Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 4, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
226611 6.8 警告 Xen プロジェクト - Xen の flask_security_label 関数におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-3687 2012-12-20 18:52 2008-08-14 Show GitHub Exploit DB Packet Storm
226612 5 警告 サン・マイクロシステムズ - Sun Java System Web Proxy Server の FTP サブシステムにおけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2008-3683 2012-12-20 18:52 2008-08-12 Show GitHub Exploit DB Packet Storm
226613 6.8 警告 YPNinc - YPN PHP Realty の dpage.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3682 2012-12-20 18:52 2008-08-14 Show GitHub Exploit DB Packet Storm
226614 7.5 危険 pozscripts - PozScripts TubeGuru Video Sharing Script の ugroups.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3674 2012-12-20 18:52 2008-08-13 Show GitHub Exploit DB Packet Storm
226615 7.5 危険 pozscripts - PozScripts Classified Ads の browsecats.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3673 2012-12-20 18:52 2008-08-13 Show GitHub Exploit DB Packet Storm
226616 7.5 危険 pozscripts - PozScripts Classified Ads の showcategory.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3672 2012-12-20 18:52 2008-08-13 Show GitHub Exploit DB Packet Storm
226617 7.5 危険 ZeeScripts.com - ZeeScripts Reviews Opinions Rating Posting Engine Web-Site PHP Script の comments.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-3669 2012-12-20 18:52 2008-08-13 Show GitHub Exploit DB Packet Storm
226618 4.3 警告 xrms - XRMS におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-3664 2012-12-20 18:52 2008-09-5 Show GitHub Exploit DB Packet Storm
226619 5 警告 Tiki Software Community Association - TikiWiki CMS/Groupware における "パスおよび PHP の設定" を取得される脆弱性 CWE-noinfo
情報不足
CVE-2008-3654 2012-12-20 18:52 2008-08-4 Show GitHub Exploit DB Packet Storm
226620 10 危険 Tiki Software Community Association - TikiWiki CMS/Groupware における脆弱性 CWE-noinfo
情報不足
CVE-2008-3653 2012-12-20 18:52 2008-08-4 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 5, 2026, 4:51 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1181 6.3 MEDIUM
Network
- - A vulnerability was identified in 1000 Projects Portfolio Management System MCA up to 1.0. This affects an unknown function of the file /admin/block_status.php. The manipulation of the argument q lea… CWE-74
CWE-89
Injection
SQL Injection
CVE-2026-7143 2026-04-29 10:00 2026-04-28 Show GitHub Exploit DB Packet Storm
1182 4.3 MEDIUM
Network
- - A security flaw has been discovered in 1000 Projects Portfolio Management System MCA 1.0. This impacts an unknown function of the file update_passwd_process.php. The manipulation of the argument temp… CWE-285
CWE-639
Improper Authorization
 Authorization Bypass Through User-Controlled Key
CVE-2026-7144 2026-04-29 10:00 2026-04-28 Show GitHub Exploit DB Packet Storm
1183 5.3 MEDIUM
Local
- - A security flaw has been discovered in GPAC up to 26.03-DEV-rev105-g8f39a1eb3-master. Affected by this vulnerability is the function elng_box_read of the file src/isomedia/box_code_base.c of the comp… CWE-119
CWE-125
Incorrect Access of Indexable Resource ('Range Error') 
Out-of-bounds Read
CVE-2026-7135 2026-04-29 10:00 2026-04-28 Show GitHub Exploit DB Packet Storm
1184 6.3 MEDIUM
Network
- - A vulnerability was determined in Wooey up to 0.13.2. The impacted element is the function add_or_update_script of the file wooey/api/scripts.py of the component API Endpoint. Executing a manipulatio… CWE-266
CWE-285
 Incorrect Privilege Assignment
Improper Authorization
CVE-2026-7142 2026-04-29 10:00 2026-04-28 Show GitHub Exploit DB Packet Storm
1185 7.3 HIGH
Network
- - A security vulnerability has been detected in AlejandroArciniegas mcp-data-vis up to de5a51525a69822290eaee569a1ab447b490746d. Affected by this vulnerability is the function axios of the file src/ser… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-7146 2026-04-29 10:00 2026-04-28 Show GitHub Exploit DB Packet Storm
1186 7.3 HIGH
Network
- - A vulnerability was detected in JoeCastrom mcp-chat-studio up to 1.5.0. Affected by this issue is some unknown functionality of the file server/routes/llm.js of the component LLM Models API. Performi… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-7147 2026-04-29 10:00 2026-04-28 Show GitHub Exploit DB Packet Storm
1187 6.3 MEDIUM
Network
- - A flaw has been found in CodeAstro Online Classroom 1.0. This affects an unknown part of the file /addnewfaculty. Executing a manipulation of the argument fname can lead to sql injection. The attack … CWE-74
CWE-89
Injection
SQL Injection
CVE-2026-7148 2026-04-29 10:00 2026-04-28 Show GitHub Exploit DB Packet Storm
1188 7.3 HIGH
Network
- - A vulnerability has been found in dexhunter kaggle-mcp up to 406127ffcb2b91b8c10e20e6c2ca787fbc1dc92d. This vulnerability affects the function prepare_kaggle_dataset of the file src/kaggle_mcp/server… CWE-22
Path Traversal
CVE-2026-7149 2026-04-29 10:00 2026-04-28 Show GitHub Exploit DB Packet Storm
1189 6.3 MEDIUM
Network
- - A vulnerability was found in dh1011 auto-favicon up to f189116a9259950c2393f114dbcb94dde0ad864b. This issue affects the function generate_favicon_from_url of the file src/auto_favicon/server.py of th… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-7150 2026-04-29 10:00 2026-04-28 Show GitHub Exploit DB Packet Storm
1190 7.3 HIGH
Network
- - A flaw has been found in disler aider-mcp-server up to b2516fa466d0d851932da92ee6d0e66946db9efc. Affected by this vulnerability is an unknown functionality of the file src/aider_mcp_server/server.py … CWE-74
CWE-77
Injection
Command Injection
CVE-2026-7157 2026-04-29 10:00 2026-04-28 Show GitHub Exploit DB Packet Storm