Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
227911 6.8 警告 Joomla! - Joomla! 用の com_performs における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2006-3774 2012-12-20 18:02 2006-07-24 Show GitHub Exploit DB Packet Storm
227912 6.8 警告 Mambo Foundation - Joomla! および Mambo 用の Bridge コンポーネントにおける PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2006-3773 2012-12-20 18:02 2006-07-10 Show GitHub Exploit DB Packet Storm
227913 5.1 警告 php-post - PHP-Post における管理者権限を取得される脆弱性 - CVE-2006-3772 2012-12-20 18:02 2006-07-24 Show GitHub Exploit DB Packet Storm
227914 7.5 危険 imaginex-resource - iManage CMS の component.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-3771 2012-12-20 18:02 2006-07-24 Show GitHub Exploit DB Packet Storm
227915 7.5 危険 phpfaber - phpFaber TopSites の index.php における SQL インジェクションの脆弱性 - CVE-2006-3770 2012-12-20 18:02 2006-07-24 Show GitHub Exploit DB Packet Storm
227916 2.6 注意 top xl - Top XL におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-3769 2012-12-20 18:02 2006-07-24 Show GitHub Exploit DB Packet Storm
227917 6.4 警告 intervations - FileCOPA FTP Server の filecpnt.exe における整数アンダーフローの脆弱性 - CVE-2006-3768 2012-12-20 18:02 2006-07-28 Show GitHub Exploit DB Packet Storm
227918 6.8 警告 darrens 5-dollar script archive - Darren's $5 Script Archive osDate の showprofile.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-3767 2012-12-20 18:02 2006-07-21 Show GitHub Exploit DB Packet Storm
227919 5 警告 darrens 5-dollar script archive - Darren's $5 Script Archive osDate における本人のレートを格上げできる脆弱性 - CVE-2006-3766 2012-12-20 18:02 2006-07-21 Show GitHub Exploit DB Packet Storm
227920 4.3 警告 huttenlocher webdesign - Huttenlocher Webdesign hwdeGUEST におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-3765 2012-12-20 18:02 2006-07-21 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 19, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
321 7.7 HIGH
Network
- - Weblate is a web based localization tool. In versions prior to 5.17, the ZIP download feature didn't verify downloaded files, potentially following symlinks outside the repository. This issue has be… New CWE-22
CWE-59
CWE-200
Path Traversal
Link Following
Information Exposure
CVE-2026-34242 2026-04-18 00:38 2026-04-16 Show GitHub Exploit DB Packet Storm
322 5.0 MEDIUM
Network
- - Weblate is a web based localization tool. In versions prior to 5.17, a user with the project.edit permission (granted by the per-project "Administration" role) can configure machine translation servi… New CWE-200
CWE-918
Information Exposure
Server-Side Request Forgery (SSRF) 
CVE-2026-34244 2026-04-18 00:38 2026-04-16 Show GitHub Exploit DB Packet Storm
323 8.8 HIGH
Network
- - Weblate is a web based localization tool. In versions prior to 5.17, the user patching API endpoint didn't properly limit the scope of edits. This issue has been fixed in version 5.17. New CWE-269
 Improper Privilege Management
CVE-2026-34393 2026-04-18 00:38 2026-04-16 Show GitHub Exploit DB Packet Storm
324 4.1 MEDIUM
Network
- - Weblate is a web based localization tool. In versions prior to 5.17, the webhook add-on did not utilize existing SSRF protections. This issue has been fixed in version 5.17. If developers are unable … New CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-39845 2026-04-18 00:38 2026-04-16 Show GitHub Exploit DB Packet Storm
325 5.0 MEDIUM
Network
- - Weblate is a web based localization tool. In versions prior to 5.17, repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses s… New CWE-22
Path Traversal
CVE-2026-40256 2026-04-18 00:38 2026-04-16 Show GitHub Exploit DB Packet Storm
326 7.8 HIGH
Local
- - Barracuda RMM versions prior to 2025.2.2 contain a privilege escalation vulnerability that allows local attackers to gain SYSTEM-level privileges by exploiting overly permissive filesystem ACLs on th… New CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2026-22676 2026-04-18 00:38 2026-04-16 Show GitHub Exploit DB Packet Storm
327 9.4 CRITICAL
Network
- - Dgraph is an open source distributed GraphQL database. Versions 25.3.1 and prior contain an unauthenticated credential disclosure vulnerability where the /debug/pprof/cmdline endpoint is registered o… New CWE-200
CWE-215
Information Exposure
 Insertion of Sensitive Information Into Debugging Code
CVE-2026-40173 2026-04-18 00:38 2026-04-16 Show GitHub Exploit DB Packet Storm
328 - - - Pega Platform versions 8.1.0 through 25.1.1 are affected by an HTML Injection vulnerability in a user interface component. Requires a high privileged user with a developer role. New CWE-80
Basic XSS
CVE-2026-1564 2026-04-18 00:38 2026-04-16 Show GitHub Exploit DB Packet Storm
329 - - - Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-Site Scripting vulnerability in a user interface component. Requires a high privileged user with a developer role. New CWE-79
Cross-site Scripting
CVE-2026-1711 2026-04-18 00:38 2026-04-16 Show GitHub Exploit DB Packet Storm
330 6.8 MEDIUM
Network
- - ProcessWire CMS version 3.0.255 and prior contain a server-side request forgery vulnerability in the admin panel's 'Add Module From URL' feature that allows authenticated administrators to supply arb… New CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-40500 2026-04-18 00:38 2026-04-16 Show GitHub Exploit DB Packet Storm