Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":April 30, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
226951 4.3 警告 xitex - Xitex WebContent M1 の redirect.do におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-1209 2012-12-20 18:34 2008-03-7 Show GitHub Exploit DB Packet Storm
226952 4.3 警告 サン・マイクロシステムズ - Sun Java System Access Manager の管理コンソールにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-1204 2012-12-20 18:34 2008-02-27 Show GitHub Exploit DB Packet Storm
226953 7.1 危険 レッドハット - Red Hat Enterprise Linux のデフォルト IPSec ifup スクリプトにおける総当り攻撃を実行される脆弱性 CWE-16
環境設定
CVE-2008-1198 2012-12-20 18:34 2008-02-28 Show GitHub Exploit DB Packet Storm
226954 4.3 警告 torrenttrader - TorrentTrader Classic の TorrentTrader Classic におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-1173 2012-12-20 18:34 2008-03-5 Show GitHub Exploit DB Packet Storm
226955 4.3 警告 torrenttrader - TorrentTrader Classic の account-inbox.php におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2008-1172 2012-12-20 18:34 2008-03-5 Show GitHub Exploit DB Packet Storm
226956 7.8 危険 simm-comm - SCI Photo Chat Server の組み込まれた HTTP サーバにおけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-1169 2012-12-20 18:34 2008-03-5 Show GitHub Exploit DB Packet Storm
226957 4.3 警告 sarg - Sarg におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-1168 2012-12-20 18:34 2008-03-5 Show GitHub Exploit DB Packet Storm
226958 10 危険 sarg - Sarg の useragent.c におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-1167 2012-12-20 18:34 2008-03-5 Show GitHub Exploit DB Packet Storm
226959 7.5 危険 phpComasy - phpComasy の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-1164 2012-12-20 18:34 2008-03-5 Show GitHub Exploit DB Packet Storm
226960 7.5 危険 phparcadescript - phpArcadeScript の index.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-1163 2012-12-20 18:34 2008-03-5 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 30, 2026, 4:58 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
451 5.4 MEDIUM
Network
openclaw openclaw OpenClaw before 2026.4.20 contains an improper authorization vulnerability in paired-device pairing management that allows limited-scope sessions to enumerate and act on pairing requests. Attackers w… Update CWE-863
 Incorrect Authorization
CVE-2026-41909 2026-04-29 04:40 2026-04-24 Show GitHub Exploit DB Packet Storm
452 10.0 CRITICAL
Network
apache camel Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Apache Camel Camel-Coap component. Apache Camel's camel-coap component is vulnerable to Camel message … New CWE-915
 Improperly Controlled Modification of Dynamically-Determined Object Attributes
CVE-2026-33453 2026-04-29 04:39 2026-04-27 Show GitHub Exploit DB Packet Storm
453 7.5 HIGH
Network
marked_project marked Marked is a markdown parser and compiler. From 18.0.0 to 18.0.1, a critical Denial of Service (DoS) vulnerability exists in marked. By providing a specific 3-byte input sequence a tab, a vertical tab… Update CWE-400
CWE-674
CWE-835
 Uncontrolled Resource Consumption
 Uncontrolled Recursion
 Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2026-41680 2026-04-29 04:37 2026-04-25 Show GitHub Exploit DB Packet Storm
454 4.3 MEDIUM
Network
rocket.chat rocket.chat In versions <8.4.0, <8.3.2, <8.2.2, <8.1.3, <8.0.4, <7.13.6, <7.12.7, <7.11.7, and <7.10.10, the endpoints /api/apps/logs and /api/apps/:id/logs have a typo in the required permission check, allowing… Update CWE-284
Improper Access Control
CVE-2026-29197 2026-04-29 04:34 2026-04-24 Show GitHub Exploit DB Packet Storm
455 5.3 MEDIUM
Network
opentelemetry opentelemetry
opentelemetry.api
opentelemetry.extensions.propagators
OpenTelemetry dotnet is a dotnet telemetry framework. In OpenTelemetry.Api 0.5.0-beta.2 to 1.15.2 and OpenTelemetry.Extensions.Propagators 1.3.1 to 1.15.2, The implementation details of the baggage, … Update CWE-789
 Memory Allocation with Excessive Size Value
CVE-2026-40894 2026-04-29 04:34 2026-04-24 Show GitHub Exploit DB Packet Storm
456 7.5 HIGH
Network
senselive x3500_firmware A vulnerability in SenseLive X3050’s management ecosystem allows unauthenticated discovery of deployed units through the vendor’s management protocol, enabling identification of device presence, iden… Update CWE-306
Missing Authentication for Critical Function
CVE-2026-35064 2026-04-29 04:33 2026-04-24 Show GitHub Exploit DB Packet Storm
457 9.8 CRITICAL
Network
senselive x3500_firmware A vulnerability in SenseLive X3050’s web management interface allows authentication logic to be performed entirely on the client side, relying on hardcoded values within browser-executed scripts rath… Update CWE-798
 Use of Hard-coded Credentials
CVE-2026-35503 2026-04-29 04:33 2026-04-24 Show GitHub Exploit DB Packet Storm
458 5.3 MEDIUM
Network
senselive x3500_firmware A vulnerability exists in SenseLive X3050’s web management interface due to its reliance on unencrypted HTTP for all administrative communication. Because management traffic, including authentication… Update CWE-319
Cleartext Transmission of Sensitive Information
CVE-2026-40431 2026-04-29 04:33 2026-04-24 Show GitHub Exploit DB Packet Storm
459 9.8 CRITICAL
Network
senselive x3500_firmware A vulnerability in SenseLive X3050’s embedded management service allows full administrative control to be established without any form of authentication or authorization on the SenseLive config appli… Update CWE-306
Missing Authentication for Critical Function
CVE-2026-40620 2026-04-29 04:32 2026-04-24 Show GitHub Exploit DB Packet Storm
460 9.1 CRITICAL
Network
senselive x3500_firmware A vulnerability exists in SenseLive X3050's web management interface that allows critical configuration parameters to be modified without sufficient authentication or server-side validation. By apply… Update CWE-306
Missing Authentication for Critical Function
CVE-2026-27843 2026-04-29 04:32 2026-04-24 Show GitHub Exploit DB Packet Storm