Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 21, 2026, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
251681 4.3 警告 VideoLAN - VLC media player におけるサービス運用妨害 (クラッシュ) の脆弱性 CWE-399
リソース管理の問題
CVE-2012-0904 2012-01-25 10:54 2012-01-20 Show GitHub Exploit DB Packet Storm
251682 4.3 警告 VMware - VMware Zimbra Desktop におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-0903 2012-01-25 10:51 2012-01-20 Show GitHub Exploit DB Packet Storm
251683 5 警告 AirTies - AirTies Air 4450 におけるサービス運用妨害 (リブート) の脆弱性 CWE-noinfo
情報不足
CVE-2012-0902 2012-01-25 10:43 2012-01-20 Show GitHub Exploit DB Packet Storm
251684 4.3 警告 attenzione - WordPress 用 YouSayToo auto-publishing プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-0901 2012-01-25 10:39 2012-01-20 Show GitHub Exploit DB Packet Storm
251685 4.3 警告 Beehive Forum - Beehive Forum におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-0900 2012-01-25 10:35 2012-01-20 Show GitHub Exploit DB Packet Storm
251686 4.3 警告 Annuaire PHP - Annuaire PHP におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-0899 2012-01-25 10:32 2012-01-20 Show GitHub Exploit DB Packet Storm
251687 5 警告 camaleo - WordPress 用 myEASYbackup プラグインにおけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2012-0898 2012-01-25 10:30 2012-01-20 Show GitHub Exploit DB Packet Storm
251688 5 警告 Tom Braider - WordPress 用 Count Per Day モジュールにおける絶対パストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2012-0896 2012-01-25 10:23 2012-01-20 Show GitHub Exploit DB Packet Storm
251689 4.3 警告 Tom Braider - WordPress 用 Count Per Day モジュールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-0895 2012-01-25 10:21 2012-01-20 Show GitHub Exploit DB Packet Storm
251690 9.3 危険 IBM - IBM Lotus Symphony の vclmi.dll における整数オーバーフローの脆弱性 CWE-189
数値処理の問題
CVE-2012-0192 2012-01-24 16:45 2012-01-23 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 22, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
4491 9.8 CRITICAL
Network
oppo coloros_assistant ColorOS Assistant has an unauthenticated start-download channel, leading to file path traversal. CWE-23
CWE-22
 Relative Path Traversal
Path Traversal
CVE-2026-22070 2026-05-5 11:53 2026-04-30 Show GitHub Exploit DB Packet Storm
4492 7.5 HIGH
Network
4d server Unauthenticated attackers can exploit a weakness in the XML parser functionality of the SOAP endpoints in 4D server. This allows them to obtain read access to files on the application server and adja… CWE-611
XXE
CVE-2024-39847 2026-05-5 11:51 2026-04-30 Show GitHub Exploit DB Packet Storm
4493 9.8 CRITICAL
Network
pylixm django-mdeditor All versions of the package django-mdeditor are vulnerable to Missing Authentication for Critical Function in the image upload endpoint. An attacker can upload malicious files and achieve arbitrary c… CWE-306
Missing Authentication for Critical Function
CVE-2025-13030 2026-05-5 11:50 2026-04-30 Show GitHub Exploit DB Packet Storm
4494 4.8 MEDIUM
Network
gnu wget2 wget2 accepts a server certificate with incorrect Key Usage (KU) or Extended Key Usage (EKU). If the attackers compromise a certificate (with the associated private key) issued for a different purpos… CWE-20
 Improper Input Validation 
CVE-2026-1858 2026-05-5 11:47 2026-04-30 Show GitHub Exploit DB Packet Storm
4495 9.8 CRITICAL
Network
tenda w3002r_firmware
a302_firmware
w309r_firmware
Tenda W3002R/A302/W309R wireless routers version V5.07.64_en contain a cookie session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient se… CWE-290
 Authentication Bypass by Spoofing
CVE-2018-25317 2026-05-5 11:46 2026-04-30 Show GitHub Exploit DB Packet Storm
4496 8.8 HIGH
Network
geovision gv-lpc2011_firmware
gv-lpc2211_firmware
An os command injection vulnerability exists in the DdnsSetting.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted DDNS configuration can lead to arbitrary command execution. An… CWE-78
OS Command 
CVE-2026-42364 2026-05-5 11:45 2026-05-4 Show GitHub Exploit DB Packet Storm
4497 6.5 MEDIUM
Network
geovision gv-lpc2011_firmware
gv-lpc2211_firmware
A privilege escalation vulnerability exists in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted HTTP request can lead to credentials leak. An attacker … CWE-522
 Insufficiently Protected Credentials
CVE-2026-42367 2026-05-5 11:45 2026-05-4 Show GitHub Exploit DB Packet Storm
4498 7.5 HIGH
Network
geovision gv-lpc2011_firmware
gv-lpc2211_firmware
A guessable session cookie vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted series of HTTP requests can lead to an authentication bypas. … CWE-341
 Predictable from Observable State
CVE-2026-42365 2026-05-5 11:44 2026-05-4 Show GitHub Exploit DB Packet Storm
4499 6.1 MEDIUM
Network
geovision gv-lpc2011_firmware
gv-lpc2211_firmware
Multiple reflected cross-site scripting (xss) vulnerabilities exist in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted malicious url can lead to an ar… CWE-79
Cross-site Scripting
CVE-2026-42366 2026-05-5 11:43 2026-05-4 Show GitHub Exploit DB Packet Storm
4500 9.9 CRITICAL
Network
geovision gv-lpc2011_firmware
gv-lpc2211_firmware
A privilege escalation vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted HTTP request can lead to execute priviledged operation. An attack… CWE-266
 Incorrect Privilege Assignment
CVE-2026-42368 2026-05-5 11:43 2026-05-4 Show GitHub Exploit DB Packet Storm