Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 12, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
236821 7.5 危険 Mambo Foundation
Mambo Communities Pty
- Mambo 用の remository コンポーネントにおける SQL インジェクションの脆弱性 - CVE-2007-4505 2012-09-25 16:59 2007-08-23 Show GitHub Exploit DB Packet Storm
236822 5 警告 Joomla! - Joomla! 用の Rsfiles コンポーネントにおけるディレクトリトラバーサルの脆弱性 - CVE-2007-4504 2012-09-25 16:59 2007-08-23 Show GitHub Exploit DB Packet Storm
236823 7.5 危険 Joomla! - Joomla! 用の Nick Talk コンポーネントにおける SQL インジェクションの脆弱性 - CVE-2007-4503 2012-09-25 16:59 2007-08-23 Show GitHub Exploit DB Packet Storm
236824 7.5 危険 Joomla! - Joomla! 用の BibTex コンポーネントの index.php における SQL インジェクションの脆弱性 - CVE-2007-4502 2012-09-25 16:59 2007-08-23 Show GitHub Exploit DB Packet Storm
236825 7.5 危険 gurur haber - Gurur haber の uyeler2.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-4491 2012-09-25 16:59 2007-08-22 Show GitHub Exploit DB Packet Storm
236826 7.5 危険 linkliste - Linkliste の index.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-4486 2012-09-25 16:59 2007-08-22 Show GitHub Exploit DB Packet Storm
236827 7.5 危険 my referer - My_REFERER の login.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-4484 2012-09-25 16:59 2007-08-22 Show GitHub Exploit DB Packet Storm
236828 4.3 警告 マイクロソフト - Microsoft Internet Explorer 6.0 および 7 におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-4478 2012-09-25 16:59 2007-08-22 Show GitHub Exploit DB Packet Storm
236829 9.3 危険 Intuit - Intuit QuickBooks Online Edition ActiveX コントロールにおける任意のファイルを上書きされる脆弱性 CWE-22
CWE-264
CVE-2007-4471 2012-09-25 16:59 2007-09-5 Show GitHub Exploit DB Packet Storm
236830 4.3 警告 nufw - NuFW における時間ベースのパケットフィルタルールを回避される脆弱性 - CVE-2007-4461 2012-09-25 16:59 2007-08-21 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 12, 2026, 5:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
501 - - - Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, several Net::IMAP commands accept a raw string argument that is… New CWE-77
CWE-93
Command Injection
CRLF Injection
CVE-2026-42257 2026-05-10 05:16 2026-05-10 Show GitHub Exploit DB Packet Storm
502 - - - Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. From versions 0.4.0 to before 0.4.24, 0.5.0 to before 0.5.14, and 0.6.0 to before 0.6.4, when authenticating… New CWE-770
CWE-1322
 Allocation of Resources Without Limits or Throttling
CVE-2026-42256 2026-05-10 05:16 2026-05-10 Show GitHub Exploit DB Packet Storm
503 - - - Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4, a man-in-the-middle attacker can cause Net::IMAP#startt… New CWE-392
CWE-393
CWE-636
CWE-754
CWE-841
 Missing Report of Error Condition
 Return of Wrong Status Code
 Not Failing Securely ('Failing Open')
 Improper Check for Unusual or Exceptional Conditions
 Improper Enforcement of Behavioral Workflow
CVE-2026-42246 2026-05-10 05:16 2026-05-10 Show GitHub Exploit DB Packet Storm
504 - - - Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, Net::IMAP::ResponseReader has quadratic time complexity when re… New CWE-407
 Inefficient Algorithmic Complexity
CVE-2026-42245 2026-05-10 05:16 2026-05-10 Show GitHub Exploit DB Packet Storm
505 - - - Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.25.0, the HTTP login endpoints (POST /login and POST /signalk/v1/auth/login) are protected by express-… New CWE-307
mproper Restriction of Excessive Authentication Attempts
CVE-2026-41893 2026-05-10 05:16 2026-05-10 Show GitHub Exploit DB Packet Storm
506 - - - Allocation of Resources Without Limits or Throttling vulnerability in absinthe-graphql absinthe allows unauthenticated denial of service via atom table exhaustion when parsing attacker-controlled Gra… CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2026-42793 2026-05-9 22:16 2026-05-9 Show GitHub Exploit DB Packet Storm
507 5.3 MEDIUM
Adjacent
- - Some EZVIZ products utilize older versions of cloud feature modules with legacy API interfaces, which pose a data transmission risk. Attackers can exploit this by eavesdropping on network requests to… - CVE-2026-32683 2026-05-9 18:16 2026-05-9 Show GitHub Exploit DB Packet Storm
508 9.1 CRITICAL
Network
apache cloudstack Instances deployed via the Proxmox extension allow unauthorized access to instances belonging to other tenants. This issue affects Apache CloudStack: from 4.21.0.0 through 4.22.0.0. The Proxm… CWE-200
Information Exposure
CVE-2026-25199 2026-05-9 16:16 2026-05-8 Show GitHub Exploit DB Packet Storm
509 5.3 MEDIUM
Network
apache cloudstack Due to multiple time-of-check time-of-use race conditions in the resource count check and increment logic, as well as missing validations, users of the platform are able to exceed the allocation limi… CWE-367
CWE-770
 Time-of-check Time-of-use (TOCTOU) Race Condition
 Allocation of Resources Without Limits or Throttling
CVE-2025-69233 2026-05-9 16:16 2026-05-8 Show GitHub Exploit DB Packet Storm
510 6.5 MEDIUM
Network
- - The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in CloudStack 4.21.0.0+ environments, where this plugin is e… CWE-359
 Exposure of Private Personal Information to an Unauthorized Actor
CVE-2025-66171 2026-05-9 16:16 2026-05-8 Show GitHub Exploit DB Packet Storm