Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 4, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
236321 5 警告 mpop - Martin Lambers mpop における任意の SSL サーバになりすまされる脆弱性 CWE-310
暗号の問題
CVE-2009-3941 2012-09-25 17:38 2009-11-16 Show GitHub Exploit DB Packet Storm
236322 10 危険 IBM - IBM BladeCenter T 用の Advanced Management Module ファームウェアにおける脆弱性 CWE-noinfo
情報不足
CVE-2009-3935 2012-09-25 17:38 2009-11-12 Show GitHub Exploit DB Packet Storm
236323 4.3 警告 Karim Ratib - Zoomify モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-3918 2012-09-25 17:38 2009-11-4 Show GitHub Exploit DB Packet Storm
236324 4.3 警告 john c fiala - Drupal 用の Link モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-3915 2012-09-25 17:38 2009-11-4 Show GitHub Exploit DB Packet Storm
236325 4.3 警告 Zoho Corporation - ManageEngine Netflow Analyzer の jspui/index.jsp におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2009-3903 2012-09-25 17:38 2009-11-6 Show GitHub Exploit DB Packet Storm
236326 7.8 危険 IBM - AIX 上の IBM PowerHA におけるオペレーティングシステムの設定を変更される脆弱性 CWE-noinfo
情報不足
CVE-2009-3900 2012-09-25 17:38 2009-11-6 Show GitHub Exploit DB Packet Storm
236327 4.9 警告 Igor Sysoev - nginx の src/http/modules/ngx_http_dav_module.c におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2009-3898 2012-09-25 17:38 2009-11-24 Show GitHub Exploit DB Packet Storm
236328 5 警告 Igor Sysoev - nginx の src/http/ngx_http_parse.c におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2009-3896 2012-09-25 17:38 2009-11-24 Show GitHub Exploit DB Packet Storm
236329 4.9 警告 Linux - Linux kernel の mm/nommu.c におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2009-3888 2012-09-25 17:38 2009-10-30 Show GitHub Exploit DB Packet Storm
236330 5 警告 Novell - Novell Groupwise Client の gxmim1.dll ActiveX コントロールにおけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2009-3863 2012-09-25 17:38 2009-11-4 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 5, 2026, 4:11 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
2161 4.3 MEDIUM
Network
- - The PDF Embedder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.9.3 via the enqueue_block_assets. This makes it possible for authenticate… CWE-200
Information Exposure
CVE-2026-7526 2026-05-28 22:45 2026-05-28 Show GitHub Exploit DB Packet Storm
2162 8.8 HIGH
Network
- - The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthenticated privilege escalation in versions up to and including 3.29.2. This is due to insecure form submission handling th… CWE-269
 Improper Privilege Management
CVE-2026-6226 2026-05-28 22:45 2026-05-28 Show GitHub Exploit DB Packet Storm
2163 5.3 MEDIUM
Network
- - The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.6.11.8 due to the pl… CWE-862
 Missing Authorization
CVE-2026-6937 2026-05-28 22:45 2026-05-28 Show GitHub Exploit DB Packet Storm
2164 6.5 MEDIUM
Network
- - The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'order_by' parameter in all versions up to, and including, 1.8.… CWE-89
SQL Injection
CVE-2026-7048 2026-05-28 22:45 2026-05-28 Show GitHub Exploit DB Packet Storm
2165 4.3 MEDIUM
Network
- - The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.11.14. This is due to a missing capability … CWE-862
 Missing Authorization
CVE-2026-8689 2026-05-28 22:45 2026-05-28 Show GitHub Exploit DB Packet Storm
2166 4.3 MEDIUM
Network
- - The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.42.0. This is… CWE-862
 Missing Authorization
CVE-2026-9015 2026-05-28 22:45 2026-05-28 Show GitHub Exploit DB Packet Storm
2167 7.0 HIGH
Local
- - A command injection vulnerability was discovered in the `rpmuncompress` utility of RPM. When extracting certain archive formats (ZIP, 7z, GEM) to a specified destination directory, the tool inserts t… CWE-78
OS Command 
CVE-2026-44604 2026-05-28 22:44 2026-05-28 Show GitHub Exploit DB Packet Storm
2168 7.7 HIGH
Network
- - A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a path traversal vulnerability in the VMExport directory endpoint. By placing … CWE-59
Link Following
CVE-2026-9804 2026-05-28 22:44 2026-05-28 Show GitHub Exploit DB Packet Storm
2169 5.4 MEDIUM
Network
apache shiro With valid login credentials, URL Redirection to Untrusted Site ('Open Redirect'), Server-Side Request Forgery (SSRF) vulnerability in Apache Shiro. This issue affects Apache Shiro from 2.0-alpha… CWE-601
CWE-918
Open Redirect
Server-Side Request Forgery (SSRF) 
CVE-2026-44598 2026-05-28 22:44 2026-05-26 Show GitHub Exploit DB Packet Storm
2170 6.1 MEDIUM
Network
mistune_project mistune Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, the mistune math plugin renders inline math ($...$) and block math ($$...$$) by concatenating the raw user-supplied con… CWE-79
Cross-site Scripting
CVE-2026-44708 2026-05-28 22:44 2026-05-27 Show GitHub Exploit DB Packet Storm