Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
233941 6.8 警告 ht editor - HT Editor におけるバッファオーバーフローの脆弱性 - CVE-2007-2823 2012-09-25 16:47 2007-05-22 Show GitHub Exploit DB Packet Storm
233942 7.5 危険 ksign - AxKSignSWAT.dll におけるスタックベースのバッファオーバーフローの脆弱性 - CVE-2007-2820 2012-09-25 16:47 2007-05-22 Show GitHub Exploit DB Packet Storm
233943 7.5 危険 ol bookmarks - ol'bookmarks の read/index.php における SQL インジェクションの脆弱性 - CVE-2007-2817 2012-09-25 16:47 2007-05-22 Show GitHub Exploit DB Packet Storm
233944 7.5 危険 ol bookmarks - ol'bookmarks における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2007-2816 2012-09-25 16:47 2007-05-22 Show GitHub Exploit DB Packet Storm
233945 10 危険 マイクロソフト - Microsoft IIS Web Server の webhits.dll における非公開 Web ディレクトリへアクセスされる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2007-2815 2012-09-25 16:47 2007-05-22 Show GitHub Exploit DB Packet Storm
233946 7.5 危険 pegasus - Pegasus ImagN' ActiveX control におけるスタックベースのバッファーオーバーフローの脆弱性 - CVE-2007-2814 2012-09-25 16:47 2007-05-22 Show GitHub Exploit DB Packet Storm
233947 4.3 警告 hlstats - HLstats の hlstats.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-2812 2012-09-25 16:47 2007-05-22 Show GitHub Exploit DB Packet Storm
233948 9.3 危険 Opera Software ASA - Windows 用の Opera の転送管理におけるバッファオーバーフローの脆弱性 - CVE-2007-2809 2012-09-25 16:47 2007-05-22 Show GitHub Exploit DB Packet Storm
233949 10 危険 ヒューレット・パッカード - HP Tru64 UNIX の SSH における有効なユーザを特定される脆弱性 - CVE-2007-2791 2012-09-25 16:47 2007-05-9 Show GitHub Exploit DB Packet Storm
233950 7.5 危険 LEAD Technologies, Inc. - LeadTools Raster Thumbnail Object Library におけるスタックベースのバッファオーバーフローの脆弱性 - CVE-2007-2787 2012-09-25 16:47 2007-05-21 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 26, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
2041 7.8 HIGH
Local
- - It has been identified that a vulnerability (CWE-427) exists in the UPS (Uninterruptible Power Supply) management application, whereby improper permissions on the installation directory allow a malic… CWE-427
 Uncontrolled Search Path Element
CVE-2026-5397 2026-04-18 00:17 2026-04-15 Show GitHub Exploit DB Packet Storm
2042 2.9 LOW
Local
- - HCL AION is affected by a vulnerability where certain system behaviours may allow exploration of internal filesystem structures. Exposure of such information may provide insights into the underlying … CWE-209
Information Exposure Through an Error Message
CVE-2025-52641 2026-04-18 00:17 2026-04-15 Show GitHub Exploit DB Packet Storm
2043 7.5 HIGH
Network
- - Uncontrolled Resource Consumption in Bosch VMS Central Server in Bosch VMS 12.0.1 allows attackers to consume excessive amounts of disk space via network interface. CWE-400
 Uncontrolled Resource Consumption
CVE-2024-33618 2026-04-18 00:17 2026-04-15 Show GitHub Exploit DB Packet Storm
2044 6.1 MEDIUM
Network
- - Versions of the package github.com/yuin/goldmark/renderer/html before 1.7.17 are vulnerable to Cross-site Scripting (XSS) due to improper ordering of URL validation and normalization. The renderer va… CWE-79
Cross-site Scripting
CVE-2026-5160 2026-04-18 00:17 2026-04-15 Show GitHub Exploit DB Packet Storm
2045 6.5 MEDIUM
Network
- - JavaScript is vulnerable to prototype pollution in Mafintosh's protocol-buffers-schema Version 3.6.0, where an attacker may alter the application logic, bypass security checks, cause a DoS or achieve… - CVE-2026-5758 2026-04-18 00:17 2026-04-16 Show GitHub Exploit DB Packet Storm
2046 7.3 HIGH
Local
- - A flaw was found in gimp. This buffer overflow vulnerability in the GIF image loading component's `ReadJeffsImage` function allows an attacker to write beyond an allocated buffer by processing a spec… CWE-120
Classic Buffer Overflow
CVE-2026-6384 2026-04-18 00:17 2026-04-16 Show GitHub Exploit DB Packet Storm
2047 6.5 MEDIUM
Network
- - A flaw was found in FFmpeg. A remote attacker could exploit this vulnerability by providing a specially crafted MPEG-PS/VOB media file containing a malicious DVD subtitle stream. This vulnerability i… CWE-190
 Integer Overflow or Wraparound
CVE-2026-6385 2026-04-18 00:17 2026-04-16 Show GitHub Exploit DB Packet Storm
2048 - - - Inadequate Encryption Strength vulnerability in TP-Link Archer C7 v5 and v5.8 (uhttpd modules) allows Password Recovery Exploitation. The web interface encrypts the admin password client-side using R… CWE-326
Inadequate Encryption Strength
CVE-2026-5363 2026-04-18 00:17 2026-04-16 Show GitHub Exploit DB Packet Storm
2049 - - - An Incorrect Permission Assignment for Critical Resource vulnerability in the ASUS DriverHub update process allows privilege escalation due to improper protection of required execution resources duri… CWE-367
 Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2026-1880 2026-04-18 00:17 2026-04-16 Show GitHub Exploit DB Packet Storm
2050 - - - A Download of Code Without Integrity Check vulnerability in the update modules in ASUS Member Center(华硕大厅) allows a local user to achieve privilege escalation to Administrator via exploitation of a T… CWE-367
CWE-494
 Time-of-check Time-of-use (TOCTOU) Race Condition
 Download of Code Without Integrity Check
CVE-2026-3428 2026-04-18 00:17 2026-04-16 Show GitHub Exploit DB Packet Storm