Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 26, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
239821 6.8 警告 l2j - L2J Statistik Script の index.php におけるディレクトリトラバーサルの脆弱性 - CVE-2007-0173 2012-09-25 15:36 2007-01-10 Show GitHub Exploit DB Packet Storm
239822 7.5 危険 locazo - LocazoList の main.asp における SQL インジェクションの脆弱性 - CVE-2007-0129 2012-09-25 15:36 2007-01-9 Show GitHub Exploit DB Packet Storm
239823 9.3 危険 Opera Software ASA - Opera の Javascript SVG サポートにおける任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2007-0127 2012-09-25 15:36 2007-01-8 Show GitHub Exploit DB Packet Storm
239824 9.3 危険 Opera Software ASA - Opera におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2007-0126 2012-09-25 15:36 2007-01-8 Show GitHub Exploit DB Packet Storm
239825 5 警告 カスペルスキー - Kaspersky Lab Antivurus Engine におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-0125 2012-09-25 15:36 2007-01-8 Show GitHub Exploit DB Packet Storm
239826 6.8 警告 michael romedahl - RI Blog の search.asp におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-0121 2012-09-25 15:36 2007-01-8 Show GitHub Exploit DB Packet Storm
239827 6.8 警告 packeteer - Packeteer PacketShaper PacketWise におけるバッファオーバーフローの脆弱性 - CVE-2007-0113 2012-09-25 15:36 2007-01-8 Show GitHub Exploit DB Packet Storm
239828 6.8 警告 Novell - Novell Access Manager Identity Server の nidp/idff/sso におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-0110 2012-09-25 15:36 2007-01-8 Show GitHub Exploit DB Packet Storm
239829 6 警告 Novell - Windows 2000/XP/2003 用の Novell Client における別のユーザプロファイルを呼び出される脆弱性 - CVE-2007-0108 2012-09-25 15:36 2007-01-8 Show GitHub Exploit DB Packet Storm
239830 10 危険 Perforce Software - Perforce クライアントにおける任意のファイルを上書きされる脆弱性 - CVE-2007-0100 2012-09-25 15:36 2007-01-8 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 27, 2026, 4:52 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1681 7.5 HIGH
Network
- - Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.2, Vvveb CMS does not validate the sign of the quantity parameter on the cart-ad… CWE-1284
 Improper Validation of Specified Quantity in Input
CVE-2026-44826 2026-05-19 02:26 2026-05-16 Show GitHub Exploit DB Packet Storm
1682 - - - Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3, This vulnerability is fixed in 1.0.8.3. CWE-79
Cross-site Scripting
CVE-2026-45616 2026-05-19 02:26 2026-05-16 Show GitHub Exploit DB Packet Storm
1683 8.1 HIGH
Network
- - Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3, the backend admin/auth-token endpoint allows an authenticated administrator t… CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-46407 2026-05-19 02:26 2026-05-16 Show GitHub Exploit DB Packet Storm
1684 7.6 HIGH
Network
- - Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3, the checkout endpoint accepts a user-controlled cart_id and uses it to enter … CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-46408 2026-05-19 02:26 2026-05-16 Show GitHub Exploit DB Packet Storm
1685 6.4 MEDIUM
Network
- - Composr CMS 10.0.34 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through the banner management interface. Attackers wi… CWE-79
Cross-site Scripting
CVE-2020-37237 2026-05-19 02:26 2026-05-17 Show GitHub Exploit DB Packet Storm
1686 6.4 MEDIUM
Network
- - CMS Made Simple 2.2.15 contains a stored cross-site scripting vulnerability that allows authenticated users with Content Manager access to inject malicious scripts through SVG file uploads. Attackers… CWE-79
Cross-site Scripting
CVE-2020-37238 2026-05-19 02:26 2026-05-17 Show GitHub Exploit DB Packet Storm
1687 5.3 MEDIUM
Network
- - bloofoxCMS 0.5.2.1 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by tricking logged-in users into visiting malicious pages. Attackers can… CWE-352
 Origin Validation Error
CVE-2020-37241 2026-05-19 02:26 2026-05-17 Show GitHub Exploit DB Packet Storm
1688 5.4 MEDIUM
Network
- - CouchCMS 2.2.1 contains a cross-site scripting vulnerability that allows authenticated attackers to execute arbitrary JavaScript by uploading malicious SVG files through the file upload functionality… CWE-79
Cross-site Scripting
CVE-2021-47955 2026-05-19 02:26 2026-05-17 Show GitHub Exploit DB Packet Storm
1689 8.8 HIGH
Network
- - TextPattern CMS 4.9.0-dev contains a remote code execution vulnerability that allows authenticated attackers to upload arbitrary PHP files by exploiting the plugin upload functionality. Attackers can… CWE-352
 Origin Validation Error
CVE-2021-47976 2026-05-19 02:26 2026-05-17 Show GitHub Exploit DB Packet Storm
1690 7.1 HIGH
Network
- - Fuel CMS 1.4.13 contains a blind SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'col' parameter in the Activity Log i… CWE-89
SQL Injection
CVE-2021-47980 2026-05-19 02:26 2026-05-17 Show GitHub Exploit DB Packet Storm