Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 7, 2026, 12:09 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
247941 10 危険 オラクル - Oracle Fusion Middleware の Oracle WebLogic Server コンポーネントにおける Node Manager の処理に関する脆弱性 CWE-noinfo
情報不足
CVE-2010-3510 2012-03-27 18:42 2011-01-19 Show GitHub Exploit DB Packet Storm
247942 3 注意 オラクル - Oracle Sun Products Suite の Oracle Explorer (Sun Explorer) コンポーネントにおける脆弱性 CWE-noinfo
情報不足
CVE-2010-3506 2012-03-27 18:42 2010-10-13 Show GitHub Exploit DB Packet Storm
247943 4.3 警告 オラクル - Oracle E-Business Suite の Oracle Applications Technology Stack コンポーネントにおける脆弱性 CWE-noinfo
情報不足
CVE-2010-3504 2012-03-27 18:42 2010-10-13 Show GitHub Exploit DB Packet Storm
247944 4 警告 オラクル - Oracle Siebel Suite の Siebel Core コンポーネントにおける脆弱性 CWE-noinfo
情報不足
CVE-2010-3502 2012-03-27 18:42 2010-10-13 Show GitHub Exploit DB Packet Storm
247945 6 警告 オラクル - Oracle Siebel Suite の Siebel Core - Highly Interactive Client コンポーネントにおける脆弱性 CWE-noinfo
情報不足
CVE-2010-3500 2012-03-27 18:42 2010-10-13 Show GitHub Exploit DB Packet Storm
247946 10 危険 TIBCO Software - TIBCO ActiveMatrix Service Grid などで使用される ActiveMatrix Runtime コンポーネントにおける任意のコードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2010-3491 2012-03-27 18:42 2010-10-19 Show GitHub Exploit DB Packet Storm
247947 6.5 警告 FreePBX - FreePBX の設定インターフェース の System Recordings コンポーネントにおけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2010-3490 2012-03-27 18:42 2010-09-28 Show GitHub Exploit DB Packet Storm
247948 4.3 警告 digitalworkroom - CMS Digital Workroom の netautor/napro4/home/login2.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2010-3489 2012-03-27 18:42 2010-09-22 Show GitHub Exploit DB Packet Storm
247949 5 警告 houbysoft - QuickShare におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2010-3488 2012-03-27 18:42 2010-09-22 Show GitHub Exploit DB Packet Storm
247950 5 警告 yellosoft - YelloSoft Pinky におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2010-3487 2012-03-27 18:42 2010-09-22 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 7, 2026, 4:22 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
531 6.3 MEDIUM
Network
- - A flaw has been found in nextlevelbuilder ui-ux-pro-max-skill up to 2.5.0. Affected by this vulnerability is the function _format_plugins of the file .claude/skills/ui-styling/scripts/tailwind_config… Update CWE-74
CWE-94
Injection
Code Injection
CVE-2026-7595 2026-05-6 04:17 2026-05-2 Show GitHub Exploit DB Packet Storm
532 4.3 MEDIUM
Network
- - A vulnerability has been found in nextlevelbuilder ui-ux-pro-max-skill up to 2.5.0. Affected by this issue is the function data.get of the file .claude/skills/design-system/scripts/generate-slide.py … Update CWE-79
CWE-94
Cross-site Scripting
Code Injection
CVE-2026-7596 2026-05-6 04:17 2026-05-2 Show GitHub Exploit DB Packet Storm
533 6.3 MEDIUM
Network
- - A vulnerability was detected in Dayoooun hwpx-mcp 0.2.0. This affects the function save_document/export_to_text/export_to_html of the file mcp-server/src/index.ts of the component MCP Interface. Perf… Update CWE-22
Path Traversal
CVE-2026-7599 2026-05-6 04:17 2026-05-2 Show GitHub Exploit DB Packet Storm
534 6.3 MEDIUM
Network
- - A flaw has been found in ArtMin96 yii2-mcp-server 1.0.2. This impacts the function yii_command_help/yii_execute_command of the file src/index.ts of the component MCP Interface. Executing a manipulati… Update CWE-77
CWE-78
Command Injection
OS Command 
CVE-2026-7600 2026-05-6 04:17 2026-05-2 Show GitHub Exploit DB Packet Storm
535 4.3 MEDIUM
Network
- - A vulnerability has been found in Open5GS up to 2.7.6. Affected is an unknown function of the file src/amf/gmm-handler.c of the component AMF. The manipulation of the argument reg_type leads to denia… Update CWE-404
 Improper Resource Shutdown or Release
CVE-2026-7601 2026-05-6 04:17 2026-05-2 Show GitHub Exploit DB Packet Storm
536 6.4 MEDIUM
Network
- - The Maxi Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `/wp-json/maxi-blocks/v1.0/style-card` REST API endpoint in all versions up to, and including, 2.1.9 due to i… Update CWE-79
Cross-site Scripting
CVE-2026-6378 2026-05-6 04:17 2026-05-2 Show GitHub Exploit DB Packet Storm
537 6.4 MEDIUM
Network
- - The Simple Link Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `qcopd-directory` shortcode in all versions up to, and including, 8.9.2. This is due to in… Update CWE-79
Cross-site Scripting
CVE-2026-7209 2026-05-6 04:17 2026-05-2 Show GitHub Exploit DB Packet Storm
538 6.3 MEDIUM
Network
- - A vulnerability was found in JeecgBoot up to 3.9.1. Affected by this vulnerability is an unknown functionality of the file /sys/fillRule/edit of the component FillRuleUtil Component. The manipulation… Update CWE-266
CWE-285
 Incorrect Privilege Assignment
Improper Authorization
CVE-2026-7602 2026-05-6 04:17 2026-05-2 Show GitHub Exploit DB Packet Storm
539 6.5 MEDIUM
Network
- - The Widgets for Social Photo Feed plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the '/trustindex_feed_hook_instagram/… Update CWE-200
Information Exposure
CVE-2025-14726 2026-05-6 04:17 2026-05-2 Show GitHub Exploit DB Packet Storm
540 9.8 CRITICAL
Network
- - The User Registration Advanced Fields plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'URAF_AJAX::method_upload' function in all versions up to… Update CWE-434
 Unrestricted Upload of File with Dangerous Type 
CVE-2026-4882 2026-05-6 04:17 2026-05-2 Show GitHub Exploit DB Packet Storm