Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
234031 9.3 危険 Nullsoft - Winamp の libmp4v2.dll における任意のコードを実行される脆弱性 - CVE-2007-2498 2012-09-25 16:47 2007-05-3 Show GitHub Exploit DB Packet Storm
234032 7.8 危険 office ocx - WordViewer.ocx の WordOCX ActiveX コントロールにおけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-2496 2012-09-25 16:47 2007-05-3 Show GitHub Exploit DB Packet Storm
234033 7.5 危険 office ocx - ExcelViewer.ocx の ExcelOCX ActiveX コントロールにおけるスタックベースのバッファオーバーフローの脆弱性 - CVE-2007-2495 2012-09-25 16:47 2007-05-3 Show GitHub Exploit DB Packet Storm
234034 10 危険 office ocx - PowerPointViewer.ocx の PowerPointOCX ActiveX コントロールにおけるスタックベースのバッファオーバーフローの脆弱性 - CVE-2007-2494 2012-09-25 16:47 2007-05-3 Show GitHub Exploit DB Packet Storm
234035 10 危険 mxbb - mxBB 用の FAQ & RULES における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-2493 2012-09-25 16:47 2007-05-3 Show GitHub Exploit DB Packet Storm
234036 7.8 危険 livedata - LiveData Server におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-2490 2012-09-25 16:47 2007-05-3 Show GitHub Exploit DB Packet Storm
234037 10 危険 livedata - LiveData Protocol Server におけるヒープベースのバッファオーバーフローの脆弱性 - CVE-2007-2489 2012-09-25 16:47 2007-05-3 Show GitHub Exploit DB Packet Storm
234038 5 警告 motobit - Motobit の download.asp におけるディレクトリトラバーサルの脆弱性 - CVE-2007-2486 2012-09-25 16:47 2007-05-3 Show GitHub Exploit DB Packet Storm
234039 4.6 警告 Linux - Linux kernel の net/ipv4/udp.c におけるローカルトラフィックを傍受される脆弱性 - CVE-2007-2480 2012-09-25 16:47 2007-04-30 Show GitHub Exploit DB Packet Storm
234040 10 危険 Novell - Novell SecureLogin における脆弱性 - CVE-2007-2476 2012-09-25 16:47 2007-04-6 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 25, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1751 9.6 CRITICAL
Network
- - NuGet Gallery is a package repository that powers nuget.org. A security vulnerability exists in the NuGetGallery backend job’s handling of .nuspec files within NuGet packages. An attacker can supply … CWE-20
CWE-22
 Improper Input Validation 
Path Traversal
CVE-2026-39399 2026-04-18 00:38 2026-04-15 Show GitHub Exploit DB Packet Storm
1752 8.1 HIGH
Network
- - An access control vulnerability was discovered in the Threat Intelligence functionality due to a specific access restriction not being properly enforced for users with view-only privileges. An authen… CWE-863
 Incorrect Authorization
CVE-2025-40897 2026-04-18 00:38 2026-04-15 Show GitHub Exploit DB Packet Storm
1753 8.9 HIGH
Network
- - A Stored Cross-Site Scripting vulnerability was discovered in the Assets and Nodes functionality due to improper validation of an input parameter. An authenticated user with custom fields privileges … CWE-79
Cross-site Scripting
CVE-2025-40899 2026-04-18 00:38 2026-04-15 Show GitHub Exploit DB Packet Storm
1754 9.9 CRITICAL
Network
- - OpenRemote is an open-source IoT platform. Versions 1.21.0 and below contain two interrelated expression injection vulnerabilities in the rules engine that allow arbitrary code execution on the serve… CWE-94
CWE-917
Code Injection
 Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
CVE-2026-39842 2026-04-18 00:38 2026-04-15 Show GitHub Exploit DB Packet Storm
1755 8.3 HIGH
Network
- - mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Versions 3.4.0 and prior contain an argument injection vulnerability in the port_forward tool in src/tools/… CWE-88
Argument Injection
CVE-2026-39884 2026-04-18 00:38 2026-04-15 Show GitHub Exploit DB Packet Storm
1756 6.9 MEDIUM
Network
- - Serendipity is a PHP-powered weblog engine. In versions 2.6-beta2 and below, the serendipity_setCookie() function in include/functions_config.inc.php uses $_SERVER['HTTP_HOST'] without validation as… CWE-565
 Reliance on Cookies without Validation and Integrity Checking
CVE-2026-39963 2026-04-18 00:38 2026-04-15 Show GitHub Exploit DB Packet Storm
1757 7.2 HIGH
Network
- - Serendipity is a PHP-powered weblog engine. In versions 2.6-beta2 and below, the email sending functionality in include/functions.inc.php inserts $_SERVER['HTTP_HOST'] directly into the Message-ID SM… CWE-113
HTTP Response Splitting
CVE-2026-39971 2026-04-18 00:38 2026-04-15 Show GitHub Exploit DB Packet Storm
1758 - - - Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (core modules). This vulnerability is associated with program files G3413CTRBl… CWE-327
 Use of a Broken or Risky Cryptographic Algorithm
CVE-2025-14813 2026-04-18 00:38 2026-04-15 Show GitHub Exploit DB Packet Storm
1759 - - - Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (prov modules). This vulnerability is asso… CWE-90
LDAP Injection
CVE-2026-0636 2026-04-18 00:38 2026-04-15 Show GitHub Exploit DB Packet Storm
1760 - - - Impact@fastify/express v4.0.4 and earlier fails to normalize URLs before passing them to Express middleware when Fastify router normalization options are enabled. This allows complete bypass of path-… CWE-436
 Interpretation Conflict
CVE-2026-33808 2026-04-18 00:38 2026-04-15 Show GitHub Exploit DB Packet Storm