Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
224581 7.5 危険 viart - ViArt Shop の products_rss.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3369 2012-12-20 18:52 2008-07-30 Show GitHub Exploit DB Packet Storm
224582 4.3 警告 webwizguide - Web Wiz RTE の RTE_popup_link.asp におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-3367 2012-12-20 18:52 2008-07-30 Show GitHub Exploit DB Packet Storm
224583 7.5 危険 Pligg - Pligg CMS の story.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3366 2012-12-20 18:52 2008-07-30 Show GitHub Exploit DB Packet Storm
224584 6.8 警告 Pixelpost.org - Windows 上で稼動する Pixelpost の index.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-3365 2012-12-20 18:52 2008-07-27 Show GitHub Exploit DB Packet Storm
224585 9.3 危険 トレンドマイクロ - Trend Micro OSCE Web-Deployment などの ObjRemoveCtrl Class ActiveX コントロールにおけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-3364 2012-12-20 18:52 2008-07-30 Show GitHub Exploit DB Packet Storm
224586 7.5 危険 runcms - RunCMS の Newbb Plus モジュールにおける PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2008-3354 2012-12-20 18:52 2008-07-28 Show GitHub Exploit DB Packet Storm
224587 4.3 警告 puresw - Pure Software Lore におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-3353 2012-12-20 18:52 2008-07-28 Show GitHub Exploit DB Packet Storm
224588 5 警告 thekelleys - dnsmasq におけるサービス運用妨害 (DoS) の脆弱性 CWE-DesignError
CVE-2008-3350 2012-12-20 18:52 2008-07-28 Show GitHub Exploit DB Packet Storm
224589 10 危険 TIBCO Software - TIBCO Hawk AMI C library および Hawk HMA におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-3338 2012-12-20 18:52 2008-08-13 Show GitHub Exploit DB Packet Storm
224590 6.4 警告 PowerDNS - PowerDNS Authoritative Server における DNS を偽装される脆弱性 CWE-20
不適切な入力確認
CVE-2008-3337 2012-12-20 18:52 2008-08-6 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 25, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
2311 9.8 CRITICAL
Network
chamilo chamilo_lms Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, the default password reset mechanism generates tokens using sha1($email) with no random component, no expiration, and no … CWE-640
 Weak Password Recovery Mechanism for Forgotten Password
CVE-2026-33707 2026-04-17 03:25 2026-04-11 Show GitHub Exploit DB Packet Storm
2312 6.5 MEDIUM
Network
chamilo chamilo_lms Chamilo LMS is a learning management system. Prior to 1.11.38, the get_user_info_from_username REST API endpoint returns personal information (email, first name, last name, user ID, active status) of… CWE-862
 Missing Authorization
CVE-2026-33708 2026-04-17 03:25 2026-04-11 Show GitHub Exploit DB Packet Storm
2313 7.5 HIGH
Network
chamilo chamilo_lms Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, REST API keys are generated using md5(time() + (user_id * 5) - rand(10000, 10000)). The rand(10000, 10000) call always re… CWE-330
 Use of Insufficiently Random Values
CVE-2026-33710 2026-04-17 03:24 2026-04-11 Show GitHub Exploit DB Packet Storm
2314 6.5 MEDIUM
Network
chamilo chamilo_lms Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, any authenticated user (including ROLE_STUDENT) can enumerate all platform users and access personal information (email, phone, roles… CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-33736 2026-04-17 03:23 2026-04-11 Show GitHub Exploit DB Packet Storm
2315 6.5 MEDIUM
Network
chamilo chamilo_lms Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, multiple files use simplexml_load_string() without XXE protection. With LIBXML_NOENT flag, arbitrary server files can be … CWE-611
XXE
CVE-2026-33737 2026-04-17 03:22 2026-04-11 Show GitHub Exploit DB Packet Storm
2316 6.8 MEDIUM
Physics
samsung android Improper input validation in data related to network restrictions prior to SMR Apr-2026 Release 1 allows physical attackers to bypass the restrictions. NVD-CWE-noinfo
CVE-2026-21003 2026-04-17 02:25 2026-04-13 Show GitHub Exploit DB Packet Storm
2317 5.5 MEDIUM
Local
samsung galaxy_wearable Incorrect default permission in Galaxy Wearable prior to version 2.2.68.26 allows local attackers to access sensitive information. CWE-276
Incorrect Default Permissions 
CVE-2026-21013 2026-04-17 02:24 2026-04-13 Show GitHub Exploit DB Packet Storm
2318 2.8 LOW
Local
samsung camera Improper access control in Samsung Camera prior to version 16.5.00.28 allows local attacker to access location data. User interaction is required for triggering this vulnerability. NVD-CWE-noinfo
CVE-2026-21014 2026-04-17 02:23 2026-04-13 Show GitHub Exploit DB Packet Storm
2319 8.5 HIGH
Network
gitlab gitlab GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.9.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user to invoke u… CWE-749
 Exposed Dangerous Method or Function
CVE-2026-5173 2026-04-17 01:44 2026-04-9 Show GitHub Exploit DB Packet Storm
2320 8.8 HIGH
Network
google chrome Use after free in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) CWE-416
 Use After Free
CVE-2026-5883 2026-04-17 01:36 2026-04-9 Show GitHub Exploit DB Packet Storm