Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
229721 4.3 警告 IBM - AMM を伴う IBM BladeCenter におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-2654 2012-09-25 17:38 2010-07-8 Show GitHub Exploit DB Packet Storm
229722 4.3 警告 LibTIFF - LibTIFF におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2010-2631 2012-09-25 17:38 2010-06-12 Show GitHub Exploit DB Packet Storm
229723 4.3 警告 LibTIFF - LibTIFF の TIFFReadDirectory 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2010-2630 2012-09-25 17:38 2010-01-11 Show GitHub Exploit DB Packet Storm
229724 7.5 危険 miyabi-seo - Miyabi CGI Tools SEO Links の index.pl における任意のコマンドを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2010-2626 2012-09-25 17:38 2010-07-2 Show GitHub Exploit DB Packet Storm
229725 7.8 危険 日立 - Hitachi ServerConductor / Deployment Manager におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2010-2625 2012-09-25 17:38 2010-06-4 Show GitHub Exploit DB Packet Storm
229726 7.5 危険 iScripts - iScripts EasySnaps における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-2624 2012-09-25 17:38 2010-07-2 Show GitHub Exploit DB Packet Storm
229727 7.5 危険 internetdm - Internet DM Specialist Bed and Breakfast の pages.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-2623 2012-09-25 17:38 2010-07-2 Show GitHub Exploit DB Packet Storm
229728 7.5 危険 joomanager - Joomla! 用の Joomanager コンポーネントにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2010-2622 2012-09-25 17:38 2010-07-2 Show GitHub Exploit DB Packet Storm
229729 5 警告 ノキア - Qt の QSslSocketBackendPrivate::transmit 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2010-2621 2012-09-25 17:38 2010-07-2 Show GitHub Exploit DB Packet Storm
229730 9.3 危険 open-ftpd - Open-FTPD における認証を回避される脆弱性 CWE-287
不適切な認証
CVE-2010-2620 2012-09-25 17:38 2010-07-2 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 17, 2026, 4:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
111 7.8 HIGH
Local
- - Eaton Intelligent Power Protector (IPP) is affected by insecure library loading in its executable, which could lead to arbitrary code execution by an attacker with access to the software package. Thi… New CWE-427
 Uncontrolled Search Path Element
CVE-2026-22619 2026-04-16 22:16 2026-04-16 Show GitHub Exploit DB Packet Storm
112 9.8 CRITICAL
Network
- - An issue pertaining to CWE-843: Access of Resource Using Incompatible Type was discovered in transloadit uppy v0.25.6. New CWE-843
Type Confusion
CVE-2025-70023 2026-04-16 22:16 2026-04-15 Show GitHub Exploit DB Packet Storm
113 4.6 MEDIUM
Physics
- - A side-channel vulnerability exists in the implementation of BIP-39 mnemonic processing, as observed in Trezor One v1.13.0 to v1.14.0, Trezor T v1.13.0 to v1.14.0, and Trezor Safe v1.13.0 to v1.14.0 … New CWE-385
 Covert Timing Channel
CVE-2025-69893 2026-04-16 22:16 2026-04-15 Show GitHub Exploit DB Packet Storm
114 9.8 CRITICAL
Network
- - A SQL injection vulnerability exists in the School Management System (version 1.0) by manikandan580. An unauthenticated or authenticated remote attacker can supply a crafted HTTP request to the affec… New CWE-89
SQL Injection
CVE-2025-65133 2026-04-16 22:16 2026-04-15 Show GitHub Exploit DB Packet Storm
115 9.8 CRITICAL
Network
- - A vulnerability was identified in OpenAI Codex CLI v0.23.0 and before that enables code execution through malicious MCP (Model Context Protocol) configuration files. The attack is triggered when a us… New CWE-94
Code Injection
CVE-2025-61260 2026-04-16 22:16 2026-04-15 Show GitHub Exploit DB Packet Storm
116 8.1 HIGH
Network
- - The example example_xcom that was included in airflow documentation implemented unsafe pattern of reading value from xcom in the way that could be exploited to allow UI user who had access to modify … New CWE-94
Code Injection
CVE-2025-54550 2026-04-16 22:16 2026-04-15 Show GitHub Exploit DB Packet Storm
117 - - - Insufficiently Protected Credentials in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client does not verify the receiver of OAuth2 credentials during OpenID authentication New CWE-522
 Insufficiently Protected Credentials
CVE-2025-15621 2026-04-16 22:16 2026-04-16 Show GitHub Exploit DB Packet Storm
118 5.4 MEDIUM
Network
gitlab gitlab GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that, in customizable analytics dashboards, could have allowed… New CWE-79
Cross-site Scripting
CVE-2026-4332 2026-04-16 22:00 2026-04-9 Show GitHub Exploit DB Packet Storm
119 2.7 LOW
Network
gitlab gitlab GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user with custom r… New CWE-862
 Missing Authorization
CVE-2026-4916 2026-04-16 21:59 2026-04-9 Show GitHub Exploit DB Packet Storm
120 7.5 HIGH
Network
- - The DirectoryPress – Business Directory And Classified Ad Listing plugin for WordPress is vulnerable to SQL Injection via the 'packages' parameter in versions up to, and including, 3.6.26 due to insu… New CWE-89
SQL Injection
CVE-2026-3489 2026-04-16 21:16 2026-04-16 Show GitHub Exploit DB Packet Storm