Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":April 29, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
227911 5 警告 Sylpheed - Sylpheed における検出されずにメッセージ内容を偽造される脆弱性 - CVE-2007-1267 2012-12-20 18:19 2007-03-6 Show GitHub Exploit DB Packet Storm
227912 7.5 危険 webmod - WebMod の server.cpp におけるスタックベースのバッファオーバーフローの脆弱性 - CVE-2007-1260 2012-12-20 18:19 2007-03-3 Show GitHub Exploit DB Packet Storm
227913 7.5 危険 web-app.org - WebAPP における脆弱性 CWE-noinfo
情報不足
CVE-2007-1259 2012-12-20 18:19 2007-03-3 Show GitHub Exploit DB Packet Storm
227914 9.3 危険 シマンテック - SMTP 用の Symantec Mail Security におけるバッファオーバーフローの脆弱性 - CVE-2007-1252 2012-12-20 18:19 2007-03-3 Show GitHub Exploit DB Packet Storm
227915 6.8 警告 WordPress.org - WordPress の AdminPanel におけるクロスサイトリクエストフォージェリの脆弱性 - CVE-2007-1244 2012-12-20 18:19 2007-03-3 Show GitHub Exploit DB Packet Storm
227916 6.4 警告 sitex - sitex における重要な情報を取得される脆弱性 - CVE-2007-1236 2012-12-20 18:19 2007-03-3 Show GitHub Exploit DB Packet Storm
227917 7.5 危険 stwc-counter - STWC-Counter の downloadcounter.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2007-1233 2012-12-20 18:19 2007-03-3 Show GitHub Exploit DB Packet Storm
227918 5.1 警告 SQLiteManager - SQLiteManager におけるディレクトリトラバーサルの脆弱性 - CVE-2007-1232 2012-12-20 18:19 2007-03-3 Show GitHub Exploit DB Packet Storm
227919 4.3 警告 SQLiteManager - SQLiteManager におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-1231 2012-12-20 18:19 2007-03-3 Show GitHub Exploit DB Packet Storm
227920 5.8 警告 WordPress.org - WordPress の wp-includes/functions.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-1230 2012-12-20 18:19 2007-02-27 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 29, 2026, 4:51 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1261 3.5 LOW
Network
- - Se ha identificado una debilidad en bufanyun HotGo 1.0/2.0. Afectada por esta vulnerabilidad es una funcionalidad desconocida del archivo /web/src/layout/components/Header/MessageList.vue del compone… CWE-79
CWE-94
Cross-site Scripting
Code Injection
CVE-2026-5253 2026-04-25 03:12 2026-04-1 Show GitHub Exploit DB Packet Storm
1262 7.3 HIGH
Network
- - A vulnerability was found in Sanster IOPaint 1.5.3. Impacted is the function _get_file of the file iopaint/file_manager/file_manager.py of the component File Manager. Performing a manipulation of the… CWE-22
Path Traversal
CVE-2026-5258 2026-04-25 03:12 2026-04-1 Show GitHub Exploit DB Packet Storm
1263 6.3 MEDIUM
Network
- - A vulnerability was determined in AutohomeCorp frostmourne up to 1.0. The affected element is an unknown function of the file frostmourne-monitor/src/main/java/com/autohome/frostmourne/monitor/contro… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-5259 2026-04-25 03:12 2026-04-1 Show GitHub Exploit DB Packet Storm
1264 7.3 HIGH
Network
- - A vulnerability was identified in Shandong Hoteam InforCenter PLM up to 8.3.8. The impacted element is the function uploadFileToIIS of the file /Base/BaseHandler.ashx. The manipulation of the argumen… CWE-284
CWE-434
Improper Access Control
 Unrestricted Upload of File with Dangerous Type 
CVE-2026-5261 2026-04-25 03:12 2026-04-1 Show GitHub Exploit DB Packet Storm
1265 6.3 MEDIUM
Network
- - A vulnerability was detected in Harvard University IQSS Dataverse up to 6.8. This affects an unknown function of the file /ThemeAndWidgets.xhtml of the component Theme Customization. Performing a man… CWE-284
CWE-434
Improper Access Control
 Unrestricted Upload of File with Dangerous Type 
CVE-2026-1879 2026-04-25 03:12 2026-04-1 Show GitHub Exploit DB Packet Storm
1266 4.3 MEDIUM
Network
- - A vulnerability has been found in Nothings stb up to 2.30. This issue affects the function stbi__gif_load_next in the library stb_image.h of the component GIF Decoder. Such manipulation leads to deni… CWE-404
 Improper Resource Shutdown or Release
CVE-2026-5313 2026-04-25 03:12 2026-04-2 Show GitHub Exploit DB Packet Storm
1267 6.4 MEDIUM
Network
- - The King Addons for Elementor plugin for WordPress is vulnerable to multiple Contributor+ DOM-Based Stored Cross-Site Scripting vulnerabilities in all versions up to, and including, 51.1.38. This is … CWE-79
Cross-site Scripting
CVE-2025-13535 2026-04-25 03:12 2026-04-2 Show GitHub Exploit DB Packet Storm
1268 2.5 LOW
Local
- - A vulnerability was identified in Enter Software Iperius Backup up to 8.7.2. This impacts an unknown function of the file IperiusAccounts.ini. Such manipulation leads to use of hard-coded cryptograph… CWE-320
CWE-321
 Key Management Errors
 Use of Hard-coded Cryptographic Key
CVE-2026-5310 2026-04-25 03:12 2026-04-2 Show GitHub Exploit DB Packet Storm
1269 6.3 MEDIUM
Network
- - A flaw has been found in SourceCodester RSS Feed Parser 1.0. Affected by this issue is the function file_get_contents. This manipulation causes server-side request forgery. The attack is possible to … CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-5126 2026-04-25 03:11 2026-03-31 Show GitHub Exploit DB Packet Storm
1270 6.3 MEDIUM
Network
- - Se ha encontrado una vulnerabilidad en SourceCodester RSS Feed Parser 1.0. Este problema afecta a la función file_get_contents. Esta manipulación provoca falsificación de petición del lado del servid… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-5126 2026-04-25 03:11 2026-03-31 Show GitHub Exploit DB Packet Storm