Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 9, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
251721 4.3 警告 マイクロソフト - Microsoft Internet Explorer 6 から 8 における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2011-1258 2011-06-28 12:16 2011-06-14 Show GitHub Exploit DB Packet Storm
251722 9.3 危険 マイクロソフト - Microsoft Internet Explorer 6 から 8 における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2011-1256 2011-06-28 12:15 2011-06-14 Show GitHub Exploit DB Packet Storm
251723 9.3 危険 マイクロソフト - Microsoft Internet Explorer 6 から 8 の HTML+TIME における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2011-1255 2011-06-28 12:14 2011-06-14 Show GitHub Exploit DB Packet Storm
251724 9.3 危険 マイクロソフト - Microsoft Internet Explorer 6 から 8 における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2011-1254 2011-06-28 12:13 2011-06-14 Show GitHub Exploit DB Packet Storm
251725 9.3 危険 マイクロソフト - Microsoft Internet Explorer 6 から 9 における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2011-1250 2011-06-28 12:12 2011-06-14 Show GitHub Exploit DB Packet Storm
251726 9.3 危険 マイクロソフト - Microsoft Internet Explorer 7 から 9 における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2011-1262 2011-06-28 12:11 2011-06-14 Show GitHub Exploit DB Packet Storm
251727 4.9 警告 Linux
レッドハット
- Linux kernel の fs/eventpoll.c におけるサービス運用妨害 (DoS)の脆弱性 CWE-399
リソース管理の問題
CVE-2011-1082 2011-06-28 10:03 2011-04-4 Show GitHub Exploit DB Packet Storm
251728 4.9 警告 Linux
レッドハット
- Linux kernel の mm/huge_memory.c におけるサービス運用妨害 (メモリ破損) の脆弱性 CWE-399
リソース管理の問題
CVE-2011-0999 2011-06-28 10:01 2011-02-23 Show GitHub Exploit DB Packet Storm
251729 1.9 注意 Linux
レッドハット
- Linux kernel の arch/x86/kvm/x86.c における重要な情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2010-3881 2011-06-28 09:53 2010-12-9 Show GitHub Exploit DB Packet Storm
251730 9.3 危険 マイクロソフト - Microsoft Internet Explorer 8 および 9 における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2011-1260 2011-06-27 16:23 2011-06-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 9, 2026, 5:07 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
3321 6.7 MEDIUM
Local
microsoft windows_10_1607
windows_10_1809
windows_10_21h2
windows_10_22h2
windows_server_2016
windows_server_2019
windows_server_2022
Reliance on untrusted inputs in a security decision in Windows Boot Loader allows an authorized attacker to bypass a security feature locally. CWE-807
 Reliance on Untrusted Inputs in a Security Decision
CVE-2026-0390 2026-04-25 05:17 2026-04-15 Show GitHub Exploit DB Packet Storm
3322 5.3 MEDIUM
Network
- - Xerte Online Toolkits versions 3.15 and earlier contain an information disclosure vulnerability that allows unauthenticated attackers to retrieve the full server-side filesystem path of the applicati… CWE-497
 Exposure of Sensitive System Information to an Unauthorized Control Sphere
CVE-2026-41459 2026-04-25 05:16 2026-04-23 Show GitHub Exploit DB Packet Storm
3323 9.8 CRITICAL
Network
- - Xerte Online Toolkits versions 3.15 and earlier contain an incomplete input validation vulnerability in the elFinder connector endpoint that fails to block PHP-executable extensions .php4 due to an i… CWE-184
 Incomplete Blacklist
CVE-2026-34415 2026-04-25 05:16 2026-04-23 Show GitHub Exploit DB Packet Storm
3324 7.1 HIGH
Network
- - Xerte Online Toolkits versions 3.15 and earlier contain a relative path traversal vulnerability in the elFinder connector endpoint at /editor/elfinder/php/connector.php where the name parameter in re… CWE-22
Path Traversal
CVE-2026-34414 2026-04-25 05:16 2026-04-23 Show GitHub Exploit DB Packet Storm
3325 8.6 HIGH
Network
- - Xerte Online Toolkits versions 3.15 and earlier contain a missing authentication vulnerability in the elFinder connector endpoint at /editor/elfinder/php/connector.php where an HTTP redirect to unaut… CWE-497
 Exposure of Sensitive System Information to an Unauthorized Control Sphere
CVE-2026-34413 2026-04-25 05:16 2026-04-23 Show GitHub Exploit DB Packet Storm
3326 5.4 MEDIUM
Network
- - Missing Authorization vulnerability in merkulove Buttoner for Elementor buttoner-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Buttoner for Elem… CWE-862
 Missing Authorization
CVE-2025-68085 2026-04-25 05:16 2025-12-16 Show GitHub Exploit DB Packet Storm
3327 6.5 MEDIUM
Network
- - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeNectar Salient Shortcodes salient-shortcodes allows Stored XSS.This issue affects Salient Sh… CWE-79
Cross-site Scripting
CVE-2025-68079 2026-04-25 05:16 2025-12-16 Show GitHub Exploit DB Packet Storm
3328 6.5 MEDIUM
Network
- - Authorization Bypass Through User-Controlled Key vulnerability in g5theme Essential Real Estate essential-real-estate allows Exploiting Incorrectly Configured Access Control Security Levels.This issu… CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2025-68071 2026-04-25 05:16 2025-12-16 Show GitHub Exploit DB Packet Storm
3329 7.5 HIGH
Network
- - Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PenciDesign Soledad soledad allows PHP Local File Inclusion.This issue affects… CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2025-68066 2026-04-25 05:16 2025-12-16 Show GitHub Exploit DB Packet Storm
3330 8.5 HIGH
Network
- - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themefic Hydra Booking hydra-booking allows SQL Injection.This issue affects Hydra Booking: from … CWE-89
SQL Injection
CVE-2025-68055 2026-04-25 05:16 2025-12-16 Show GitHub Exploit DB Packet Storm