Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
224951 4.3 警告 tru-zone - Nuke ET のプライベートメッセージ機能におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-1873 2012-12-20 18:52 2008-04-17 Show GitHub Exploit DB Packet Storm
224952 6.5 警告 scriptsagent - Scriptsagent.com Links Directory の links.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-1871 2012-12-20 18:52 2008-04-17 Show GitHub Exploit DB Packet Storm
224953 7.5 危険 site sift media - Site Sift Listings における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-1869 2012-12-20 18:52 2008-04-17 Show GitHub Exploit DB Packet Storm
224954 7.5 危険 pixel motion - Blog Pixel Motion の admin/sauvBase.php における重要な情報を含む blogPM.sql ファイルの結果を取得される脆弱性 CWE-287
不適切な認証
CVE-2008-1868 2012-12-20 18:52 2008-04-17 Show GitHub Exploit DB Packet Storm
224955 7.5 危険 pixel motion - Blog Pixel Motion における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-1867 2012-12-20 18:52 2008-04-17 Show GitHub Exploit DB Packet Storm
224956 9 危険 pixel motion - Blog Pixel Motion の admin/modif_config.php における任意の PHP スクリプトをアップロードされる脆弱性 CWE-94
コード・インジェクション
CVE-2008-1866 2012-12-20 18:52 2008-04-17 Show GitHub Exploit DB Packet Storm
224957 7.5 危険 prozilla - Prozilla Freelancers の project.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-1864 2012-12-20 18:52 2008-04-17 Show GitHub Exploit DB Packet Storm
224958 7.5 危険 prozilla - Prozilla Cheat Script の view_reviews.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-1863 2012-12-20 18:52 2008-04-17 Show GitHub Exploit DB Packet Storm
224959 5 警告 SmarterTools Inc. - SmarterMail の SmarterMail Web Server におけるサービス運用妨害 (DoS) の脆弱性 CWE-DesignError
CVE-2008-1854 2012-12-20 18:52 2008-04-16 Show GitHub Exploit DB Packet Storm
224960 4.3 警告 SAP - SAP NetWeaver のデフォルト設定におけるクロスサイトスクリプティング攻撃を実行される脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-1846 2012-12-20 18:52 2008-04-16 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 25, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1541 7.0 HIGH
Local
microsoft windows_11_26h1 Stack-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. CWE-121
Stack-based Buffer Overflow
CVE-2026-32195 2026-04-21 01:37 2026-04-15 Show GitHub Exploit DB Packet Storm
1542 8.8 HIGH
Network
dataease dataease DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the sort parameter of the /de2api/datasetData/enumValueObj en… CWE-89
SQL Injection
CVE-2026-33084 2026-04-21 01:36 2026-04-17 Show GitHub Exploit DB Packet Storm
1543 8.8 HIGH
Network
dataease dataease DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the orderDirection parameter used in dataset-related endpoint… CWE-89
SQL Injection
CVE-2026-33083 2026-04-21 01:35 2026-04-17 Show GitHub Exploit DB Packet Storm
1544 9.8 CRITICAL
Network
dataease dataease DataEase is an open source data visualization analysis tool. Versions 2.10.20 and below contain a SQL injection vulnerability in the dataset export functionality. The expressionTree parameter in POST… CWE-89
SQL Injection
CVE-2026-33082 2026-04-21 01:34 2026-04-17 Show GitHub Exploit DB Packet Storm
1545 9.1 CRITICAL
Network
- - An attacker with network access to the PLC is able to brute force discover passwords to gain unauthorized access to systems and services. The limited password complexity and no password input limiter… CWE-521
Weak Password Requirements 
CVE-2026-6284 2026-04-21 01:16 2026-04-18 Show GitHub Exploit DB Packet Storm
1546 9.8 CRITICAL
Network
- - SGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file containing a malcious tokenizer.chat_template is loaded, as the Jinja2 chat templates are rendered usin… CWE-94
Code Injection
CVE-2026-5760 2026-04-21 01:16 2026-04-20 Show GitHub Exploit DB Packet Storm
1547 5.8 MEDIUM
Local
- - In JetBrains Junie before 252.549.29 command execution was possible via malicious project file CWE-77
Command Injection
CVE-2026-41153 2026-04-21 01:16 2026-04-18 Show GitHub Exploit DB Packet Storm
1548 5.4 MEDIUM
Network
b3log siyuan SiYuan is an open-source personal knowledge management system. In versions 3.6.1 through 3.6.3, a prior fix for XSS in bazaar README rendering (incomplete fix for CVE-2026-33066) enabled the Lute HTM… CWE-79
Cross-site Scripting
CVE-2026-40922 2026-04-21 01:16 2026-04-17 Show GitHub Exploit DB Packet Storm
1549 - - - radare2 prior to version 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows attackers to execute arbitrary commands by embedding a newline byte in… CWE-78
OS Command 
CVE-2026-40499 2026-04-21 01:16 2026-04-15 Show GitHub Exploit DB Packet Storm
1550 9.3 CRITICAL
Local
- - NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. In versions prior to 0.24, Syscall 12 (JumpToUser) accepts an arbitrary entry point address from user-space registers with… CWE-20
CWE-269
 Improper Input Validation 
 Improper Privilege Management
CVE-2026-40317 2026-04-21 01:16 2026-04-18 Show GitHub Exploit DB Packet Storm