Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
233861 7.8 危険 Mozilla Foundation - Mac OS X 上などの Mozilla Firefox におけるディレクトリトラバーサルの脆弱性 - CVE-2007-3073 2012-09-25 16:47 2007-05-17 Show GitHub Exploit DB Packet Storm
233862 7.1 危険 Mozilla Foundation - Mozilla Firefox におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2007-3072 2012-09-25 16:47 2007-01-18 Show GitHub Exploit DB Packet Storm
233863 7.5 危険 particle soft - Particle Soft Particle Gallery の viewimage.php における SQL インジェクションの脆弱性 - CVE-2007-3065 2012-09-25 16:47 2007-06-5 Show GitHub Exploit DB Packet Storm
233864 4.3 警告 mealex - My Databook の diary.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-3064 2012-09-25 16:47 2007-06-5 Show GitHub Exploit DB Packet Storm
233865 7.5 危険 kartli alisveris sistemi - Kartli Alisveris Sistemi の news.asp における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-3119 2012-09-25 16:47 2007-06-7 Show GitHub Exploit DB Packet Storm
233866 7.5 危険 k-letter - K-letter における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-3118 2012-09-25 16:47 2007-06-7 Show GitHub Exploit DB Packet Storm
233867 5 警告 MaraDNS - MaraDNS の server/MaraDNS.c におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2007-3116 2012-09-25 16:47 2007-06-7 Show GitHub Exploit DB Packet Storm
233868 7.8 危険 MaraDNS - MaraDNS の server/MaraDNS.c におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2007-3115 2012-09-25 16:47 2007-06-7 Show GitHub Exploit DB Packet Storm
233869 5 警告 MaraDNS - MaraDNS の server/MaraDNS.c におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2007-3114 2012-09-25 16:47 2007-06-7 Show GitHub Exploit DB Packet Storm
233870 10 危険 マイクロソフト
provideo
- ISSCamControl.dll の Provideo Camimage ActiveX コントロールにおけるバッファオーバーフローの脆弱性 - CVE-2007-3111 2012-09-25 16:47 2007-06-7 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 25, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1511 6.7 MEDIUM
Local
- - Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS command injection vulnerability. A high privileged attacke… CWE-78
OS Command 
CVE-2026-26942 2026-04-21 02:16 2026-04-21 Show GitHub Exploit DB Packet Storm
1512 7.2 HIGH
Network
- - Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an OS command injection vuln… CWE-78
OS Command 
CVE-2026-24506 2026-04-21 02:16 2026-04-21 Show GitHub Exploit DB Packet Storm
1513 7.2 HIGH
Network
- - Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain an improper input validation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability,… CWE-20
 Improper Input Validation 
CVE-2026-24505 2026-04-21 02:16 2026-04-21 Show GitHub Exploit DB Packet Storm
1514 7.2 HIGH
Network
- - Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper input validation… CWE-20
 Improper Input Validation 
CVE-2026-24504 2026-04-21 02:16 2026-04-21 Show GitHub Exploit DB Packet Storm
1515 6.7 MEDIUM
Local
- - Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain a command injection vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading … CWE-78
OS Command 
CVE-2026-22761 2026-04-21 02:16 2026-04-21 Show GitHub Exploit DB Packet Storm
1516 6.5 MEDIUM
Network
- - A vulnerability exists in the Buffalo Link Station version 1.85-0.01 that allows unauthenticated or guest-level users to enumerate valid usernames and their associated privilege roles. The issue is t… CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2025-66954 2026-04-21 02:16 2026-04-21 Show GitHub Exploit DB Packet Storm
1517 3.7 LOW
Network
apostrophecms apostrophecms ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a timing side-channel vulnerability in the password reset endpoint (/api/v1/@apostrophecms/login/r… CWE-208
 Information Exposure Through Timing Discrepancy
CVE-2026-33877 2026-04-21 02:05 2026-04-16 Show GitHub Exploit DB Packet Storm
1518 5.3 MEDIUM
Network
apostrophecms apostrophecms ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain an authorization bypass vulnerability in the getRestQuery method of the @apostrophecms/piece-type … CWE-200
CWE-863
Information Exposure
 Incorrect Authorization
CVE-2026-33888 2026-04-21 02:04 2026-04-16 Show GitHub Exploit DB Packet Storm
1519 5.4 MEDIUM
Network
apostrophecms apostrophecms ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a stored cross-site scripting vulnerability in the @apostrophecms/color-field module, where color … CWE-79
Cross-site Scripting
CVE-2026-33889 2026-04-21 02:03 2026-04-16 Show GitHub Exploit DB Packet Storm
1520 5.3 MEDIUM
Network
apostrophecms apostrophecms ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain an authorization bypass vulnerability in the choices and counts query parameters of the REST API, … CWE-200
Information Exposure
CVE-2026-39857 2026-04-21 02:03 2026-04-16 Show GitHub Exploit DB Packet Storm