Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
223821 4.3 警告 PrestaShop - PrestaShop におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-6503 2012-12-20 19:10 2009-03-20 Show GitHub Exploit DB Packet Storm
223822 4.6 警告 Pro Chat Rooms - Pro Chat Rooms におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-6502 2012-12-20 19:10 2009-03-20 Show GitHub Exploit DB Packet Storm
223823 4.3 警告 Pro Chat Rooms - Pro Chat Rooms の profiles/index.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-6501 2012-12-20 19:10 2009-03-20 Show GitHub Exploit DB Packet Storm
223824 7.8 危険 tp - Neostrada Livebox ADSL ルータにおけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2008-6497 2012-12-20 19:10 2009-03-19 Show GitHub Exploit DB Packet Storm
223825 8.8 危険 visagesoft - VISAGESOFT eXPert PDF EditorX の VSPDFEditorX.VSPDFEdit ActiveX コントロールにおける任意のファイルを作成される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-6496 2012-12-20 19:10 2009-03-19 Show GitHub Exploit DB Packet Storm
223826 4.3 警告 zirkon box - Fritz Berger yappa-ng の index.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-6495 2012-12-20 19:10 2009-03-19 Show GitHub Exploit DB Packet Storm
223827 5 警告 robs-projects - ASP User Engine.NET におけるデータベースをダウンロードされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-6494 2012-12-20 19:10 2009-03-19 Show GitHub Exploit DB Packet Storm
223828 6.8 警告 tizag - Tizag Countdown Creator の process.php における任意のコードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2008-6492 2012-12-20 19:10 2009-03-19 Show GitHub Exploit DB Packet Storm
223829 7.5 危険 softcomplex - SoftComplex PHP Image Gallery の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-6488 2012-12-20 19:10 2009-03-18 Show GitHub Exploit DB Packet Storm
223830 6.8 警告 shatm - SharedLog の slideshow_uploadvideo.content.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2008-6486 2012-12-20 19:10 2009-03-18 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 20, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1161 9.3 CRITICAL
Network
- - Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Ex… CWE-502
 Deserialization of Untrusted Data
CVE-2026-34615 2026-04-16 01:14 2026-04-15 Show GitHub Exploit DB Packet Storm
1162 8.7 HIGH
Network
- - Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Cross-Site Scripting (XSS) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vul… CWE-79
Cross-site Scripting
CVE-2026-34617 2026-04-16 01:14 2026-04-15 Show GitHub Exploit DB Packet Storm
1163 9.8 CRITICAL
Network
cryptography.io cryptography cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Pyth… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2026-39892 2026-04-16 01:12 2026-04-9 Show GitHub Exploit DB Packet Storm
1164 8.4 HIGH
Local
nixos nix Nix is a package manager for Linux and other Unix systems. A bug in the fix for CVE-2024-27297 allowed for arbitrary overwrites of files writable by the Nix process orchestrating the builds (typicall… CWE-61
 UNIX Symbolic Link (Symlink) Following
CVE-2026-39860 2026-04-16 01:12 2026-04-9 Show GitHub Exploit DB Packet Storm
1165 4.9 MEDIUM
Network
kamailio kamailio Kamailio is an open source implementation of a SIP Signaling Server. Prior to 6.0.5 and 5.8.7, an out-of-bounds read in the auth module of Kamailio (formerly OpenSER and SER) allows remote attackers … CWE-125
Out-of-bounds Read
CVE-2026-39864 2026-04-16 01:06 2026-04-9 Show GitHub Exploit DB Packet Storm
1166 6.5 MEDIUM
Network
openclaw openclaw OpenClaw before 2026.3.22 contains an information disclosure vulnerability that allows attackers with operator.read scope to expose credentials embedded in channel baseUrl and httpUrl fields. Attacke… CWE-312
 Cleartext Storage of Sensitive Information
CVE-2026-35644 2026-04-16 01:03 2026-04-10 Show GitHub Exploit DB Packet Storm
1167 7.5 HIGH
Network
kamailio kamailio Kamailio is an open source implementation of a SIP Signaling Server. Prior to 6.1.1, 6.0.6, and 5.8.8, an out-of-bounds access in the core of Kamailio (formerly OpenSER and SER) allows remote attacke… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2026-39863 2026-04-16 00:58 2026-04-9 Show GitHub Exploit DB Packet Storm
1168 8.8 HIGH
Network
apache storm Deserialization of Untrusted Data vulnerability in Apache Storm. Versions Affected: before 2.8.6. Description: When processing topology credentials submitted via the Nimbus Thrift API, Storm deser… CWE-502
 Deserialization of Untrusted Data
CVE-2026-35337 2026-04-16 00:54 2026-04-13 Show GitHub Exploit DB Packet Storm
1169 5.4 MEDIUM
Network
apache storm Stored Cross-Site Scripting (XSS) via Unsanitized Topology Metadata in Apache Storm UI Versions Affected: before 2.8.6 Description: The Storm UI visualization component interpolates topology meta… CWE-79
Cross-site Scripting
CVE-2026-35565 2026-04-16 00:53 2026-04-13 Show GitHub Exploit DB Packet Storm
1170 4.3 MEDIUM
Network
apache openmeetings Improper Handling of Insufficient Privileges vulnerability in Apache OpenMeetings. Any registered user can query web service with their credentials and get files/sub-folders of any folder by ID (met… CWE-274
 Improper Handling of Insufficient Privileges
CVE-2026-33005 2026-04-16 00:27 2026-04-10 Show GitHub Exploit DB Packet Storm