Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
241671 10 危険 extremail - eXtremail における DNS のなりすましを実行される脆弱性 - CVE-2007-2188 2012-06-26 15:46 2007-04-24 Show GitHub Exploit DB Packet Storm
241672 10 危険 extremail - eXtremail におけるスタックベースのバッファオーバーフローの脆弱性 - CVE-2007-2187 2012-06-26 15:46 2007-04-24 Show GitHub Exploit DB Packet Storm
241673 5 警告 Foxit Software Inc - Foxit Reader におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-2186 2012-06-26 15:46 2007-04-24 Show GitHub Exploit DB Packet Storm
241674 7.6 危険 アップル - Safari などで使用される Apple QuickTime Java 拡張における任意のコードを実行される脆弱性 - CVE-2007-2175 2012-06-26 15:46 2007-04-24 Show GitHub Exploit DB Packet Storm
241675 7.2 危険 チェック・ポイント・ソフトウェア・テクノロジーズ - Check Point ZoneAlarm の ZoneAlarm SRE における任意のファイルを実行される脆弱性 - CVE-2007-2174 2012-06-26 15:46 2007-04-24 Show GitHub Exploit DB Packet Storm
241676 10 危険 double precision incorporated
Gentoo Linux
- Courier-IMAP の courier-imapd.indirect における任意のコマンドを実行される脆弱性 - CVE-2007-2173 2012-06-26 15:46 2007-04-24 Show GitHub Exploit DB Packet Storm
241677 7.5 危険 aimstats - AimStats の process.php における PHP コードを挿入される脆弱性 - CVE-2007-2168 2012-06-26 15:46 2007-04-22 Show GitHub Exploit DB Packet Storm
241678 7.5 危険 aimstats - AimStats の process.php における PHP コードを挿入される脆弱性 - CVE-2007-2167 2012-06-26 15:46 2007-04-22 Show GitHub Exploit DB Packet Storm
241679 5 警告 アップル - Apple Safari におけるサービス運用妨害 (DoS) 状態となる脆弱性 - CVE-2007-2163 2012-06-26 15:46 2007-04-22 Show GitHub Exploit DB Packet Storm
241680 7.8 危険 GNU Project
Mozilla Foundation
- Mozilla Firefox におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2007-2162 2012-06-26 15:46 2007-04-22 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 18, 2026, 4:11 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
101 4.9 MEDIUM
Network
- - October is a Content Management System (CMS) and web platform. Versions prior to 3.7.13 and versions 4.0.0 through 4.1.4 contain a sandbox bypass vulnerability in the optional Twig safe mode feature … New CWE-284
CWE-693
Improper Access Control
 Protection Mechanism Failure
CVE-2026-22692 2026-04-18 00:38 2026-04-15 Show GitHub Exploit DB Packet Storm
102 9.8 CRITICAL
Network
- - An issue pertaining to CWE-843: Access of Resource Using Incompatible Type was discovered in transloadit uppy v0.25.6. New CWE-843
Type Confusion
CVE-2025-70023 2026-04-18 00:38 2026-04-15 Show GitHub Exploit DB Packet Storm
103 - - - A vulnerability exists in FlashBlade whereby sensitive information may be logged under specific conditions. New CWE-532
 Inclusion of Sensitive Information in Log Files
CVE-2026-0207 2026-04-18 00:38 2026-04-15 Show GitHub Exploit DB Packet Storm
104 - - - Under certain administrative conditions, FlashArray Purity may apply snapshot retention policies earlier or later than configured. New CWE-783
 Operator Precedence Logic Error
CVE-2026-0209 2026-04-18 00:38 2026-04-15 Show GitHub Exploit DB Packet Storm
105 - - - October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a Stored Cross-Site Scripting (XSS) vulnerability in the Backend Editor Settings. The Markup… New CWE-79
Cross-site Scripting
CVE-2026-24906 2026-04-18 00:38 2026-04-15 Show GitHub Exploit DB Packet Storm
106 - - - October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a stored cross-site scripting (XSS) vulnerability in the Event Log mail preview feature. Whe… New CWE-79
Cross-site Scripting
CVE-2026-24907 2026-04-18 00:38 2026-04-15 Show GitHub Exploit DB Packet Storm
107 - - - Chamilo is an open-source learning management system (LMS). Version 2.0.0-RC.2 contains a SQL Injection vulnerability in the statistics AJAX endpoint, which is an incomplete fix for CVE-2026-30881. W… New CWE-89
SQL Injection
CVE-2026-33714 2026-04-18 00:38 2026-04-15 Show GitHub Exploit DB Packet Storm
108 4.3 MEDIUM
Network
- - Docmost is open-source collaborative wiki and documentation software. An authorization bypass vulnerability in versions 0.70.0 through 0.70.2 exposes restricted child page titles and text snippets th… New CWE-285
Improper Authorization
CVE-2026-33146 2026-04-18 00:38 2026-04-15 Show GitHub Exploit DB Packet Storm
109 7.7 HIGH
Network
- - In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _… New CWE-843
Type Confusion
CVE-2026-40683 2026-04-18 00:38 2026-04-15 Show GitHub Exploit DB Packet Storm
110 8.8 HIGH
Network
- - openITCOCKPIT is an open source monitoring tool built for different monitoring engines. openITCOCKPIT Community Edition prior to version 5.5.2 contains a command injection vulnerability that allows a… New CWE-20
CWE-78
 Improper Input Validation 
OS Command 
CVE-2026-24893 2026-04-18 00:38 2026-04-15 Show GitHub Exploit DB Packet Storm