Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
691 8.1 重要
Network
ThemeMove EduMall ThemeMoveのWordPress用EduMallにおけるPHP リモートファイルインクルージョンの脆弱性 CWE-98
PHP リモートファイルインクルージョン
CVE-2025-59564 2026-02-2 19:31 2025-10-22 Show GitHub Exploit DB Packet Storm
692 8.1 重要
Network
ThemeMove Minimogwp ThemeMoveのWordPress用MinimogwpにおけるPHP リモートファイルインクルージョンの脆弱性 CWE-98
PHP リモートファイルインクルージョン
CVE-2025-60069 2026-02-2 19:31 2025-12-18 Show GitHub Exploit DB Packet Storm
693 10 緊急
Network
GongRzhe Terminal Controller for MCP GongRzheのTerminal Controller for MCPにおけるコマンドインジェクションの脆弱性 CWE-77
コマンドインジェクション
CVE-2025-61492 2026-02-2 19:31 2026-01-7 Show GitHub Exploit DB Packet Storm
694 7.5 重要
Network
wpwebelite Follow My Blog Post WPWeb EliteのWordPress用Follow My Blog Postにおける認可されていない制御領域への重要情報の漏えいに関する脆弱性 CWE-497
認可されていない制御領域への重要情報の漏えい
CVE-2025-64258 2026-02-2 19:31 2025-12-18 Show GitHub Exploit DB Packet Storm
695 5.4 警告
Network
Qode Interactive Bard Qode InteractiveのWordPress用Bardにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2025-64368 2026-02-2 19:31 2025-10-31 Show GitHub Exploit DB Packet Storm
696 5.3 警告
Network
XWiki Full Calendar Macro (macro-fullcalendar-pom) XWikiのFull Calendar Macro (macro-fullcalendar-pom)における情報漏えいに関する脆弱性 CWE-200
情報漏えい
CVE-2025-65090 2026-02-2 19:31 2026-01-10 Show GitHub Exploit DB Packet Storm
697 10 緊急
Network
XWiki Full Calendar Macro (macro-fullcalendar-pom) XWikiのFull Calendar Macro (macro-fullcalendar-pom)におけるSQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2025-65091 2026-02-2 19:31 2026-01-10 Show GitHub Exploit DB Packet Storm
698 6.5 警告
Network
Mega-Fence Project Mega-Fence Mega-Fence ProjectのMega-Fenceにおけるセキュリティ決定の信頼できない入力への依存に関する脆弱性 CWE-807
セキュリティ決定の信頼できない入力への依存
CVE-2025-65328 2026-02-2 19:31 2026-01-5 Show GitHub Exploit DB Packet Storm
699 7.5 重要
Network
WebPros International GmbH Plesk Obsidian WebPros International GmbHのPlesk Obsidianにおけるリソースの枯渇に関する脆弱性 CWE-400
リソースの枯渇
CVE-2025-65518 2026-02-2 19:31 2026-01-8 Show GitHub Exploit DB Packet Storm
700 8.8 重要
Network
Qode Interactive Powerlift Qode InteractiveのWordPress用Powerliftにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2025-66532 2026-02-2 19:31 2025-12-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 26, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
283411 - bibtex mase Multiple PHP remote file inclusion vulnerabilities in bibtex mase beta 2.0 allow remote attackers to execute arbitrary PHP code via a URL in the bibtexrootrel parameter to (1) unavailable.php, (2) so… CWE-94
Code Injection
CVE-2007-2260 2018-10-17 01:42 2007-04-26 Show GitHub Exploit DB Packet Storm
283412 - realink c-arbre PHP remote file inclusion vulnerability in espaces/communiques/annotations.php in C-Arbre 0.6PR7 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter… NVD-CWE-Other
CVE-2007-2261 2018-10-17 01:42 2007-04-26 Show GitHub Exploit DB Packet Storm
283413 - sinato jmuffin Multiple PHP remote file inclusion vulnerabilities in html/php/detail.php in Sinato jmuffin allow remote attackers to execute arbitrary PHP code via a URL in the (1) relPath and (2) folder parameters… CWE-94
Code Injection
CVE-2007-2262 2018-10-17 01:42 2007-04-26 Show GitHub Exploit DB Packet Storm
283414 - realnetworks realone_player
realplayer
realplayer_enterprise
Heap-based buffer overflow in RealNetworks RealPlayer 10.0, 10.1, and possibly 10.5, RealOne Player, and RealPlayer Enterprise allows remote attackers to execute arbitrary code via an SWF (Flash) fil… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2007-2263 2018-10-17 01:42 2007-11-1 Show GitHub Exploit DB Packet Storm
283415 - realnetworks realone_player
realplayer
realplayer_enterprise
Heap-based buffer overflow in RealNetworks RealPlayer 8, 10, 10.1, and possibly 10.5; RealOne Player 1 and 2; and RealPlayer Enterprise allows remote attackers to execute arbitrary code via a RAM (.r… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2007-2264 2018-10-17 01:42 2007-11-1 Show GitHub Exploit DB Packet Storm
283416 - phpee ya_book Cross-site scripting (XSS) vulnerability in YA Book 0.98-alpha allows remote attackers to inject arbitrary web script or HTML via the City field in a sign action in index.php. NVD-CWE-Other
CVE-2007-2265 2018-10-17 01:42 2007-04-26 Show GitHub Exploit DB Packet Storm
283417 - progress webspeed_messenger Progress Webspeed Messenger allows remote attackers to read, create, modify, and execute arbitrary files by invoking webutil/_cpyfile.p in the WService parameter to (1) cgiip.exe or (2) wsisa.dll in … NVD-CWE-Other
CVE-2007-2266 2018-10-17 01:42 2007-04-26 Show GitHub Exploit DB Packet Storm
283418 - plogger plogger Session fixation vulnerability in Plogger allows remote attackers to hijack web sessions by setting the PHPSESSID parameter. CWE-287
Improper Authentication
CVE-2007-2277 2018-10-17 01:42 2007-04-26 Show GitHub Exploit DB Packet Storm
283419 - dcp-portal dcp-portal Multiple PHP remote file inclusion vulnerabilities in DCP-Portal 6.1.1 allow remote attackers to execute arbitrary PHP code via a URL in (1) the path parameter to library/adodb/adodb.inc.php, (2) the… NVD-CWE-Other
CVE-2007-2278 2018-10-17 01:42 2007-04-26 Show GitHub Exploit DB Packet Storm
283420 - symantec veritas_storage_foundation The Scheduler Service (VxSchedService.exe) in Symantec Storage Foundation for Windows 5.0 allows remote attackers to bypass authentication and execute arbitrary code via certain requests to the servi… CWE-264
Permissions, Privileges, and Access Controls
CVE-2007-2279 2018-10-17 01:42 2007-06-5 Show GitHub Exploit DB Packet Storm