Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
701 4.8 警告
Network
Hotwire Turbo HotwireのTurboにおける競合状態に関する脆弱性 CWE-362
競合状態
CVE-2025-66803 2026-02-2 19:30 2026-01-20 Show GitHub Exploit DB Packet Storm
702 7.5 重要
Network
Manos Websocket Server ManosのWebsocket Serverにおける入力確認に関する脆弱性 CWE-20
不適切な入力確認
CVE-2025-66902 2026-02-2 19:30 2026-01-20 Show GitHub Exploit DB Packet Storm
703 6.1 警告
Network
AnyComment AnyComment.io AnyCommentのAnyComment.ioにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2025-67025 2026-02-2 19:30 2026-01-15 Show GitHub Exploit DB Packet Storm
704 7.5 重要
Network
Revotech I6032W-FHW Firmware RevotechのI6032W-FHW Firmwareにおける認証に関する脆弱性 CWE-287
不適切な認証
CVE-2025-67158 2026-02-2 19:30 2026-01-2 Show GitHub Exploit DB Packet Storm
705 7.5 重要
Network
Vatilon PA4 Firmware VatilonのPA4 Firmwareにおける重要な情報の平文での送信に関する脆弱性 CWE-319
重要な情報の平文での送信
CVE-2025-67159 2026-02-2 19:30 2026-01-2 Show GitHub Exploit DB Packet Storm
706 7.5 重要
Network
Vatilon PA4 Firmware VatilonのPA4 Firmwareにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2025-67160 2026-02-2 19:30 2026-01-2 Show GitHub Exploit DB Packet Storm
707 6.5 警告
Network
Abacre Limited Abacre Retail Point of Sale (POS) Abacre LimitedのAbacre Retail Point of Sale (POS)におけるSQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2025-67261 2026-02-2 19:30 2026-01-20 Show GitHub Exploit DB Packet Storm
708 6.1 警告
Network
Abacre Limited Abacre Retail Point of Sale (POS) Abacre LimitedのAbacre Retail Point of Sale (POS)におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2025-67263 2026-02-2 19:30 2026-01-20 Show GitHub Exploit DB Packet Storm
709 7.5 重要
Network
comfy ComfyUI Manager comfyのComfyUI Managerにおける保護されていない代替チャネルに関する脆弱性 CWE-420
保護されていない代替チャネル
CVE-2025-67303 2026-02-2 19:30 2026-01-5 Show GitHub Exploit DB Packet Storm
710 9.8 緊急
Network
Qode Interactive Wilmer Qode InteractiveのWordPress用WilmerにおけるPHP リモートファイルインクルージョンの脆弱性 CWE-98
PHP リモートファイルインクルージョン
CVE-2025-67515 2026-02-2 19:30 2025-12-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 26, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
283241 - npds npds Multiple SQL injection vulnerabilities in mainfile.php in NPDS 5.10 and earlier allow remote authenticated users to execute arbitrary SQL commands via a (1) nickname or (2) Id in a cookie, or (3) the… NVD-CWE-Other
CVE-2007-2537 2018-10-17 01:44 2007-05-9 Show GitHub Exploit DB Packet Storm
283242 - runcms runcms SQL injection vulnerability in class/debug/debug_show.php in RunCms 1.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the executed_queries array parameter. NVD-CWE-Other
CVE-2007-2538 2018-10-17 01:44 2007-05-9 Show GitHub Exploit DB Packet Storm
283243 - runcms runcms The show_files function in RunCms 1.5.2 and earlier allows remote attackers to obtain sensitive information (file existence and file metadata) via unspecified vectors. NVD-CWE-Other
CVE-2007-2539 2018-10-17 01:44 2007-05-9 Show GitHub Exploit DB Packet Storm
283244 - simple_machines simple_machines_forum Session fixation vulnerability in Simple Machines Forum (SMF) 1.1.2 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter. CWE-287
Improper Authentication
CVE-2007-2546 2018-10-17 01:44 2007-05-9 Show GitHub Exploit DB Packet Storm
283245 - turnkey_web_tools sunshop_shopping_cart Cross-site scripting (XSS) vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 allows remote attackers to inject arbitrary web script or HTML via the l parameter. NVD-CWE-Other
CVE-2007-2547 2018-10-17 01:44 2007-05-9 Show GitHub Exploit DB Packet Storm
283246 - turnkey_web_tools sunshop_shopping_cart Unspecified vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 has unknown impact and an l remote attack vector, related to "Cookie Manipulation." NVD-CWE-Other
CVE-2007-2548 2018-10-17 01:44 2007-05-9 Show GitHub Exploit DB Packet Storm
283247 - turnkey_web_tools sunshop_shopping_cart SQL injection vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 allows remote attackers to execute arbitrary SQL commands via the (1) c or (2) quantity parameter. NVD-CWE-Other
CVE-2007-2549 2018-10-17 01:44 2007-05-9 Show GitHub Exploit DB Packet Storm
283248 - devellion cubecart Multiple CRLF injection vulnerabilities in Devellion CubeCart 3.0.15 allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in a cookie… NVD-CWE-Other
CVE-2007-2550 2018-10-17 01:44 2007-05-9 Show GitHub Exploit DB Packet Storm
283249 - hp tru64 Unspecified vulnerability in dop in HP Tru64 UNIX 5.1B-4, 5.1B-3, and 5.1A PK6 allows local users to gain privileges via a large amount of data in the environment, as demonstrated by a long environme… NVD-CWE-noinfo
CVE-2007-2553 2018-10-17 01:44 2007-05-10 Show GitHub Exploit DB Packet Storm
283250 - associated_press newspower Associated Press (AP) Newspower 4.0.1 and earlier uses a default blank password for the MySQL root account, which allows remote attackers to insert or modify news articles via shows.tblscript. NVD-CWE-Other
CVE-2007-2554 2018-10-17 01:44 2007-05-10 Show GitHub Exploit DB Packet Storm