Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
224141 10 危険 south river technologies - Titan FTP Server におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-5281 2012-12-20 18:52 2008-11-28 Show GitHub Exploit DB Packet Storm
224142 5 警告 zilab - ZIM Server の Local ZIM Server におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2008-5280 2012-12-20 18:52 2008-11-28 Show GitHub Exploit DB Packet Storm
224143 10 危険 zilab - ZIP Server の Local ZIM Server における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2008-5279 2012-12-20 18:52 2008-11-28 Show GitHub Exploit DB Packet Storm
224144 4.3 警告 PowerDNS - PowerDNS におけるサービス運用妨害 (DoS) の脆弱性 CWE-16
環境設定
CVE-2008-5277 2012-12-20 18:52 2008-11-18 Show GitHub Exploit DB Packet Storm
224145 5 警告 toddwoolums - Todd Woolums ASP News Management におけるニュース項目を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-5274 2012-12-20 18:52 2008-11-28 Show GitHub Exploit DB Packet Storm
224146 7.5 危険 Powie - pSys の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-5269 2012-12-20 18:52 2008-11-28 Show GitHub Exploit DB Packet Storm
224147 6.8 警告 tntforum - TNT Forum の index.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-5265 2012-12-20 18:52 2008-11-28 Show GitHub Exploit DB Packet Storm
224148 4.3 警告 tornado - Tornado Knowledge Retrieval System の searcher.exe におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-5264 2012-12-20 18:52 2008-11-28 Show GitHub Exploit DB Packet Storm
224149 4.4 警告 virtualox - Sun Innotek VirtualBox の ipcdUnix.cpp における任意のファイルを上書きされる脆弱性 CWE-59
リンク解釈の問題
CVE-2008-5256 2012-12-20 18:52 2008-11-26 Show GitHub Exploit DB Packet Storm
224150 4.3 警告 Xine - xine-lib におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2008-5248 2012-12-20 18:52 2008-11-25 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 21, 2026, 4:10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1311 8.8 HIGH
Network
apache storm Deserialization of Untrusted Data vulnerability in Apache Storm. Versions Affected: before 2.8.6. Description: When processing topology credentials submitted via the Nimbus Thrift API, Storm deser… CWE-502
 Deserialization of Untrusted Data
CVE-2026-35337 2026-04-16 00:54 2026-04-13 Show GitHub Exploit DB Packet Storm
1312 5.4 MEDIUM
Network
apache storm Stored Cross-Site Scripting (XSS) via Unsanitized Topology Metadata in Apache Storm UI Versions Affected: before 2.8.6 Description: The Storm UI visualization component interpolates topology meta… CWE-79
Cross-site Scripting
CVE-2026-35565 2026-04-16 00:53 2026-04-13 Show GitHub Exploit DB Packet Storm
1313 4.3 MEDIUM
Network
apache openmeetings Improper Handling of Insufficient Privileges vulnerability in Apache OpenMeetings. Any registered user can query web service with their credentials and get files/sub-folders of any folder by ID (met… CWE-274
 Improper Handling of Insufficient Privileges
CVE-2026-33005 2026-04-16 00:27 2026-04-10 Show GitHub Exploit DB Packet Storm
1314 7.5 HIGH
Network
apache openmeetings Use of Hard-coded Cryptographic Key vulnerability in Apache OpenMeetings. The remember-me cookie encryption key is set to default value in openmeetings.properties and not being auto-rotated. In case… CWE-321
 Use of Hard-coded Cryptographic Key
CVE-2026-33266 2026-04-16 00:21 2026-04-10 Show GitHub Exploit DB Packet Storm
1315 7.5 HIGH
Network
apache openmeetings Use of GET Request Method With Sensitive Query Strings vulnerability in Apache OpenMeetings. The REST login endpoint uses HTTP GET method with username and password passed as query parameters. Pleas… CWE-598
Information Exposure Through Query Strings in GET Request 
CVE-2026-34020 2026-04-16 00:21 2026-04-10 Show GitHub Exploit DB Packet Storm
1316 6.5 MEDIUM
Network
- - The YML for Yandex Market WordPress plugin before 5.0.26 is vulnerable to Remote Code Execution via the feed generation process. - CVE-2025-14545 2026-04-16 00:05 2026-04-10 Show GitHub Exploit DB Packet Storm
1317 6.5 MEDIUM
Network
- - The YITH WooCommerce Wishlist WordPress plugin before 4.13.0 does not properly validate wishlist ownership in the save_title() AJAX handler before allowing wishlist renaming operations. The function … - CVE-2026-4432 2026-04-16 00:05 2026-04-10 Show GitHub Exploit DB Packet Storm
1318 6.8 MEDIUM
Network
- - The Form Maker by 10Web WordPress plugin before 1.15.38 does not properly prepare SQL queries when the "MySQL Mapping" feature is in use, which could make SQL Injection attacks possible in certain c… CWE-89
SQL Injection
CVE-2025-15441 2026-04-16 00:05 2026-04-13 Show GitHub Exploit DB Packet Storm
1319 8.6 HIGH
Network
- - The Product Filter for WooCommerce by WBW WordPress plugin before 3.1.3 does not sanitize and escape a parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL inje… CWE-89
SQL Injection
CVE-2026-3830 2026-04-16 00:05 2026-04-13 Show GitHub Exploit DB Packet Storm
1320 9.1 CRITICAL
Network
- - V2Board 1.6.1 through 1.7.4 and Xboard through 0.1.9 expose authentication tokens in HTTP response bodies of the loginWithMailLink endpoint when the login_with_mail_link_enable feature is active. Una… CWE-201
 Insertion of Sensitive Information Into Sent Data
CVE-2026-39912 2026-04-16 00:00 2026-04-10 Show GitHub Exploit DB Packet Storm