Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 8, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
254771 6.8 警告 マイクロソフト - Microsoft Windows の kernel における権限を取得される脆弱性 CWE-20
不適切な入力確認
CVE-2009-1127 2010-01-4 15:24 2009-11-10 Show GitHub Exploit DB Packet Storm
254772 10 危険 マイクロソフト - Microsoft Windows の License Logging Server (llssrv.exe) における任意のコードを実行される脆弱性 CWE-119
バッファエラー
CVE-2009-2523 2010-01-4 15:24 2009-11-10 Show GitHub Exploit DB Packet Storm
254773 9.3 危険 マイクロソフト - Microsoft Windows の Web Services on Devices API (WSDAPI) における任意のコードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2009-2512 2010-01-4 15:23 2009-11-10 Show GitHub Exploit DB Packet Storm
254774 10 危険 アップル
VMware
サン・マイクロシステムズ
- Sun Java SE の Provider クラスにおける詳細不明な脆弱性 CWE-noinfo
情報不足
CVE-2009-2722 2010-01-4 14:56 2009-08-10 Show GitHub Exploit DB Packet Storm
254775 10 危険 アップル
VMware
サン・マイクロシステムズ
- Sun Java SE の Provider クラスにおける詳細不明な脆弱性 CWE-noinfo
情報不足
CVE-2009-2723 2010-01-4 14:55 2009-08-10 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 8, 2026, 4:54 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
3641 4.3 MEDIUM
Network
- - A vulnerability was determined in SourceCodester Diary App 1.0. The affected element is an unknown function of the file diary.php. Executing a manipulation can lead to cross-site request forgery. The… CWE-352
CWE-862
 Origin Validation Error
 Missing Authorization
CVE-2026-4968 2026-04-25 01:36 2026-03-28 Show GitHub Exploit DB Packet Storm
3642 3.5 LOW
Network
- - A vulnerability was identified in code-projects Social Networking Site 1.0. The impacted element is an unknown function of the file /home.php of the component Alert Handler. The manipulation of the a… CWE-79
CWE-94
Cross-site Scripting
Code Injection
CVE-2026-4969 2026-04-25 01:36 2026-03-28 Show GitHub Exploit DB Packet Storm
3643 6.3 MEDIUM
Network
- - A security flaw has been discovered in code-projects Social Networking Site 1.0. This affects an unknown function of the file delete_photos.php of the component Endpoint. The manipulation of the argu… CWE-74
CWE-89
Injection
SQL Injection
CVE-2026-4970 2026-04-25 01:36 2026-03-28 Show GitHub Exploit DB Packet Storm
3644 4.3 MEDIUM
Network
- - A weakness has been identified in SourceCodester Note Taking App up to 1.0. This impacts an unknown function. This manipulation causes cross-site request forgery. The attack is possible to be carried… CWE-352
CWE-862
 Origin Validation Error
 Missing Authorization
CVE-2026-4971 2026-04-25 01:36 2026-03-28 Show GitHub Exploit DB Packet Storm
3645 2.4 LOW
Network
- - A security vulnerability has been detected in code-projects Online Reviewer System up to 1.0. Affected is an unknown function of the file /system/system/students/assessments/databank/btn_functions.ph… CWE-79
CWE-94
Cross-site Scripting
Code Injection
CVE-2026-4972 2026-04-25 01:36 2026-03-28 Show GitHub Exploit DB Packet Storm
3646 3.5 LOW
Network
- - A vulnerability was detected in SourceCodester Online Quiz System up to 1.0. Affected by this vulnerability is an unknown functionality of the file endpoint/add-question.php. Performing a manipulatio… CWE-79
CWE-94
Cross-site Scripting
Code Injection
CVE-2026-4973 2026-04-25 01:36 2026-03-28 Show GitHub Exploit DB Packet Storm
3647 4.3 MEDIUM
Network
- - A vulnerability was identified in dloebl CGIF up to 0.5.2. This vulnerability affects the function cgif_addframe of the file src/cgif.c of the component GIF Image Handler. The manipulation of the arg… CWE-189
CWE-190
Numeric Errors
 Integer Overflow or Wraparound
CVE-2026-4985 2026-04-25 01:36 2026-03-28 Show GitHub Exploit DB Packet Storm
3648 7.3 HIGH
Network
- - A security vulnerability has been detected in chatwoot up to 4.11.1. The affected element is an unknown function of the file /app/login of the component Signup Endpoint. Such manipulation of the argu… CWE-266
CWE-285
 Incorrect Privilege Assignment
Improper Authorization
CVE-2026-4990 2026-04-25 01:36 2026-03-28 Show GitHub Exploit DB Packet Storm
3649 8.0 HIGH
Network
- - The Ultimate Member plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.11.2. This is due to the '{usermeta:password_reset_link}' template tag… CWE-285
Improper Authorization
CVE-2026-4248 2026-04-25 01:36 2026-03-28 Show GitHub Exploit DB Packet Storm
3650 8.0 HIGH
Network
- - El plugin Ultimate Member para WordPress es vulnerable a la exposición de información sensible en todas las versiones hasta e incluyendo la 2.11.2. Esto se debe a que la etiqueta de plantilla '{userm… CWE-285
Improper Authorization
CVE-2026-4248 2026-04-25 01:36 2026-03-28 Show GitHub Exploit DB Packet Storm