Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
131 9.8 緊急
Network
SolarWinds Web Help Desk SolarWindsのWeb Help Deskにおける信頼できないデータのデシリアライゼーションに関する脆弱性 CWE-502
信頼性のないデータのデシリアライゼーション
CVE-2025-40553 2026-02-5 15:51 2026-01-28 Show GitHub Exploit DB Packet Storm
132 9.8 緊急
Network
SolarWinds Web Help Desk SolarWindsのWeb Help Deskにおける弱い認証に関する脆弱性 CWE-1390
脆弱な認証
CVE-2025-40554 2026-02-5 15:51 2026-01-28 Show GitHub Exploit DB Packet Storm
133 5.5 警告
Local
Pure Storage, Inc. Portworx Pure Storage, Inc.のPortworxにおけるエンコードおよびエスケープに関する脆弱性 CWE-116
不適切なエンコード、または出力のエスケープ
CVE-2025-9127 2026-02-5 15:51 2025-12-4 Show GitHub Exploit DB Packet Storm
134 6.5 警告
Network
Tildeslash Ltd. M/Monit Tildeslash Ltd.のM/Monitにおける認証情報の不十分な保護に関する脆弱性 CWE-522
認証情報の不十分な保護
CVE-2020-36968 2026-02-5 15:51 2026-01-28 Show GitHub Exploit DB Packet Storm
135 8.8 重要
Network
Tildeslash Ltd. M/Monit Tildeslash Ltd.のM/Monitにおける不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2020-36969 2026-02-5 15:51 2026-01-28 Show GitHub Exploit DB Packet Storm
136 9.8 緊急
Network
Joakim Nygard and Jacob Oettinger Webgrind Webgrind projectのWebgrindにおけるOS コマンドインジェクションの脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2023-54339 2026-02-5 15:51 2026-01-13 Show GitHub Exploit DB Packet Storm
137 6.1 警告
Network
Joakim Nygard and Jacob Oettinger Webgrind Webgrind projectのWebgrindにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2023-54341 2026-02-5 15:51 2026-01-13 Show GitHub Exploit DB Packet Storm
138 5.4 警告
Network
tagify project tagify FactorialのTagifyにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2025-13983 2026-02-5 15:51 2026-01-28 Show GitHub Exploit DB Packet Storm
139 9.8 緊急
Network
Petlibro, Inc. PETLIBRO Petlibro, Inc.のPETLIBROにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2025-15115 2026-02-5 15:50 2026-01-4 Show GitHub Exploit DB Packet Storm
140 7.5 重要
Network
Redlib Redlib Redlibにおける複数の脆弱性 CWE-400
CWE-502
CVE-2025-30160 2026-02-5 15:50 2025-03-20 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 23, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
341 6.1 MEDIUM
Network
- - zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, the proxyUi template engine uses Go's text/template (which performs no HTML escaping) instead of html/… CWE-79
CWE-116
Cross-site Scripting
 Improper Encoding or Escaping of Output
CVE-2026-40302 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
342 4.7 MEDIUM
Network
- - DOMSanitizer is a DOM/SVG/MathML Sanitizer for PHP 7.3+. Prior to version 1.0.10, DOMSanitizer::sanitize() allows <style> elements in SVG content but never inspects their text content. CSS url() refe… CWE-79
Cross-site Scripting
CVE-2026-40301 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
343 - - - next-intl provides internationalization for Next.js. Applications using the `next-intl` middleware prior to version 4.9.1with `localePrefix: 'as-needed'` could construct URLs where path handling and … CWE-601
Open Redirect
CVE-2026-40299 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
344 6.5 MEDIUM
Network
- - OpenFGA is an authorization/permission engine built for developers. In versions 0.1.4 through 1.13.1, when OpenFGA is configured to use preshared-key authentication with the built-in playground enabl… CWE-200
Information Exposure
CVE-2026-40293 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
345 7.5 HIGH
Network
- - WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the 'Member Registration' (Cadastrar Sócio) functi… CWE-79
Cross-site Scripting
CVE-2026-40286 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
346 6.8 MEDIUM
Network
- - WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vulnerability allows an authenticated user to inject malicious JavaScript via the … CWE-79
Cross-site Scripting
CVE-2026-40284 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
347 - - - WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vulnerability allows an authenticated user to inject malicious JavaScript into the… CWE-79
Cross-site Scripting
CVE-2026-40282 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
348 8.1 HIGH
Network
- - HomeBox is a home inventory and organization system. Versions prior to 0.25.0 contain a vulnerability where the defaultGroup ID remained permanently assigned to a user after being invited to a group,… CWE-708
 Incorrect Ownership Assignment
CVE-2026-40196 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
349 5.4 MEDIUM
Network
- - The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. In versions 4.12.0 through 4.17.1, simultaneous requests that trigger a nonce retry may cause the prox… CWE-362
CWE-863
Race Condition
 Incorrect Authorization
CVE-2026-40155 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
350 - - - Claude Code is an agentic coding tool. In versions prior to 2.1.75 on Windows, Claude Code loaded the system-wide default configuration from C:\ProgramData\ClaudeCode\managed-settings.json without va… CWE-426
 Untrusted Search Path
CVE-2026-35603 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm