Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
233761 7.5 危険 Novell - Novell Access Manager の Linux Access Gateway におけるセキュリティコントロールを回避される脆弱性 - CVE-2007-3570 2012-09-25 16:47 2007-07-5 Show GitHub Exploit DB Packet Storm
233762 5 警告 imlib - imlib の _LoadBMP 関数におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-3568 2012-09-25 16:47 2007-07-5 Show GitHub Exploit DB Packet Storm
233763 7.5 危険 MySQLDumper-Team - MySQLDumper における認証要求を回避される脆弱性 - CVE-2007-3567 2012-09-25 16:47 2007-07-5 Show GitHub Exploit DB Packet Storm
233764 7.5 危険 Haxx - libcurl における特定のアクセス制限を回避される脆弱性 - CVE-2007-3564 2012-09-25 16:47 2007-07-10 Show GitHub Exploit DB Packet Storm
233765 7.5 危険 php director - PHP Director の videos.php における SQL インジェクションの脆弱性 - CVE-2007-3562 2012-09-25 16:47 2007-07-4 Show GitHub Exploit DB Packet Storm
233766 4.3 警告 Moodle - Moodle の index.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-3555 2012-09-25 16:47 2007-07-4 Show GitHub Exploit DB Packet Storm
233767 7.6 危険 ヒューレット・パッカード - HP Instant Support - Driver Check におけるスタックベースのバッファオーバーフローの脆弱性 - CVE-2007-3554 2012-09-25 16:47 2007-06-13 Show GitHub Exploit DB Packet Storm
233768 4.3 警告 オラクル - Oracle Application Server 11i の Rapid Install Web Server におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-3553 2012-09-25 16:47 2007-07-3 Show GitHub Exploit DB Packet Storm
233769 4.3 警告 Tenable, Inc. - Nessus Vulnerability Scanner の Windows GUI におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-3546 2012-09-25 16:47 2007-07-3 Show GitHub Exploit DB Packet Storm
233770 7.8 危険 IBM - iSeries マシン上の IBM OS/400 におけるファイアーウォールルールを回避される脆弱性 - CVE-2007-3537 2012-09-25 16:47 2007-06-28 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 25, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1421 8.8 HIGH
Network
- - Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can escalate their own account to administrator by sending `isAdmin=… CWE-862
 Missing Authorization
CVE-2026-40349 2026-04-21 04:03 2026-04-18 Show GitHub Exploit DB Packet Storm
1422 8.8 HIGH
Network
- - Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can access the user-management endpoints `/settings/users` and use t… CWE-863
 Incorrect Authorization
CVE-2026-40350 2026-04-21 04:03 2026-04-18 Show GitHub Exploit DB Packet Storm
1423 9.0 CRITICAL
Local
- - NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. In versions prior to 0.24, Syscall 15 (MemoryMapRange) allows Ring 3 user-mode processes to map arbitrary virtual address … CWE-269
 Improper Privilege Management
CVE-2026-40572 2026-04-21 04:03 2026-04-18 Show GitHub Exploit DB Packet Storm
1424 6.5 MEDIUM
Network
- - gdown is a Google Drive public file/folder downloader. Versions prior to 5.2.2 are vulnerable to a Path Traversal attack within the extractall functionality. When extracting a maliciously crafted ZIP… CWE-22
Path Traversal
CVE-2026-40491 2026-04-21 04:03 2026-04-18 Show GitHub Exploit DB Packet Storm
1425 - - - WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vulnerability allows an authenticated user to inject malicious JavaScript into the… CWE-79
Cross-site Scripting
CVE-2026-40282 2026-04-21 04:02 2026-04-18 Show GitHub Exploit DB Packet Storm
1426 6.8 MEDIUM
Network
- - WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vulnerability allows an authenticated user to inject malicious JavaScript via the … CWE-79
Cross-site Scripting
CVE-2026-40284 2026-04-21 04:02 2026-04-18 Show GitHub Exploit DB Packet Storm
1427 7.5 HIGH
Network
- - WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the 'Member Registration' (Cadastrar Sócio) functi… CWE-79
Cross-site Scripting
CVE-2026-40286 2026-04-21 04:02 2026-04-18 Show GitHub Exploit DB Packet Storm
1428 6.1 MEDIUM
Physics
- - libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, two functions in camlibs/ptp2/ptp-pack.c accept a data pointer but no length parameter, performing unbounded… CWE-125
Out-of-bounds Read
CVE-2026-40333 2026-04-21 04:00 2026-04-18 Show GitHub Exploit DB Packet Storm
1429 3.5 LOW
Physics
- - libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, a missing null terminator exists in ptp_unpack_Canon_FE() in camlibs/ptp2/ptp-pack.c (line 1377). The functi… CWE-170
 Improper Null Termination
CVE-2026-40334 2026-04-21 04:00 2026-04-18 Show GitHub Exploit DB Packet Storm
1430 5.2 MEDIUM
Physics
- - libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in `ptp_unpack_DPV()` in `camlibs/ptp2/ptp-pack.c` (lines 622–629). The UINT128 and I… CWE-125
Out-of-bounds Read
CVE-2026-40335 2026-04-21 04:00 2026-04-18 Show GitHub Exploit DB Packet Storm