Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
231251 5 警告 オラクル - Oracle E-Business Suite における脆弱性 CWE-noinfo
情報不足
CVE-2008-7239 2012-09-25 17:27 2008-08-15 Show GitHub Exploit DB Packet Storm
231252 6 警告 オラクル - Oracle E-Business Suite における脆弱性 CWE-noinfo
情報不足
CVE-2008-7238 2012-09-25 17:27 2008-08-15 Show GitHub Exploit DB Packet Storm
231253 4.3 警告 LinPHA - LinPHA におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-7223 2012-09-25 17:27 2008-07-20 Show GitHub Exploit DB Packet Storm
231254 10 危険 Horde - Horde Kronolith H3 などにおける脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-7219 2012-09-25 17:27 2008-02-6 Show GitHub Exploit DB Packet Storm
231255 7.5 危険 ming han - AJchat の directory.php における SQL インジェクション攻撃を実行される脆弱性 CWE-89
SQLインジェクション
CVE-2008-7210 2012-09-25 17:27 2009-09-11 Show GitHub Exploit DB Packet Storm
231256 7.5 危険 InsaneVisions - OneCMS の a_upload.php の add2 アクションにおける任意のコードを実行される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-7209 2012-09-25 17:27 2009-09-11 Show GitHub Exploit DB Packet Storm
231257 6.8 警告 InsaneVisions - OneCMS における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-7208 2012-09-25 17:27 2009-09-11 Show GitHub Exploit DB Packet Storm
231258 4.3 警告 openwebmail.acatysmoof - OpenWebMail におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-7202 2012-09-25 17:27 2009-09-10 Show GitHub Exploit DB Packet Storm
231259 7.8 危険 Lantronix, Inc. - Lantronix MSS485-T におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2008-7201 2012-09-25 17:27 2009-09-10 Show GitHub Exploit DB Packet Storm
231260 5 警告 PHOENIX CONTACT - Phoenix Contact FL IL 24 BK-PAC におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2008-7199 2012-09-25 17:27 2009-09-10 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 20, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
121 8.1 HIGH
Network
- - HomeBox is a home inventory and organization system. Versions prior to 0.25.0 contain a vulnerability where the defaultGroup ID remained permanently assigned to a user after being invited to a group,… New CWE-708
 Incorrect Ownership Assignment
CVE-2026-40196 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
122 5.4 MEDIUM
Network
- - The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. In versions 4.12.0 through 4.17.1, simultaneous requests that trigger a nonce retry may cause the prox… New CWE-362
CWE-863
Race Condition
 Incorrect Authorization
CVE-2026-40155 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
123 - - - Claude Code is an agentic coding tool. In versions prior to 2.1.75 on Windows, Claude Code loaded the system-wide default configuration from C:\ProgramData\ClaudeCode\managed-settings.json without va… New CWE-426
 Untrusted Search Path
CVE-2026-35603 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
124 - - - xrdp is an open source RDP server. Versions through 0.10.5 have a heap-based buffer overflow in the EGFX (graphics dynamic virtual channel) implementation due to insufficient validation of client-con… New CWE-122
Heap-based Buffer Overflow
CVE-2026-35512 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
125 - - - mcp-neo4j-cypher is an MCP server for executing Cypher queries against Neo4j databases. In versions prior to 0.6.0, the read_only mode enforcement can be bypassed using APOC CALL procedures, potentia… New CWE-284
Improper Access Control
CVE-2026-35402 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
126 - - - xrdp is an open source RDP server. Versions through 0.10.5 have an out-of-bounds read vulnerability in the pre-authentication RDP message parsing logic. A remote, unauthenticated attacker can trigger… New CWE-125
Out-of-bounds Read
CVE-2026-33689 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
127 3.1 LOW
Network
- - Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. In versions prior to 2.0.0, file upload endpoints render user-supplied filenames directly into HTML … New CWE-20
CWE-79
CWE-116
 Improper Input Validation 
Cross-site Scripting
 Improper Encoding or Escaping of Output
CVE-2026-33436 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
128 6.3 MEDIUM
Network
- - xrdp is an open source RDP server. Versions through 0.10.5 allow an authenticated remote user to execute arbitrary commands on the server due to unsafe handling of the AlternateShell parameter in xrd… New CWE-78
OS Command 
CVE-2026-33145 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
129 - - - Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versions prior to 23.0.0 , the ODT to PDF conversion process in odf.php concatenates … New CWE-78
OS Command 
CVE-2026-23500 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
130 7.5 HIGH
Network
- - Anviz CX2 Lite and CX7 are vulnerable to unauthenticated POST requests that modify debug settings (e.g., enabling SSH), allowing unauthorized state changes that can facilitate later compromise. New CWE-306
Missing Authentication for Critical Function
CVE-2026-40461 2026-04-18 05:16 2026-04-18 Show GitHub Exploit DB Packet Storm