Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
224951 4.3 警告 tru-zone - Nuke ET のプライベートメッセージ機能におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-1873 2012-12-20 18:52 2008-04-17 Show GitHub Exploit DB Packet Storm
224952 6.5 警告 scriptsagent - Scriptsagent.com Links Directory の links.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-1871 2012-12-20 18:52 2008-04-17 Show GitHub Exploit DB Packet Storm
224953 7.5 危険 site sift media - Site Sift Listings における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-1869 2012-12-20 18:52 2008-04-17 Show GitHub Exploit DB Packet Storm
224954 7.5 危険 pixel motion - Blog Pixel Motion の admin/sauvBase.php における重要な情報を含む blogPM.sql ファイルの結果を取得される脆弱性 CWE-287
不適切な認証
CVE-2008-1868 2012-12-20 18:52 2008-04-17 Show GitHub Exploit DB Packet Storm
224955 7.5 危険 pixel motion - Blog Pixel Motion における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-1867 2012-12-20 18:52 2008-04-17 Show GitHub Exploit DB Packet Storm
224956 9 危険 pixel motion - Blog Pixel Motion の admin/modif_config.php における任意の PHP スクリプトをアップロードされる脆弱性 CWE-94
コード・インジェクション
CVE-2008-1866 2012-12-20 18:52 2008-04-17 Show GitHub Exploit DB Packet Storm
224957 7.5 危険 prozilla - Prozilla Freelancers の project.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-1864 2012-12-20 18:52 2008-04-17 Show GitHub Exploit DB Packet Storm
224958 7.5 危険 prozilla - Prozilla Cheat Script の view_reviews.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-1863 2012-12-20 18:52 2008-04-17 Show GitHub Exploit DB Packet Storm
224959 5 警告 SmarterTools Inc. - SmarterMail の SmarterMail Web Server におけるサービス運用妨害 (DoS) の脆弱性 CWE-DesignError
CVE-2008-1854 2012-12-20 18:52 2008-04-16 Show GitHub Exploit DB Packet Storm
224960 4.3 警告 SAP - SAP NetWeaver のデフォルト設定におけるクロスサイトスクリプティング攻撃を実行される脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-1846 2012-12-20 18:52 2008-04-16 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 25, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1571 8.4 HIGH
Adjacent
- - OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “VS Administration” permissions to execute arbitrary commands on the Loa… CWE-77
Command Injection
CVE-2026-3519 2026-04-20 23:16 2026-04-20 Show GitHub Exploit DB Packet Storm
1572 8.4 HIGH
Adjacent
- - OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “All” permissions to execute arbitrary commands on the LoadMaster applia… CWE-77
Command Injection
CVE-2026-3518 2026-04-20 23:16 2026-04-20 Show GitHub Exploit DB Packet Storm
1573 8.4 HIGH
Adjacent
- - OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “Geo Administration” permissions to execute arbitrary commands on the Lo… CWE-77
Command Injection
CVE-2026-3517 2026-04-20 23:16 2026-04-20 Show GitHub Exploit DB Packet Storm
1574 3.5 LOW
Network
- - The Email Encoder WordPress plugin before 2.3.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks… CWE-79
Cross-site Scripting
CVE-2024-7083 2026-04-20 23:16 2026-04-20 Show GitHub Exploit DB Packet Storm
1575 - - - When sed is invoked with both -i (in-place edit) and --follow-symlinks, the function open_next_file() performs two separate, non-atomic filesystem operations on the same path: 1. resolves symlink to… CWE-367
 Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2026-5958 2026-04-20 21:16 2026-04-20 Show GitHub Exploit DB Packet Storm
1576 - - - Fudo Enterprise in versions from 5.5.0 through 5.6.2 allows low privileged users to access certain administrator-only resources via improperly protected API endpoints. This includes sensitive informa… CWE-863
 Incorrect Authorization
CVE-2025-13480 2026-04-20 19:16 2026-04-20 Show GitHub Exploit DB Packet Storm
1577 8.8 HIGH
Network
- - ThreatSonar Anti-Ransomware developed by TeamT5 has an Privilege Escalation vulnerability. Authenticated remote attackers with shell access can inject OS commands and execute them with root privilege… CWE-78
OS Command 
CVE-2026-5967 2026-04-20 18:16 2026-04-20 Show GitHub Exploit DB Packet Storm
1578 7.8 HIGH
Local
- - SKYSEA Client View and SKYMEC IT Manager provided by Sky Co.,LTD. configure the installation folder with improper file access permission settings. A non-administrative user may manipulate and/or plac… CWE-276
Incorrect Default Permissions 
CVE-2026-39454 2026-04-20 18:16 2026-04-20 Show GitHub Exploit DB Packet Storm
1579 8.1 HIGH
Network
- - ThreatSonar Anti-Ransomware developed by TeamT5 has an Arbitrary File Deletion vulnerability. Authenticated remote attackers with web access can exploit Path Traversal to delete arbitrary files on th… CWE-23
 Relative Path Traversal
CVE-2026-5966 2026-04-20 17:16 2026-04-20 Show GitHub Exploit DB Packet Storm
1580 9.8 CRITICAL
Network
- - EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents. CWE-89
SQL Injection
CVE-2026-5964 2026-04-20 17:16 2026-04-20 Show GitHub Exploit DB Packet Storm