Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":April 29, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
227811 7.5 危険 realguestbook - realGuestbook における SQL インジェクションの脆弱性 - CVE-2007-1624 2012-12-20 18:19 2007-03-23 Show GitHub Exploit DB Packet Storm
227812 4.3 警告 realguestbook - realGuestbook におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-1623 2012-12-20 18:19 2007-03-23 Show GitHub Exploit DB Packet Storm
227813 4.3 警告 WordPress.org - WordPress の wp-admin/vars.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-1622 2012-12-20 18:19 2007-03-22 Show GitHub Exploit DB Packet Storm
227814 7.5 危険 scriptmagix - ScriptMagix Photo Rating の viewcomments.php における SQL インジェクションの脆弱性 - CVE-2007-1619 2012-12-20 18:19 2007-03-22 Show GitHub Exploit DB Packet Storm
227815 7.5 危険 scriptmagix - ScriptMagix FAQ Builder の index.php における SQL インジェクションの脆弱性 - CVE-2007-1618 2012-12-20 18:19 2007-03-22 Show GitHub Exploit DB Packet Storm
227816 7.5 危険 scriptmagix - ScriptMagix Recipes の index.php における SQL インジェクションの脆弱性 - CVE-2007-1617 2012-12-20 18:19 2007-03-22 Show GitHub Exploit DB Packet Storm
227817 7.5 危険 scriptmagix - ScriptMagix Lyrics の index.php における SQL インジェクションの脆弱性 - CVE-2007-1616 2012-12-20 18:19 2007-03-22 Show GitHub Exploit DB Packet Storm
227818 7.5 危険 scriptmagix - ScriptMagix Jokes の index.php における SQL インジェクションの脆弱性 - CVE-2007-1615 2012-12-20 18:19 2007-03-22 Show GitHub Exploit DB Packet Storm
227819 9.3 危険 zziplib project - ZZIPlib Library の zzip/file.c におけるスタックベースのバッファオーバーフローの脆弱性 - CVE-2007-1614 2012-12-20 18:19 2007-03-17 Show GitHub Exploit DB Packet Storm
227820 5 警告 W-Agora - Web-Agora の search.php における重要な情報を取得される脆弱性 - CVE-2007-1607 2012-12-20 18:19 2007-03-22 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 29, 2026, 4:51 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1261 3.5 LOW
Network
- - Se ha identificado una debilidad en bufanyun HotGo 1.0/2.0. Afectada por esta vulnerabilidad es una funcionalidad desconocida del archivo /web/src/layout/components/Header/MessageList.vue del compone… CWE-79
CWE-94
Cross-site Scripting
Code Injection
CVE-2026-5253 2026-04-25 03:12 2026-04-1 Show GitHub Exploit DB Packet Storm
1262 7.3 HIGH
Network
- - A vulnerability was found in Sanster IOPaint 1.5.3. Impacted is the function _get_file of the file iopaint/file_manager/file_manager.py of the component File Manager. Performing a manipulation of the… CWE-22
Path Traversal
CVE-2026-5258 2026-04-25 03:12 2026-04-1 Show GitHub Exploit DB Packet Storm
1263 6.3 MEDIUM
Network
- - A vulnerability was determined in AutohomeCorp frostmourne up to 1.0. The affected element is an unknown function of the file frostmourne-monitor/src/main/java/com/autohome/frostmourne/monitor/contro… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-5259 2026-04-25 03:12 2026-04-1 Show GitHub Exploit DB Packet Storm
1264 7.3 HIGH
Network
- - A vulnerability was identified in Shandong Hoteam InforCenter PLM up to 8.3.8. The impacted element is the function uploadFileToIIS of the file /Base/BaseHandler.ashx. The manipulation of the argumen… CWE-284
CWE-434
Improper Access Control
 Unrestricted Upload of File with Dangerous Type 
CVE-2026-5261 2026-04-25 03:12 2026-04-1 Show GitHub Exploit DB Packet Storm
1265 6.3 MEDIUM
Network
- - A vulnerability was detected in Harvard University IQSS Dataverse up to 6.8. This affects an unknown function of the file /ThemeAndWidgets.xhtml of the component Theme Customization. Performing a man… CWE-284
CWE-434
Improper Access Control
 Unrestricted Upload of File with Dangerous Type 
CVE-2026-1879 2026-04-25 03:12 2026-04-1 Show GitHub Exploit DB Packet Storm
1266 4.3 MEDIUM
Network
- - A vulnerability has been found in Nothings stb up to 2.30. This issue affects the function stbi__gif_load_next in the library stb_image.h of the component GIF Decoder. Such manipulation leads to deni… CWE-404
 Improper Resource Shutdown or Release
CVE-2026-5313 2026-04-25 03:12 2026-04-2 Show GitHub Exploit DB Packet Storm
1267 6.4 MEDIUM
Network
- - The King Addons for Elementor plugin for WordPress is vulnerable to multiple Contributor+ DOM-Based Stored Cross-Site Scripting vulnerabilities in all versions up to, and including, 51.1.38. This is … CWE-79
Cross-site Scripting
CVE-2025-13535 2026-04-25 03:12 2026-04-2 Show GitHub Exploit DB Packet Storm
1268 2.5 LOW
Local
- - A vulnerability was identified in Enter Software Iperius Backup up to 8.7.2. This impacts an unknown function of the file IperiusAccounts.ini. Such manipulation leads to use of hard-coded cryptograph… CWE-320
CWE-321
 Key Management Errors
 Use of Hard-coded Cryptographic Key
CVE-2026-5310 2026-04-25 03:12 2026-04-2 Show GitHub Exploit DB Packet Storm
1269 6.3 MEDIUM
Network
- - A flaw has been found in SourceCodester RSS Feed Parser 1.0. Affected by this issue is the function file_get_contents. This manipulation causes server-side request forgery. The attack is possible to … CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-5126 2026-04-25 03:11 2026-03-31 Show GitHub Exploit DB Packet Storm
1270 6.3 MEDIUM
Network
- - Se ha encontrado una vulnerabilidad en SourceCodester RSS Feed Parser 1.0. Este problema afecta a la función file_get_contents. Esta manipulación provoca falsificación de petición del lado del servid… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-5126 2026-04-25 03:11 2026-03-31 Show GitHub Exploit DB Packet Storm