Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":April 29, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
227881 10 危険 webo - Leo West WEBO の modules/abook/foldertree.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-1391 2012-12-20 18:19 2007-03-10 Show GitHub Exploit DB Packet Storm
227882 4.3 警告 Snitz - Snitz Forums 2000 の pop_profile.asp におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-1374 2012-12-20 18:19 2007-03-9 Show GitHub Exploit DB Packet Storm
227883 10 危険 Pegasus Mail - Mercury/32 におけるスタックベースのバッファオーバーフローの脆弱性 - CVE-2007-1373 2012-12-20 18:19 2007-03-9 Show GitHub Exploit DB Packet Storm
227884 10 危険 postguestbook - PHP-Nuke 用の PostGuestbook モジュールにおける PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-1372 2012-12-20 18:19 2007-03-9 Show GitHub Exploit DB Packet Storm
227885 6.9 警告 Jon Trulson - Conquest におけるバッファオーバーフローの脆弱性 - CVE-2007-1371 2012-12-20 18:19 2007-03-9 Show GitHub Exploit DB Packet Storm
227886 6.2 警告 Zend Technologies Ltd. - Zend Platform におけるルート権限を取得される脆弱性 - CVE-2007-1370 2012-12-20 18:19 2007-03-9 Show GitHub Exploit DB Packet Storm
227887 4.4 警告 Zend Technologies Ltd. - Zend Platform の ini_modifier における system.ini ファイルを変更される脆弱性 - CVE-2007-1369 2012-12-20 18:19 2007-03-9 Show GitHub Exploit DB Packet Storm
227888 4.3 警告 VirtueMart - VirtueMart の virtuemart_parser.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-1361 2012-12-20 18:19 2007-03-8 Show GitHub Exploit DB Packet Storm
227889 6.6 警告 サン・マイクロシステムズ - Sun Fire X2100M2 および X2200M2 用の ipmitool における権限を取得される脆弱性 - CVE-2007-1346 2012-12-20 18:19 2007-03-7 Show GitHub Exploit DB Packet Storm
227890 7.5 危険 webcalendar - Craig Knudsen WebCalendar の includes/functions.php における任意のグローバル変数を設定される脆弱性 - CVE-2007-1343 2012-12-20 18:19 2007-03-8 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 29, 2026, 4:51 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1221 7.5 HIGH
Network
- - The Text to Speech for WP (AI Voices by Mementor) plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and including, 1.9.8. This is due to the plugin containin… CWE-798
 Use of Hard-coded Credentials
CVE-2026-1233 2026-04-25 03:13 2026-04-4 Show GitHub Exploit DB Packet Storm
1222 7.2 HIGH
Network
- - The Visitor Traffic Real Time Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page_title' parameter in all versions up to, and including, 8.4 due to insufficient… CWE-79
Cross-site Scripting
CVE-2026-2936 2026-04-25 03:13 2026-04-4 Show GitHub Exploit DB Packet Storm
1223 6.5 MEDIUM
Network
- - The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all ve… CWE-94
Code Injection
CVE-2026-3309 2026-04-25 03:13 2026-04-4 Show GitHub Exploit DB Packet Storm
1224 8.8 HIGH
Network
- - The wpForo Forum plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 2.4.16. This is due to a missing file name/path validation against path traversal … CWE-22
Path Traversal
CVE-2026-3666 2026-04-25 03:13 2026-04-4 Show GitHub Exploit DB Packet Storm
1225 6.3 MEDIUM
Network
- - A security vulnerability has been detected in MoussaabBadla code-screenshot-mcp up to 0.1.0. This affects an unknown part of the component HTTP Interface. Such manipulation leads to os command inject… CWE-77
CWE-78
Command Injection
OS Command 
CVE-2026-5528 2026-04-25 03:13 2026-04-5 Show GitHub Exploit DB Packet Storm
1226 4.3 MEDIUM
Network
- - A vulnerability was detected in Dromara lamp-cloud up to 5.8.1. This vulnerability affects the function pageUser of the file /defUser/pageUser of the component DefUserController. Performing a manipul… CWE-266
CWE-285
 Incorrect Privilege Assignment
Improper Authorization
CVE-2026-5529 2026-04-25 03:13 2026-04-5 Show GitHub Exploit DB Packet Storm
1227 6.3 MEDIUM
Network
- - A flaw has been found in Ollama up to 18.1. This issue affects some unknown processing of the file server/download.go of the component Model Pull API. Executing a manipulation can lead to server-side… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-5530 2026-04-25 03:13 2026-04-5 Show GitHub Exploit DB Packet Storm
1228 5.3 MEDIUM
Network
- - A vulnerability has been found in SourceCodester Student Result Management System 1.0. Impacted is an unknown function of the file /login_credentials.txt of the component HTTP GET Request Handler. Th… CWE-312
CWE-313
 Cleartext Storage of Sensitive Information
 Cleartext Storage in a File or on Disk
CVE-2026-5531 2026-04-25 03:13 2026-04-5 Show GitHub Exploit DB Packet Storm
1229 7.3 HIGH
Network
- - A vulnerability was determined in code-projects Student Membership System 1.0. The impacted element is an unknown function of the file /admin/index.php of the component Admin Login. This manipulation… CWE-74
CWE-89
Injection
SQL Injection
CVE-2026-5198 2026-04-25 03:12 2026-03-31 Show GitHub Exploit DB Packet Storm
1230 4.7 MEDIUM
Network
- - A vulnerability was found in CMS Made Simple up to 2.2.22. This impacts the function _copyFilesToFolder in the library modules/UserGuide/lib/class.UserGuideImporterExporter.php of the component UserG… CWE-22
Path Traversal
CVE-2026-5203 2026-04-25 03:12 2026-04-1 Show GitHub Exploit DB Packet Storm