Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 7, 2026, 4:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
235611 4.3 警告 jlmforo system - JLMForo System の modificarPerfil.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-6364 2012-09-25 16:59 2007-12-14 Show GitHub Exploit DB Packet Storm
235612 2.1 注意 IBM - IBM Tivoli Netcool Security Manager におけるログインアクセス権を取得される脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-6363 2012-09-25 16:59 2007-12-14 Show GitHub Exploit DB Packet Storm
235613 7.5 危険 Joomla! - Mambo および Joomla! 用の RSGallery における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-6362 2012-09-25 16:59 2007-12-14 Show GitHub Exploit DB Packet Storm
235614 5.8 警告 マイクロソフト - Microsoft Office Access におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2007-6357 2012-09-25 16:59 2007-12-14 Show GitHub Exploit DB Packet Storm
235615 7.8 危険 Perforce Software - Perforce P4Web の P4Webs.exe におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2007-6349 2012-09-25 16:59 2007-12-20 Show GitHub Exploit DB Packet Storm
235616 6.8 警告 mcms - Mcms Easy Web Make の modules/cms/index.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2007-6344 2012-09-25 16:59 2007-12-13 Show GitHub Exploit DB Packet Storm
235617 4.3 警告 ヒューレット・パッカード - HP OV NNM におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-6343 2012-09-25 16:59 2007-11-28 Show GitHub Exploit DB Packet Storm
235618 5 警告 net-dns.org - SpamAssassin などのパッケージで使用されている Net::DNS の Net/DNS/RR/A.pm におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2007-6341 2012-09-25 16:59 2007-12-20 Show GitHub Exploit DB Packet Storm
235619 5 警告 ingres - 複数の CA 製品で使用される Windows の Ingres における権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2007-6334 2012-09-25 16:59 2007-12-19 Show GitHub Exploit DB Packet Storm
235620 5.8 警告 ヒューレット・パッカード - HP QLBCTRL.exe の hpinfocenter.exe における任意のレジストリ値を読まれる脆弱性 CWE-DesignError
CVE-2007-6333 2012-09-25 16:59 2007-12-13 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 7, 2026, 4:22 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
381 - - - In the Linux kernel, the following vulnerability has been resolved: dm: clear cloned request bio pointer when last clone bio completes Stale rq->bio values have been observed to cause double-initia… New - CVE-2026-43278 2026-05-6 22:07 2026-05-6 Show GitHub Exploit DB Packet Storm
382 - - - In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Add sanity check for OOB writes at silencing At silencing the playback URB packets in the implicit fb mode befor… New - CVE-2026-43279 2026-05-6 22:07 2026-05-6 Show GitHub Exploit DB Packet Storm
383 - - - In the Linux kernel, the following vulnerability has been resolved: drm/xe: Add bounds check on pat_index to prevent OOB kernel read in madvise When user provides a bogus pat_index value through th… New - CVE-2026-43280 2026-05-6 22:07 2026-05-6 Show GitHub Exploit DB Packet Storm
384 5.3 MEDIUM
Network
- - The Mercado Pago payments for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'mp_pix_image' WooCommerce API endpoint in all ver… New CWE-862
 Missing Authorization
CVE-2026-3208 2026-05-6 22:06 2026-05-6 Show GitHub Exploit DB Packet Storm
385 6.5 MEDIUM
Network
- - The All-in-One WP Migration Unlimited Extension plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.83. This is due to the 'Ai1wmve_Schedules_Controller::s… New CWE-862
 Missing Authorization
CVE-2026-5753 2026-05-6 22:06 2026-05-6 Show GitHub Exploit DB Packet Storm
386 4.3 MEDIUM
Network
- - The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to unauthorized database table creation due to missing authorization checks on the `createFluentCartTable` function in al… New CWE-862
 Missing Authorization
CVE-2026-2306 2026-05-6 22:06 2026-05-6 Show GitHub Exploit DB Packet Storm
387 6.4 MEDIUM
Network
- - The Affiliate Program Suite — SliceWP Affiliates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode attributes in all versions up to, and including, 1.2.7. This is due to… New CWE-79
Cross-site Scripting
CVE-2026-6672 2026-05-6 22:06 2026-05-6 Show GitHub Exploit DB Packet Storm
388 4.9 MEDIUM
Network
- - The Fluent Forms plugin for WordPress is vulnerable to Arbitrary File Read in versions up to and including 6.2.1. This is due to insufficient path validation in the getAttachments() method of EmailNo… New CWE-22
Path Traversal
CVE-2026-6344 2026-05-6 22:06 2026-05-6 Show GitHub Exploit DB Packet Storm
389 7.2 HIGH
Network
- - The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'booking_form_page_url' parameter in all versions up to, … New CWE-79
Cross-site Scripting
CVE-2026-7332 2026-05-6 22:06 2026-05-6 Show GitHub Exploit DB Packet Storm
390 7.2 HIGH
Network
- - The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'first_name' parameter in all versions up to, and includi… New CWE-79
Cross-site Scripting
CVE-2026-7448 2026-05-6 22:06 2026-05-6 Show GitHub Exploit DB Packet Storm