Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":April 30, 2026, 2:16 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
227821 5.8 警告 VMware - EMC VMware の IntraProcessLogging.dll における絶対パストラバーサルの脆弱性 - CVE-2007-4059 2012-12-20 18:33 2007-07-30 Show GitHub Exploit DB Packet Storm
227822 4.6 警告 ultradefrag - UltraDefrag の FindFiles 関数におけるヒープベースのバッファオーバーフローの脆弱性 - CVE-2007-4051 2012-12-20 18:33 2007-07-30 Show GitHub Exploit DB Packet Storm
227823 4.3 警告 phpsysinfo - phpSysInfo の index.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-4048 2012-12-20 18:33 2007-07-30 Show GitHub Exploit DB Packet Storm
227824 5 警告 securecomputing - Secure Computing SecurityReporter の file.cgi における認証を回避される脆弱性 CWE-287
不適切な認証
CVE-2007-4043 2012-12-20 18:33 2007-07-27 Show GitHub Exploit DB Packet Storm
227825 9.3 危険 Yahoo! - Yahoo! Widgets の YDPCTL.dll におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2007-4034 2012-12-20 18:33 2007-07-27 Show GitHub Exploit DB Packet Storm
227826 7.5 危険 webSPELL - Webspell の index.php における絶対パストラバーサルの脆弱性 - CVE-2007-4028 2012-12-20 18:33 2007-07-26 Show GitHub Exploit DB Packet Storm
227827 6.8 警告 Telaxus LLC - epesi framework における任意の PHP コードを実行される脆弱性 - CVE-2007-4026 2012-12-20 18:33 2007-07-26 Show GitHub Exploit DB Packet Storm
227828 4.3 警告 サン・マイクロシステムズ - Windows 用の SJS Application Server における JSP ソースコードを取得される脆弱性 - CVE-2007-4025 2012-12-20 18:33 2007-07-24 Show GitHub Exploit DB Packet Storm
227829 4.3 警告 w1l3d4 - W1L3D4 Philboard の W1L3D4_aramasonuc.asp におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-4024 2012-12-20 18:33 2007-07-26 Show GitHub Exploit DB Packet Storm
227830 4.3 警告 WordPress.org - WordPress 用の Blix テーマなどに関する特定の index.php インストールスクリプトにおけるクロスサイトスクリプティングの脆弱性 - CVE-2007-4014 2012-12-20 18:33 2007-07-25 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 30, 2026, 4:58 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1391 7.5 HIGH
Network
apache log4j Apache Log4j Core's XmlLayout https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout , in versions up to and including 2.25.3, fails to sanitize characters forbidden by the XML 1.0 spec… CWE-116
 Improper Encoding or Escaping of Output
CVE-2026-34480 2026-04-25 03:21 2026-04-11 Show GitHub Exploit DB Packet Storm
1392 5.5 MEDIUM
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: can: bcm: fix locking for bcm_op runtime updates Commit c2aba69d0c36 ("can: bcm: add locking for bcm_op runtime updates") added a… CWE-667
 Improper Locking
CVE-2026-23362 2026-04-25 03:21 2026-03-25 Show GitHub Exploit DB Packet Storm
1393 5.5 MEDIUM
Local
linux linux_kernel En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: can: bcm: corregir el bloqueo para las actualizaciones en tiempo de ejecución de bcm_op El commit c2aba69d0c36 ('can: bcm: añadi… CWE-667
 Improper Locking
CVE-2026-23362 2026-04-25 03:21 2026-03-25 Show GitHub Exploit DB Packet Storm
1394 7.8 HIGH
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: crypto: ccp - Fix use-after-free on error path In the error path of sev_tsm_init_locked(), the code dereferences 't' after it has… CWE-416
 Use After Free
CVE-2026-23344 2026-04-25 03:17 2026-03-25 Show GitHub Exploit DB Packet Storm
1395 7.8 HIGH
Local
linux linux_kernel En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: crypto: ccp - Corrección de uso después de liberación en la ruta de error En la ruta de error de sev_tsm_init_locked(), el códig… CWE-416
 Use After Free
CVE-2026-23344 2026-04-25 03:17 2026-03-25 Show GitHub Exploit DB Packet Storm
1396 5.5 MEDIUM
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: arm64: gcs: Do not set PTE_SHARED on GCS mappings if FEAT_LPA2 is enabled When FEAT_LPA2 is enabled, bits 8-9 of the PTE replace … NVD-CWE-noinfo
CVE-2026-23345 2026-04-25 03:17 2026-03-25 Show GitHub Exploit DB Packet Storm
1397 5.5 MEDIUM
Local
linux linux_kernel En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: arm64: gcs: No establecer PTE_SHARED en mapeos GCS si FEAT_LPA2 está habilitado Cuando FEAT_LPA2 está habilitado, los bits 8-9 d… NVD-CWE-noinfo
CVE-2026-23345 2026-04-25 03:17 2026-03-25 Show GitHub Exploit DB Packet Storm
1398 6.5 MEDIUM
Network
- - A Broken Access Control vulnerability exists in ClassroomIO v0.1.13 where an authenticated low-privileged "student" user can access unauthorized course-level information by modifying intercepted API … CWE-284
CWE-285
Improper Access Control
Improper Authorization
CVE-2025-67259 2026-04-25 03:16 2026-04-25 Show GitHub Exploit DB Packet Storm
1399 6.4 MEDIUM
Network
- - The Wavr plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `wave` shortcode in all versions up to, and including, 0.2.6. This is due to insufficient input sanitizatio… CWE-79
Cross-site Scripting
CVE-2026-5506 2026-04-25 03:15 2026-04-8 Show GitHub Exploit DB Packet Storm
1400 6.4 MEDIUM
Network
- - The WowPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `wowpress` shortcode in all versions up to, and including, 1.0.0. This is due to insufficient input san… CWE-79
Cross-site Scripting
CVE-2026-5508 2026-04-25 03:15 2026-04-8 Show GitHub Exploit DB Packet Storm