Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
232131 4.9 警告 Linux - Linux kernel の mm/filemap.c におけるサービス運用妨害 (DoS) の脆弱性 CWE-189
数値処理の問題
CVE-2008-3535 2012-09-25 17:17 2008-08-8 Show GitHub Exploit DB Packet Storm
232132 4.9 警告 Linux - Linux kernel の tmpfs 実装におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2008-3534 2012-09-25 17:17 2008-08-8 Show GitHub Exploit DB Packet Storm
232133 7.8 危険 Linux - Linux kernel の sctp 実装における整数オーバーフローの脆弱性 CWE-189
数値処理の問題
CVE-2008-3526 2012-09-25 17:17 2008-08-27 Show GitHub Exploit DB Packet Storm
232134 7.2 危険 JasPer Project - JasPer の libjasper/base/jas_stream.c におけるサービス運用妨害 (DoS) の脆弱性 CWE-59
リンク解釈の問題
CVE-2008-3521 2012-09-25 17:17 2008-10-2 Show GitHub Exploit DB Packet Storm
232135 7.5 危険 PHPNUKE - PHP-Nuke 用の Book Catalog モジュールにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3513 2012-09-25 17:17 2008-08-7 Show GitHub Exploit DB Packet Storm
232136 7.5 危険 PHPNUKE - PHP-Nuke 用の Kleinanzeigen モジュールにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3512 2012-09-25 17:17 2008-08-7 Show GitHub Exploit DB Packet Storm
232137 7.5 危険 lovecms - LoveCMS における設定を変更される脆弱性 CWE-94
コード・インジェクション
CVE-2008-3509 2012-09-25 17:17 2008-08-7 Show GitHub Exploit DB Packet Storm
232138 7.5 危険 mpfm - mPFM における脆弱性 CWE-287
不適切な認証
CVE-2008-3504 2012-09-25 17:17 2008-08-6 Show GitHub Exploit DB Packet Storm
232139 4.3 警告 Novell - Novell Groupwise の WebAccess 簡易インターフェースにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-3501 2012-09-25 17:17 2008-06-19 Show GitHub Exploit DB Packet Storm
232140 6.8 警告 myphp cms - MyPHP CMS の pages.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3497 2012-09-25 17:17 2008-08-6 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 20, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
121 8.1 HIGH
Network
- - HomeBox is a home inventory and organization system. Versions prior to 0.25.0 contain a vulnerability where the defaultGroup ID remained permanently assigned to a user after being invited to a group,… New CWE-708
 Incorrect Ownership Assignment
CVE-2026-40196 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
122 5.4 MEDIUM
Network
- - The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. In versions 4.12.0 through 4.17.1, simultaneous requests that trigger a nonce retry may cause the prox… New CWE-362
CWE-863
Race Condition
 Incorrect Authorization
CVE-2026-40155 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
123 - - - Claude Code is an agentic coding tool. In versions prior to 2.1.75 on Windows, Claude Code loaded the system-wide default configuration from C:\ProgramData\ClaudeCode\managed-settings.json without va… New CWE-426
 Untrusted Search Path
CVE-2026-35603 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
124 - - - xrdp is an open source RDP server. Versions through 0.10.5 have a heap-based buffer overflow in the EGFX (graphics dynamic virtual channel) implementation due to insufficient validation of client-con… New CWE-122
Heap-based Buffer Overflow
CVE-2026-35512 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
125 - - - mcp-neo4j-cypher is an MCP server for executing Cypher queries against Neo4j databases. In versions prior to 0.6.0, the read_only mode enforcement can be bypassed using APOC CALL procedures, potentia… New CWE-284
Improper Access Control
CVE-2026-35402 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
126 - - - xrdp is an open source RDP server. Versions through 0.10.5 have an out-of-bounds read vulnerability in the pre-authentication RDP message parsing logic. A remote, unauthenticated attacker can trigger… New CWE-125
Out-of-bounds Read
CVE-2026-33689 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
127 3.1 LOW
Network
- - Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. In versions prior to 2.0.0, file upload endpoints render user-supplied filenames directly into HTML … New CWE-20
CWE-79
CWE-116
 Improper Input Validation 
Cross-site Scripting
 Improper Encoding or Escaping of Output
CVE-2026-33436 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
128 6.3 MEDIUM
Network
- - xrdp is an open source RDP server. Versions through 0.10.5 allow an authenticated remote user to execute arbitrary commands on the server due to unsafe handling of the AlternateShell parameter in xrd… New CWE-78
OS Command 
CVE-2026-33145 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
129 - - - Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versions prior to 23.0.0 , the ODT to PDF conversion process in odf.php concatenates … New CWE-78
OS Command 
CVE-2026-23500 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
130 7.5 HIGH
Network
- - Anviz CX2 Lite and CX7 are vulnerable to unauthenticated POST requests that modify debug settings (e.g., enabling SSH), allowing unauthorized state changes that can facilitate later compromise. New CWE-306
Missing Authentication for Critical Function
CVE-2026-40461 2026-04-18 05:16 2026-04-18 Show GitHub Exploit DB Packet Storm