webhook authentication that allows attackers to brute-force weak webhook passwords without throttling. Remote attackers can… CWE-307
mproper Restriction of Excessive Authentication Attempts
CVE-2026-35623 2026-04-16 23:17 2026-04-10 Show GitHub Exploit DB Packet Storm
1170 5.3 MEDIUM
Network
- - The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference via the 'submission_id' parameter in … CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-4160 2026-04-16 23:16 2026-04-16 Show GitHub Exploit DB Packet Storm