Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 6, 2026, 2 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
225681 6.8 警告 runcms - RunCMS におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2008-7221 2012-12-20 19:10 2009-09-14 Show GitHub Exploit DB Packet Storm
225682 7.5 危険 prototypejs - Prototype JavaScript フレームワークにおける "クロスサイト ajax リクエスト" を実行される脆弱性 CWE-Other
その他
CVE-2008-7220 2012-12-20 19:10 2009-09-13 Show GitHub Exploit DB Packet Storm
225683 4.3 警告 WordPress.org - WordPress 用の Peter's Math Anti-Spam Spinoff プラグインにおける CAPTCHA 保護を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-7216 2012-12-20 19:10 2009-09-11 Show GitHub Exploit DB Packet Storm
225684 6.9 警告 soundblaster - Ensoniq PCI 1371 サウンドカードで使用されている CreativeLabs es1371mp.sys WDM 音声ドライバにおける SYSTEM 権限を取得される脆弱性 CWE-Other
その他
CVE-2008-7211 2012-12-20 19:10 2009-09-11 Show GitHub Exploit DB Packet Storm
225685 2.1 注意 RivetCode Software - RivetTracker におけるパスワードを特定される脆弱性 CWE-310
暗号の問題
CVE-2008-7207 2012-12-20 19:10 2009-09-11 Show GitHub Exploit DB Packet Storm
225686 4.3 警告 stefan ritt - ELOG における脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-7206 2012-12-20 19:10 2009-09-11 Show GitHub Exploit DB Packet Storm
225687 4.3 警告 VirtueMart - VirtueMart の製品ビュー機能における任意のファイルを読み取られる脆弱性 CWE-20
不適切な入力確認
CVE-2008-7205 2012-12-20 19:10 2009-09-11 Show GitHub Exploit DB Packet Storm
225688 6.8 警告 VirtueMart - VirtueMart におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2008-7204 2012-12-20 19:10 2009-09-11 Show GitHub Exploit DB Packet Storm
225689 5 警告 valve software - Valve Software Half-Life Counter-Strike におけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2008-7203 2012-12-20 19:10 2009-09-11 Show GitHub Exploit DB Packet Storm
225690 6.8 警告 PHPKIT - PHPKIT におけるクロスサイトリクエストフォージェリ攻撃を実行される脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2008-7193 2012-12-20 19:10 2009-09-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 6, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
291 5.3 MEDIUM
Network
- - Note Mark is an open-source note-taking application. Prior to version 0.19.3, after a note-mark owner soft-deletes a public book, its notes and uploaded assets stay readable at /api/notes/{id}, /api/… New CWE-285
Improper Authorization
CVE-2026-41572 2026-05-5 03:16 2026-05-5 Show GitHub Exploit DB Packet Storm
292 9.4 CRITICAL
Network
- - Note Mark is an open-source note-taking application. In version 0.19.2, IsPasswordMatch in backend/db/models.go falls back to a hard-coded bcrypt("null") placeholder whenever a user has no stored pas… New CWE-287
Improper Authentication
CVE-2026-41571 2026-05-5 03:16 2026-05-5 Show GitHub Exploit DB Packet Storm
293 7.5 HIGH
Network
- - Easy PayPal Events & Tickets plugin for WordPress versions 1.3 and earlier contain an information disclosure vulnerability in the QR code scanning endpoint that allows unauthenticated attackers to en… New CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2026-41471 2026-05-5 03:16 2026-05-5 Show GitHub Exploit DB Packet Storm
294 - - - An integer underflow in FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message. New - CVE-2026-37459 2026-05-5 03:16 2026-05-5 Show GitHub Exploit DB Packet Storm
295 8.8 HIGH
Network
- - An XML external entity (XXE) vulnerability in the /designer/loadReport endpoint of SpringBlade v4.8.0 allows authenticated attackers to execute arbitrary code via injecting a crafted payload. Update CWE-611
XXE
CVE-2026-36765 2026-05-5 03:16 2026-05-1 Show GitHub Exploit DB Packet Storm
296 8.8 HIGH
Network
- - An issue in the fileEntityId parameter in the /a/file/upload endpoint of JeeSite v5.15.1 allows authenticated attackers with file upload permissions to execute a path traversal and write arbitrary fi… Update CWE-22
Path Traversal
CVE-2026-36762 2026-05-5 03:16 2026-05-1 Show GitHub Exploit DB Packet Storm
297 7.5 HIGH
Network
- - Buffer Over-read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue. New CWE-126
 Buffer Over-read
CVE-2026-34059 2026-05-5 03:16 2026-05-4 Show GitHub Exploit DB Packet Storm
298 5.3 MEDIUM
Network
- - Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which f… New CWE-125
CWE-170
Out-of-bounds Read
 Improper Null Termination
CVE-2026-34032 2026-05-5 03:16 2026-05-4 Show GitHub Exploit DB Packet Storm
299 5.3 MEDIUM
Network
- - Out-of-bounds Read vulnerability in mod_proxy_ajp of Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the… New CWE-125
Out-of-bounds Read
CVE-2026-33857 2026-05-5 03:16 2026-05-4 Show GitHub Exploit DB Packet Storm
300 6.5 MEDIUM
Network
- - HTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend servers. This issue affects Apache HTTP Server: from through 2.4.66. Users are rec… New CWE-443
CVE-2026-33523 2026-05-5 03:16 2026-05-5 Show GitHub Exploit DB Packet Storm