Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
224111 7.5 危険 slimcms - SlimCMS の edit.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-5491 2012-12-20 18:52 2008-12-12 Show GitHub Exploit DB Packet Storm
224112 7.5 危険 phpstore - PHPStore Yahoo Answers の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-5490 2012-12-20 18:52 2008-12-12 Show GitHub Exploit DB Packet Storm
224113 4.3 警告 turnkeyforms - TurnkeyForms Text Link Sales の admin.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-5487 2012-12-20 18:52 2008-12-12 Show GitHub Exploit DB Packet Storm
224114 7.5 危険 turnkeyforms - TurnkeyForms Text Link Sales の admin.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-5486 2012-12-20 18:52 2008-12-12 Show GitHub Exploit DB Packet Storm
224115 4.3 警告 PunBB - PunBB の moderate.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-5435 2012-12-20 18:52 2008-12-11 Show GitHub Exploit DB Packet Storm
224116 6.5 警告 PunBB - PunBB における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-5434 2012-12-20 18:52 2008-12-11 Show GitHub Exploit DB Packet Storm
224117 4.3 警告 PunBB - PunBB の login.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-5433 2012-12-20 18:52 2008-12-11 Show GitHub Exploit DB Packet Storm
224118 4.3 警告 シマンテック - Norton Internet Security の Norton Antivirus におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2008-5427 2012-12-20 18:52 2008-12-11 Show GitHub Exploit DB Packet Storm
224119 4.3 警告 サン・マイクロシステムズ - Sun Sun Ray Server Software などにおける Sun Ray 管理者パスワードを特定される脆弱性 CWE-200
情報漏えい
CVE-2008-5423 2012-12-20 18:52 2008-12-4 Show GitHub Exploit DB Packet Storm
224120 7.5 危険 サン・マイクロシステムズ - Sun Sun Ray Server Software における Sun Ray 管理者パスワードを特定される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-5422 2012-12-20 18:52 2008-12-4 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 18, 2026, 4:11 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1721 5.3 MEDIUM
Network
sillytavern sillytavern SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to version… CWE-22
Path Traversal
CVE-2026-34523 2026-04-14 03:35 2026-04-3 Show GitHub Exploit DB Packet Storm
1722 8.1 HIGH
Network
sillytavern sillytavern SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to version… CWE-22
CWE-73
Path Traversal
 External Control of File Name or Path
CVE-2026-34522 2026-04-14 03:34 2026-04-3 Show GitHub Exploit DB Packet Storm
1723 9.8 CRITICAL
Network
microsoft bing Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to elevate privileges over a network. CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-32186 2026-04-14 03:32 2026-04-4 Show GitHub Exploit DB Packet Storm
1724 9.8 CRITICAL
Network
cloudreve cloudreve Cloudreve is a self-hosted file management and sharing system. Prior to version 4.13.0, the application uses the weak pseudo-random number generator math/rand seeded with time.Now().UnixNano() to gen… CWE-338
 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
CVE-2026-25726 2026-04-14 03:31 2026-04-4 Show GitHub Exploit DB Packet Storm
1725 10.0 CRITICAL
Network
zimaspace zimaos ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. Prior to version 1.5.3, a proxy endpoint (/v1/sys/proxy) exposed by ZimaOS's web interface can be abused… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-28798 2026-04-14 03:27 2026-04-4 Show GitHub Exploit DB Packet Storm
1726 8.1 HIGH
Network
fka prompts.chat prompts.chat prior to commit 0f8d4c3 contains a path traversal vulnerability in skill file handling that allows attackers to write arbitrary files to the client system by crafting malicious ZIP archi… CWE-22
Path Traversal
CVE-2026-22661 2026-04-14 03:23 2026-04-4 Show GitHub Exploit DB Packet Storm
1727 7.7 HIGH
Network
elastic kibana Execution with Unnecessary Privileges (CWE-250) in Kibana’s Fleet plugin debug route handlers can lead reading index data beyond their direct Elasticsearch RBAC scope via Privilege Abuse (CAPEC-122).… CWE-250
 Execution with Unnecessary Privileges
CVE-2026-4498 2026-04-14 03:22 2026-04-9 Show GitHub Exploit DB Packet Storm
1728 6.5 MEDIUM
Network
elastic kibana Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with access to the automatic import feature can submit … CWE-400
 Uncontrolled Resource Consumption
CVE-2026-33459 2026-04-14 03:21 2026-04-9 Show GitHub Exploit DB Packet Storm
1729 5.5 MEDIUM
Local
dell elastic_cloud_storage
objectscale
Dell Elastic Cloud Storage, version 3.8.1.7 and prior, and Dell ObjectScale, versions prior to 4.1.0.3 and version 4.2.0.0, contains an Insertion of Sensitive Information into Log File vulnerability.… CWE-532
 Inclusion of Sensitive Information in Log Files
CVE-2026-28261 2026-04-14 03:20 2026-04-8 Show GitHub Exploit DB Packet Storm
1730 6.5 MEDIUM
Network
google chrome Insufficient validation of untrusted input in WebSockets in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a … CWE-20
 Improper Input Validation 
CVE-2026-5919 2026-04-14 03:19 2026-04-9 Show GitHub Exploit DB Packet Storm