Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
223751 6.8 警告 phpmotion - PHPmotion の password.php におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2008-6729 2012-12-20 19:10 2009-04-20 Show GitHub Exploit DB Packet Storm
223752 7.5 危険 PHPNUKE - PHP-Nuke の Sections モジュールにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6728 2012-12-20 19:10 2009-04-20 Show GitHub Exploit DB Packet Storm
223753 7.5 危険 turnkeyforms - TurnkeyForms Entertainment Portal における認証を回避される脆弱性 CWE-287
不適切な認証
CVE-2008-6723 2012-12-20 19:10 2009-04-14 Show GitHub Exploit DB Packet Storm
223754 7.5 危険 uochm - U&M Software Event Lister における脆弱性 CWE-287
不適切な認証
CVE-2008-6719 2012-12-20 19:10 2009-04-13 Show GitHub Exploit DB Packet Storm
223755 7.5 危険 uochm - U&M Software JustBookIt における脆弱性 CWE-287
不適切な認証
CVE-2008-6718 2012-12-20 19:10 2009-04-13 Show GitHub Exploit DB Packet Storm
223756 7.5 危険 uochm - U&M Software Signup における脆弱性 CWE-287
不適切な認証
CVE-2008-6717 2012-12-20 19:10 2009-04-13 Show GitHub Exploit DB Packet Storm
223757 7.5 危険 PreProject.com - Pre ADS Portal の homeadmin/adminhome.php における脆弱性 CWE-287
不適切な認証
CVE-2008-6716 2012-12-20 19:10 2009-04-13 Show GitHub Exploit DB Packet Storm
223758 4.3 警告 PreProject.com - Pre ADS Portal におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-6715 2012-12-20 19:10 2009-04-13 Show GitHub Exploit DB Packet Storm
223759 7.5 危険 xecms - xeCMS の admin.php における認証を回避される脆弱性 CWE-287
不適切な認証
CVE-2008-6714 2012-12-20 19:10 2009-04-10 Show GitHub Exploit DB Packet Storm
223760 5 警告 stalker-game - S.T.A.L.K.E.R.: Shadow of Chernobyl の MultipacketReciever::RecievePacket 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2008-6705 2012-12-20 19:10 2009-04-10 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 19, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1461 7.8 HIGH
Local
lfprojects mlflow A command injection vulnerability exists in mlflow/mlflow when serving a model with `enable_mlserver=True`. The `model_uri` is embedded directly into a shell command executed via `bash -c` without pr… CWE-78
OS Command 
CVE-2026-0596 2026-04-15 01:01 2026-04-1 Show GitHub Exploit DB Packet Storm
1462 8.8 HIGH
Network
ajax30 bravecms Brave CMS is an open-source CMS. Prior to 2.0.6, an unrestricted file upload vulnerability exists in the CKEditor upload functionality. It is found in app/Http/Controllers/Dashboard/CkEditorControlle… CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2026-35164 2026-04-15 00:51 2026-04-7 Show GitHub Exploit DB Packet Storm
1463 8.8 HIGH
Network
ajax30 bravecms Brave CMS is an open-source CMS. Prior to 2.0.6, this vulnerability is a missing authorization check found in the update role endpoint at routes/web.php. The POST route for /rights/update-role/{id} l… CWE-862
 Missing Authorization
CVE-2026-35182 2026-04-15 00:50 2026-04-7 Show GitHub Exploit DB Packet Storm
1464 5.4 MEDIUM
Network
ajax30 bravecms Brave CMS is an open-source CMS. Prior to 2.0.6, an Insecure Direct Object Reference (IDOR) vulnerability exists in the article image deletion feature. It is located in app/Http/Controllers/Dashboard… CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-35183 2026-04-15 00:50 2026-04-7 Show GitHub Exploit DB Packet Storm
1465 7.8 HIGH
Local
tokfinity infcode InfCode's terminal auto-execution module contains a critical command filtering vulnerability that renders its blacklist security mechanism completely ineffective. The predefined blocklist fails to co… CWE-78
OS Command 
CVE-2026-30309 2026-04-15 00:49 2026-04-1 Show GitHub Exploit DB Packet Storm
1466 7.5 HIGH
Network
openairinterface oai-cn5g-amf OpenAirInterface Version 2.2.0 has a Buffer Overflow vulnerability in processing UplinkNASTransport containing Authentication Response containing a NAS PDU with oversize response (For example 100 byt… CWE-120
Classic Buffer Overflow
CVE-2026-30075 2026-04-15 00:47 2026-04-9 Show GitHub Exploit DB Packet Storm
1467 7.5 HIGH
Network
openairinterface oai-cn5g-amf OpenAirInterface v2.2.0 accepts Security Mode Complete without any integrity protection. Configuration has supported integrity NIA1 and NIA2. But if an UE sends initial registration request with only… CWE-294
Authentication Bypass by Capture-replay 
CVE-2026-30080 2026-04-15 00:47 2026-04-9 Show GitHub Exploit DB Packet Storm
1468 9.1 CRITICAL
Network
frappe erpnext
frappe
A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frappe Framework v16.1.1, where user-supplied HTML is insufficiently sanitized befor… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-31017 2026-04-15 00:46 2026-04-9 Show GitHub Exploit DB Packet Storm
1469 6.1 MEDIUM
Network
kantorge yaffa yaffa v2.0.0 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript into the "Add Account Group" function on the account-group page, allowing execution of arbitrary … CWE-94
Code Injection
CVE-2025-70844 2026-04-15 00:46 2026-04-8 Show GitHub Exploit DB Packet Storm
1470 9.8 CRITICAL
Network
openairinterface oai-cn5g-amf In OpenAirInterface V2.2.0 AMF, Out of sequence messages causes incorrect state transition during UE registration procedure. This allows authentication to be bypassed completely. If a SecurityModeCom… CWE-288
Authentication Bypass Using an Alternate Path or Channel
CVE-2026-30079 2026-04-15 00:45 2026-04-8 Show GitHub Exploit DB Packet Storm