Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 3, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2811 6.5 警告
Network
Abacre Limited Abacre Retail Point of Sale (POS) Abacre LimitedのAbacre Retail Point of Sale (POS)におけるSQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2025-67261 2026-02-2 19:30 2026-01-20 Show GitHub Exploit DB Packet Storm
2812 6.1 警告
Network
Abacre Limited Abacre Retail Point of Sale (POS) Abacre LimitedのAbacre Retail Point of Sale (POS)におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2025-67263 2026-02-2 19:30 2026-01-20 Show GitHub Exploit DB Packet Storm
2813 7.5 重要
Network
comfy ComfyUI Manager comfyのComfyUI Managerにおける保護されていない代替チャネルに関する脆弱性 CWE-420
保護されていない代替チャネル
CVE-2025-67303 2026-02-2 19:30 2026-01-5 Show GitHub Exploit DB Packet Storm
2814 9.8 緊急
Network
Qode Interactive Wilmer Qode InteractiveのWordPress用WilmerにおけるPHP リモートファイルインクルージョンの脆弱性 CWE-98
PHP リモートファイルインクルージョン
CVE-2025-67515 2026-02-2 19:30 2025-12-9 Show GitHub Exploit DB Packet Storm
2815 9.8 緊急
Network
yunjie.xiao openvpn-cms-flask yunjie.xiaoのopenvpn-cms-flaskにおける複数の脆弱性 CWE-74
CWE-77
CWE-77
CVE-2025-6775 2026-02-2 19:30 2025-06-27 Show GitHub Exploit DB Packet Storm
2816 9.8 緊急
Network
yunjie.xiao openvpn-cms-flask yunjie.xiaoのopenvpn-cms-flaskにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2025-6776 2026-02-2 19:30 2025-06-27 Show GitHub Exploit DB Packet Storm
2817 8.1 重要
Network
Qode Interactive Optimize Qode InteractiveのWordPress用OptimizeにおけるPHP リモートファイルインクルージョンの脆弱性 CWE-98
PHP リモートファイルインクルージョン
CVE-2025-67935 2026-02-2 19:30 2026-01-8 Show GitHub Exploit DB Packet Storm
2818 8.1 重要
Network
Qode Interactive Curly Qode InteractiveのWordPress用CurlyにおけるPHP リモートファイルインクルージョンの脆弱性 CWE-98
PHP リモートファイルインクルージョン
CVE-2025-67936 2026-02-2 19:30 2026-01-8 Show GitHub Exploit DB Packet Storm
2819 8.1 重要
Network
Qode Interactive Hendon Qode InteractiveのWordPress用HendonにおけるPHP リモートファイルインクルージョンの脆弱性 CWE-98
PHP リモートファイルインクルージョン
CVE-2025-67937 2026-02-2 19:30 2026-01-8 Show GitHub Exploit DB Packet Storm
2820 7.5 重要
Network
ThemeMove EduMall ThemeMoveのWordPress用EduMallにおけるPHP リモートファイルインクルージョンの脆弱性 CWE-98
PHP リモートファイルインクルージョン
CVE-2025-68061 2026-02-2 19:30 2025-12-16 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 3, 2026, 4:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
348751 - phpbb_group phpbb admin_ug_auth.php in phpBB 2.0.0 allows local users to gain administrator privileges by directly calling admin_ug_auth.php with modifed form fields such as "u". NVD-CWE-Other
CVE-2002-1537 2008-09-6 05:30 2003-03-31 Show GitHub Exploit DB Packet Storm
348752 - acuma acusend Acuma Acusend 4, and possibly earlier versions, allows remote authenticated users to read the reports of other users by inferring the full URL, whose name is easily predictable. NVD-CWE-Other
CVE-2002-1538 2008-09-6 05:30 2003-03-31 Show GitHub Exploit DB Packet Storm
348753 - alt-n mdaemon Buffer overflow in MDaemon POP server 6.0.7 and earlier allows remote authenticated users to cause a denial of service via long (1) DELE or (2) UIDL arguments. NVD-CWE-Other
CVE-2002-1539 2008-09-6 05:30 2003-03-31 Show GitHub Exploit DB Packet Storm
348754 - working_resources_inc. badblue BadBlue 1.7 allows remote attackers to bypass password protections for directories and files via an HTTP request containing an extra / (slash). NVD-CWE-Other
CVE-2002-1541 2008-09-6 05:30 2003-03-31 Show GitHub Exploit DB Packet Storm
348755 - solarwinds tftp_server SolarWinds TFTP server 5.0.55 and earlier allows remote attackers to cause a denial of service (crash) via a large UDP datagram, possibly triggering a buffer overflow. NVD-CWE-Other
CVE-2002-1542 2008-09-6 05:30 2003-03-31 Show GitHub Exploit DB Packet Storm
348756 - netbsd netbsd Buffer overflow in trek on NetBSD 1.5 through 1.5.3 allows local users to gain privileges via long keyboard input. NVD-CWE-Other
CVE-2002-1543 2008-09-6 05:30 2003-03-31 Show GitHub Exploit DB Packet Storm
348757 - cooolsoft personal_ftp_server Directory traversal vulnerability in CooolSoft Personal FTP Server 2.24 allows remote attackers to read or modify arbitrary files via .. (dot dot) sequences in the commands (1) LIST (ls), (2) mkdir, … NVD-CWE-Other
CVE-2002-1544 2008-09-6 05:30 2003-03-31 Show GitHub Exploit DB Packet Storm
348758 - cooolsoft personal_ftp_server CooolSoft Personal FTP Server 2.24 allows remote attackers to obtain the absolute pathname of the FTP root via a PWD command, which includes the full path in the response. NVD-CWE-Other
CVE-2002-1545 2008-09-6 05:30 2003-03-31 Show GitHub Exploit DB Packet Storm
348759 - brs webweaver BRS WebWeaver Web Server 1.01 allows remote attackers to bypass password protections for files and directories via an HTTP request containing a "/./" sequence. NVD-CWE-Other
CVE-2002-1546 2008-09-6 05:30 2003-03-31 Show GitHub Exploit DB Packet Storm
348760 - juniper netscreen_screenos Netscreen running ScreenOS 4.0.0r6 and earlier allows remote attackers to cause a denial of service via a malformed SSH packet to the Secure Command Shell (SCS) management interface, as demonstrated … NVD-CWE-Other
CVE-2002-1547 2008-09-6 05:30 2003-03-31 Show GitHub Exploit DB Packet Storm