Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
241481 7.8 危険 ARRIS Group - Arris Cadant C3 CMTS におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-2796 2012-06-26 15:46 2007-06-12 Show GitHub Exploit DB Packet Storm
241482 7.5 危険 Geeklog - Geeklog の ImageImageMagick.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-2793 2012-06-26 15:46 2007-05-21 Show GitHub Exploit DB Packet Storm
241483 7.5 危険 com yanc - Mambo の yanc コンポーネントにおける SQL インジェクションの脆弱性 - CVE-2007-2792 2012-06-26 15:46 2007-05-21 Show GitHub Exploit DB Packet Storm
241484 6.8 警告 eSyndiCat - eSyndiCat Pro の manage-admins.php における追加の管理者アカウントを作成される脆弱性 - CVE-2007-2785 2012-06-26 15:46 2007-05-21 Show GitHub Exploit DB Packet Storm
241485 7.8 危険 Globus - Globus Toolkit の globus-job-manager におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-2784 2012-06-26 15:46 2007-05-21 Show GitHub Exploit DB Packet Storm
241486 7.5 危険 AlstraSoft - AlstraSoft Template Seller Pro の admin/addsptemplate.php における無制限にファイルをアップロードされる脆弱性 - CVE-2007-2777 2012-06-26 15:46 2007-05-21 Show GitHub Exploit DB Packet Storm
241487 10 危険 AlstraSoft - AlstraSoft Template Seller Pro における管理アクセス権を取得される脆弱性 - CVE-2007-2776 2012-06-26 15:46 2007-05-21 Show GitHub Exploit DB Packet Storm
241488 10 危険 AlstraSoft - AlstraSoft Live Support における管理アクセス権を取得される脆弱性 - CVE-2007-2775 2012-06-26 15:46 2007-05-21 Show GitHub Exploit DB Packet Storm
241489 7.8 危険 CA Technologies - CA BrightStor Backup の caloggerd.exe におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-2772 2012-06-26 15:46 2007-05-16 Show GitHub Exploit DB Packet Storm
241490 7.2 危険 backup manager - Backup Manager の lib/backup-methods.sh におけるパスワードを取得される脆弱性 CWE-255
証明書・パスワード管理
CVE-2007-2766 2012-06-26 15:46 2007-05-18 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 19, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
151 9.1 CRITICAL
Network
apache apisix Header injection vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-auth plugin to inject malicious headers. This issue affects Apache APISIX: from 2… Update CWE-75
Special Element Injection
CVE-2026-31908 2026-04-18 03:40 2026-04-14 Show GitHub Exploit DB Packet Storm
152 7.5 HIGH
Network
apache apisix Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. This can occur due to `ssl_verify` in openid-connect plugin configuration being set to false by default. This issue af… Update CWE-319
Cleartext Transmission of Sensitive Information
CVE-2026-31923 2026-04-18 03:39 2026-04-14 Show GitHub Exploit DB Packet Storm
153 5.3 MEDIUM
Network
apache apisix Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. tencent-cloud-cls log export uses plaintext HTTP This issue affects Apache APISIX: from 2.99.0 through 3.15.0. Users … Update CWE-319
Cleartext Transmission of Sensitive Information
CVE-2026-31924 2026-04-18 03:38 2026-04-14 Show GitHub Exploit DB Packet Storm
154 8.1 HIGH
Network
apache airflow The example example_xcom that was included in airflow documentation implemented unsafe pattern of reading value from xcom in the way that could be exploited to allow UI user who had access to modify … New CWE-94
Code Injection
CVE-2025-54550 2026-04-18 03:38 2026-04-15 Show GitHub Exploit DB Packet Storm
155 6.5 MEDIUM
Network
apache airflow The `access_key` and `connection_string` connection properties were not marked as sensitive names in secrets masker. This means that user with read permission could see the values in Connection UI, a… New CWE-200
Information Exposure
CVE-2026-25219 2026-04-18 03:37 2026-04-15 Show GitHub Exploit DB Packet Storm
156 10.0 CRITICAL
Network
praison praisonai PraisonAI is a multi-agent teams system. Prior to 4.5.128, the /api/v1/runs endpoint accepts an arbitrary webhook_url in the request body with no URL validation. When a submitted job completes (succe… Update CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-40114 2026-04-18 03:36 2026-04-10 Show GitHub Exploit DB Packet Storm
157 7.5 HIGH
Network
praison praisonai PraisonAI is a multi-agent teams system. Prior to 4.5.128, the WSGI-based recipe registry server (server.py) reads the entire HTTP request body into memory based on the client-supplied Content-Length… Update CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2026-40115 2026-04-18 03:34 2026-04-10 Show GitHub Exploit DB Packet Storm
158 7.5 HIGH
Network
praison praisonai PraisonAI is a multi-agent teams system. Prior to 4.5.128, the /media-stream WebSocket endpoint in PraisonAI's call module accepts connections from any client without authentication or Twilio signatu… Update CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2026-40116 2026-04-18 03:33 2026-04-10 Show GitHub Exploit DB Packet Storm
159 6.5 MEDIUM
Network
juniper junos_os_evolved A Function Call With Incorrect Argument Type vulnerability in the sensor interface of Juniper Networks Junos OS Evolved on PTX Series allows a network-based, authenticated attacker with low privilege… Update CWE-686
 Function Call With Incorrect Argument Type
CVE-2026-33783 2026-04-18 03:27 2026-04-10 Show GitHub Exploit DB Packet Storm
160 7.5 HIGH
Network
praison praisonaiagents PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, read_skill_file() in skill_tools.py allows reading arbitrary files from the filesystem by accepting an unrestricted skill_path paramet… Update CWE-862
 Missing Authorization
CVE-2026-40117 2026-04-18 03:23 2026-04-10 Show GitHub Exploit DB Packet Storm