Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 5, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
227091 7.5 危険 predictionfootball - Prediction Football の showpredictionsformatch.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-1732 2012-12-20 18:52 2008-04-11 Show GitHub Exploit DB Packet Storm
227092 9.3 危険 tumbleweed - Tumbleweed SecureTransport Server の vcst_en.dll におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-1724 2012-12-20 18:52 2008-04-11 Show GitHub Exploit DB Packet Storm
227093 7.5 危険 Samba Project - rsync におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-1720 2012-12-20 18:52 2008-04-8 Show GitHub Exploit DB Packet Storm
227094 6.8 警告 tru-zone - Nuke ET におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2008-1719 2012-12-20 18:52 2008-04-10 Show GitHub Exploit DB Packet Storm
227095 5 警告 woltlab - WoltLab Burning Board の WCF におけるフルパスを取得される脆弱性 CWE-200
情報漏えい
CVE-2008-1717 2012-12-20 18:52 2008-04-9 Show GitHub Exploit DB Packet Storm
227096 4.3 警告 woltlab - WoltLab Burning Board の WCF におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-1716 2012-12-20 18:52 2008-04-9 Show GitHub Exploit DB Packet Storm
227097 5 警告 terong - Terong PHP Photo Gallery における重要な情報を取得される脆弱性 CWE-310
暗号の問題
CVE-2008-1711 2012-12-20 18:52 2008-04-9 Show GitHub Exploit DB Packet Storm
227098 10 危険 TIBCO Software - TIBCO Software EMS および iProcess Engine におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-1704 2012-12-20 18:52 2008-04-11 Show GitHub Exploit DB Packet Storm
227099 9.3 危険 TIBCO Software - TIBCO Software Rendezvous におけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-1703 2012-12-20 18:52 2008-04-11 Show GitHub Exploit DB Packet Storm
227100 4.3 警告 ventrian - Simple Gallery の gallery.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-1698 2012-12-20 18:52 2008-04-8 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 6, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1781 5.9 MEDIUM
Network
- - Incomplete path traversal fixes in awslabs/tough before tough-v0.22.0 allow remote authenticated users with delegated signing authority to write files outside intended output directories via absolute… CWE-22
Path Traversal
CVE-2026-6968 2026-04-28 03:57 2026-04-25 Show GitHub Exploit DB Packet Storm
1782 7.8 HIGH
Local
- - NSIS (Nullsoft Scriptable Install System) 3.06.1 before 3.12 sometimes uses the Low IL temp directory when executing as SYSTEM, allowing local attackers to gain privileges (if they can cause my_GetTe… CWE-427
 Uncontrolled Search Path Element
CVE-2026-42171 2026-04-28 03:57 2026-04-25 Show GitHub Exploit DB Packet Storm
1783 4.0 MEDIUM
Network
- - Hickory DNS hickory-recursor 0.1 through 0.25.2 allows cross-zone poisoning because cached data is not directly associated with a query that triggered a response. CWE-706
 Use of Incorrectly-Resolved Name or Reference
CVE-2026-42254 2026-04-28 03:57 2026-04-26 Show GitHub Exploit DB Packet Storm
1784 7.0 HIGH
Local
- - Successful exploitation of the race condition vulnerability could allow an attacker to trigger a kernel heap overflow, potentially leading to local privilege escalation and granting system-level acce… CWE-362
Race Condition
CVE-2026-3006 2026-04-28 03:57 2026-04-27 Show GitHub Exploit DB Packet Storm
1785 - - - An improper ownership management vulnerability has been identified in Moxa’s Secure Router. Because of improper ownership management, a low-privileged authenticated user may access a configuration fi… CWE-282
 Improper Ownership Management
CVE-2026-3867 2026-04-28 03:57 2026-04-27 Show GitHub Exploit DB Packet Storm
1786 - - - An improper handling of the length parameter inconsistency vulnerability has been identified in Moxa’s Secure Router. Because of improper validation of length parameters in the HTTPS management inter… CWE-130
 Improper Handling of Length Parameter Inconsistency
CVE-2026-3868 2026-04-28 03:57 2026-04-27 Show GitHub Exploit DB Packet Storm
1787 6.6 MEDIUM
Local
- - Successful exploitation of the string injection vulnerability could allow an attacker to obtain memory address information or crash the application. CWE-134
Use of Externally-Controlled Format String
CVE-2026-3008 2026-04-28 03:57 2026-04-27 Show GitHub Exploit DB Packet Storm
1788 5.1 MEDIUM
Local
- - uriparser before 1.0.1 has numeric truncation in text range comparison, if an application accepts URIs with a length in gigabytes. CWE-197
 Numeric Truncation Error
CVE-2026-42371 2026-04-28 03:57 2026-04-27 Show GitHub Exploit DB Packet Storm
1789 - - - OPPO Wallet APP contains a trusted domain validation flaw that allows attackers to bypass protected interface access restrictions, which may lead to account token hijacking and sensitive information … CWE-346
 Origin Validation Error
CVE-2026-22077 2026-04-28 03:57 2026-04-27 Show GitHub Exploit DB Packet Storm
1790 - - - Authenticated user can bypass authorization in Ribblr - Crochet & Knitting iOS application CWE-639
 Authorization Bypass Through User-Controlled Key
CVE-2025-15626 2026-04-28 03:57 2026-04-27 Show GitHub Exploit DB Packet Storm