Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
224061 8.5 危険 WordPress.org - WordPress MU および WordPress の wp-admin/options.php における任意のコードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2008-5695 2012-12-20 19:10 2008-12-19 Show GitHub Exploit DB Packet Storm
224062 10 危険 sandbox - Sandbox の lib/jpgraph/jpgraph_errhandler.inc.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2008-5694 2012-12-20 19:10 2008-12-19 Show GitHub Exploit DB Packet Storm
224063 6.5 警告 phparanoid - PHParanoid における脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-5673 2012-12-20 19:10 2008-12-18 Show GitHub Exploit DB Packet Storm
224064 6.8 警告 phparanoid - PHParanoid におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2008-5672 2012-12-20 19:10 2008-12-18 Show GitHub Exploit DB Packet Storm
224065 6.8 警告 Textpattern - Textpattern におけるセッションのハイジャック後パスワードを変更される脆弱性 CWE-255
証明書・パスワード管理
CVE-2008-5670 2012-12-20 19:10 2008-12-18 Show GitHub Exploit DB Packet Storm
224066 5 警告 Textpattern - Textpattern のコメントプレビューセクションにおけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2008-5669 2012-12-20 19:10 2008-12-18 Show GitHub Exploit DB Packet Storm
224067 4.3 警告 Textpattern - Textpattern におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-5668 2012-12-20 19:10 2008-12-18 Show GitHub Exploit DB Packet Storm
224068 5 警告 VirusBlokAda Ltd. - VirusBlokAda VBA32 Personal Antivirus のスキャンエンジンにおけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2008-5667 2012-12-20 19:10 2008-12-18 Show GitHub Exploit DB Packet Storm
224069 3.5 注意 WING FTP software - WinFTP FTP Server におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2008-5666 2012-12-20 18:52 2008-12-18 Show GitHub Exploit DB Packet Storm
224070 7.5 危険 XOOPS - XOOPS の xhresim モジュールにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-5665 2012-12-20 18:52 2008-12-18 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 20, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1331 5.5 MEDIUM
Local
mcafee netschedscan NetSchedScan 1.0 contains a buffer overflow vulnerability in the scan Hostname/IP field that allows local attackers to crash the application by supplying an oversized input string. Attackers can past… CWE-787
 Out-of-bounds Write
CVE-2016-20050 2026-04-15 04:03 2026-04-4 Show GitHub Exploit DB Packet Storm
1332 6.1 MEDIUM
Network
electronjs electron Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From versions 39.0.0-alpha.1 to before 39.8.0, 40.0.0-alpha.1 to before 40.7.0, and 41.0.0-alph… CWE-668
CWE-1188
 Exposure of Resource to Wrong Sphere
 Insecure Default Initialization of Resource
CVE-2026-34780 2026-04-15 04:02 2026-04-4 Show GitHub Exploit DB Packet Storm
1333 9.1 CRITICAL
Network
adobe commerce
commerce_b2b
magento
Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attacker can abuse this … CWE-20
 Improper Input Validation 
CVE-2025-54236 2026-04-15 04:00 2025-09-9 Show GitHub Exploit DB Packet Storm
1334 10.0 CRITICAL
Network
praison praisonai PraisonAI is a multi-agent teams system. Prior to version 4.5.97, SubprocessSandbox in all modes (BASIC, STRICT, NETWORK_ISOLATED) calls subprocess.run() with shell=True and relies solely on string-p… CWE-78
OS Command 
CVE-2026-34955 2026-04-15 03:56 2026-04-4 Show GitHub Exploit DB Packet Storm
1335 7.8 HIGH
Local
electronjs electron Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, on macOS, app.moveToApplicationsFo… CWE-78
OS Command 
CVE-2026-34779 2026-04-15 03:55 2026-04-4 Show GitHub Exploit DB Packet Storm
1336 5.4 MEDIUM
Network
opensourcepos open_source_point_of_sale Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Prior to 3.4.3, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Daily Sa… CWE-79
Cross-site Scripting
CVE-2026-32712 2026-04-15 03:45 2026-04-8 Show GitHub Exploit DB Packet Storm
1337 7.5 HIGH
Network
opentelemetry opentelemetry OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each header field-value independently and aggregates members across va… CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2026-29181 2026-04-15 03:45 2026-04-8 Show GitHub Exploit DB Packet Storm
1338 4.3 MEDIUM
Network
plane plane Plane is an an open-source project management tool. Prior to 1.3.0, a vulnerability was identified in Plane's authentication flow where a user's email address is included as a query parameter in the … CWE-200
CWE-598
NVD-CWE-noinfo
Information Exposure
Information Exposure Through Query Strings in GET Request 
CVE-2026-27949 2026-04-15 03:44 2026-04-8 Show GitHub Exploit DB Packet Storm
1339 8.8 HIGH
Network
polarlearn polarlearn PolarLearn is a free and open-source learning program. In 0-PRERELEASE-15 and earlier, POST /api/v1/auth/sign-in creates a valid session for banned accounts before verifying the supplied password. Th… CWE-287
Improper Authentication
CVE-2026-39322 2026-04-15 03:44 2026-04-8 Show GitHub Exploit DB Packet Storm
1340 5.1 MEDIUM
Local
ocaml ocaml In OCaml through 4.14.3, Bigarray.reshape allows an integer overflow, and resultant reading of arbitrary memory, when untrusted data is processed. CWE-190
 Integer Overflow or Wraparound
CVE-2026-34353 2026-04-15 03:43 2026-03-27 Show GitHub Exploit DB Packet Storm