Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
224681 7.5 危険 TYPO3 Association - TYPO3 用の DAM Frontend エクステンションにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3039 2012-12-20 18:52 2008-07-7 Show GitHub Exploit DB Packet Storm
224682 7.5 危険 TYPO3 Association - TYPO3 用の Address Directory エクステンションにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3038 2012-12-20 18:52 2008-07-7 Show GitHub Exploit DB Packet Storm
224683 4.3 警告 TYPO3 Association - TYPO3 用の Address Directory エクステンションにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-3037 2012-12-20 18:52 2008-07-7 Show GitHub Exploit DB Packet Storm
224684 6.5 警告 xchangeboard - XchangeBoard の newThread.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3035 2012-12-20 18:52 2008-07-7 Show GitHub Exploit DB Packet Storm
224685 7.5 危険 rss aggregator - RSS-aggregator における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3034 2012-12-20 18:52 2008-07-7 Show GitHub Exploit DB Packet Storm
224686 9.3 危険 rss aggregator - RSS-aggregator における admin 関数へアクセスされ脆弱性 CWE-287
不適切な認証
CVE-2008-3033 2012-12-20 18:52 2008-07-7 Show GitHub Exploit DB Packet Storm
224687 4.3 警告 The phpMyAdmin Project - TYPO3 用の phpMyAdmin エクステンションにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-3032 2012-12-20 18:52 2008-07-7 Show GitHub Exploit DB Packet Storm
224688 7.5 危険 Thomas Abeel - Simple PHP Agenda の index.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-3031 2012-12-20 18:52 2008-07-7 Show GitHub Exploit DB Packet Storm
224689 4.3 警告 Web-Empowered Church Team - TYPO3 用の WEC Discussion Forum エクステンションにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-3029 2012-12-20 18:52 2008-07-7 Show GitHub Exploit DB Packet Storm
224690 4.3 警告 TYPO3 Association - TYPO3 用の Send-A-Card エクステンションにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-3028 2012-12-20 18:52 2008-07-7 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 25, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
321 - - - Mako is a template library written in Python. Prior to 1.3.11, TemplateLookup.get_template() is vulnerable to path traversal when a URI starts with // (e.g., //../../../secret.txt). The root cause is… New CWE-22
Path Traversal
CVE-2026-41205 2026-04-24 23:50 2026-04-24 Show GitHub Exploit DB Packet Storm
322 5.9 MEDIUM
Network
- - @node-oauth/oauth2-server is a module for implementing an OAuth2 server in Node.js. The token exchange path accepts RFC7636-invalid code_verifier values (including one-character strings) for S256 PKC… New CWE-307
CWE-1289
mproper Restriction of Excessive Authentication Attempts
 Improper Validation of Unsafe Equivalence in Input
CVE-2026-41213 2026-04-24 23:50 2026-04-24 Show GitHub Exploit DB Packet Storm
323 8.7 HIGH
Network
- - pretalx is a conference planning tool. Prior to 2026.1.0, The organiser search in the pretalx backend rendered submission titles, speaker display names, and user names/emails into the result dropdown… New CWE-79
Cross-site Scripting
CVE-2026-41241 2026-04-24 23:50 2026-04-24 Show GitHub Exploit DB Packet Storm
324 - - - elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.67, elFinder contains a command injection vulnerability in the resize command. The bg (background … New CWE-78
OS Command 
CVE-2026-41247 2026-04-24 23:50 2026-04-24 Show GitHub Exploit DB Packet Storm
325 - - - Mastodon is a free, open-source social network server based on ActivityPub. Prior to v4.5.9, v4.4.16, and v4.3.22, Mastodon allows restricting new user sign-up based on e-mail domain names, and perfo… New CWE-841
 Improper Enforcement of Behavioral Workflow
CVE-2026-41259 2026-04-24 23:50 2026-04-24 Show GitHub Exploit DB Packet Storm
326 - - - A path traversal condition in Intrado 911 Emergency Gateway could allow an attacker with existing network access the ability to access the EGW management interface without authentication. Successful … New CWE-35
 Path Traversal: '.../...//'
CVE-2026-6074 2026-04-24 23:50 2026-04-24 Show GitHub Exploit DB Packet Storm
327 8.1 HIGH
Network
- - Contour is a Kubernetes ingress controller using Envoy proxy. From v1.19.0 to before v1.33.4, v1.32.5, and v1.31.6, Contour's Cookie Rewriting feature is vulnerable to Lua code injection. An attacker… New CWE-94
Code Injection
CVE-2026-41246 2026-04-24 23:50 2026-04-24 Show GitHub Exploit DB Packet Storm
328 - - - LeRobot through 0.5.1 contains an unsafe deserialization vulnerability in the async inference pipeline where pickle.loads() is used to deserialize data received over unauthenticated gRPC channels wit… New CWE-502
 Deserialization of Untrusted Data
CVE-2026-25874 2026-04-24 23:50 2026-04-24 Show GitHub Exploit DB Packet Storm
329 6.8 MEDIUM
Network
- - SWUpdate contains an integer underflow vulnerability in the multipart upload parser in mongoose_multipart.c that allows unauthenticated attackers to cause a denial of service by sending a crafted HTT… New CWE-125
CWE-191
Out-of-bounds Read
 Integer Underflow (Wrap or Wraparound)
CVE-2026-28525 2026-04-24 23:50 2026-04-24 Show GitHub Exploit DB Packet Storm
330 - - - A vulnerability in SpiceJet’s booking API allows unauthenticated users to query passenger name records (PNRs) without any access controls. Because PNR identifiers follow a predictable pattern, an att… New CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-6375 2026-04-24 23:50 2026-04-24 Show GitHub Exploit DB Packet Storm