Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228201 4.9 警告 VMware
Linux
- x86 プラットフォーム上の Linux Kernel におけるサービス運用妨害 (DoS) の脆弱性 CWE-189
数値処理の問題
CVE-2011-3209 2012-12-17 15:59 2008-07-13 Show GitHub Exploit DB Packet Storm
228202 7.8 危険 VMware
Linux
- Linux Kernel の IPv4 と IPv6 の実装におけるサービス運用妨害 (ネットワーク障害) の脆弱性 CWE-DesignError
CVE-2011-3188 2012-12-17 15:57 2012-05-24 Show GitHub Exploit DB Packet Storm
228203 4.3 警告 VideoLAN - VideoLAN VLC media player の libpng_plugin におけるサービス運用妨害 (アプリケーションクラッシュ) の脆弱性 CWE-119
バッファエラー
CVE-2012-5470 2012-12-17 13:47 2012-10-26 Show GitHub Exploit DB Packet Storm
228204 2.1 注意 シトリックス・システムズ - Xen におけるサービス運用妨害 (無限ループ および ハングアップまたはクラッシュ) の脆弱性 CWE-399
リソース管理の問題
CVE-2012-4539 2012-12-17 13:43 2012-11-13 Show GitHub Exploit DB Packet Storm
228205 4.9 警告 シトリックス・システムズ - Xen の HVMOP_pagetable_dying ハイパーコールにおけるサービス運用妨害 (ハイパーバイザクラッシュ) の脆弱性 CWE-20
不適切な入力確認
CVE-2012-4538 2012-12-17 13:41 2012-11-13 Show GitHub Exploit DB Packet Storm
228206 2.1 注意 シトリックス・システムズ - Xen におけるサービス運用妨害 (メモリ消費および表明違反) の脆弱性 CWE-16
環境設定
CVE-2012-4537 2012-12-17 12:30 2012-11-13 Show GitHub Exploit DB Packet Storm
228207 1.9 注意 シトリックス・システムズ - Xen におけるサービス運用妨害 (Xen の無限ループおよび物理 CPU の消費) の脆弱性 CWE-399
リソース管理の問題
CVE-2012-4535 2012-12-17 12:28 2012-11-13 Show GitHub Exploit DB Packet Storm
228208 4.3 警告 Wikka Development Team - WikkaWiki におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
- 2012-12-17 12:15 2012-12-17 Show GitHub Exploit DB Packet Storm
228209 4.3 警告 Netsweeper, Inc. - Netsweeper の WebAdmin Portal におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-2446 2012-12-17 11:02 2012-07-9 Show GitHub Exploit DB Packet Storm
228210 10 危険 Netsweeper, Inc. - Netsweeper の WebAdmin Portal における脆弱性 CWE-noinfo
情報不足
CVE-2012-3859 2012-12-17 10:56 2012-07-9 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 20, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
271 7.7 HIGH
Network
- - In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _… Update CWE-843
Type Confusion
CVE-2026-40683 2026-04-18 00:38 2026-04-15 Show GitHub Exploit DB Packet Storm
272 8.8 HIGH
Network
- - openITCOCKPIT is an open source monitoring tool built for different monitoring engines. openITCOCKPIT Community Edition prior to version 5.5.2 contains a command injection vulnerability that allows a… Update CWE-20
CWE-78
 Improper Input Validation 
OS Command 
CVE-2026-24893 2026-04-18 00:38 2026-04-15 Show GitHub Exploit DB Packet Storm
273 - - - Chamilo is an open-source learning management system (LMS). Version 2.0.0-RC.2 contains a SQL Injection vulnerability in the statistics AJAX endpoint, which is an incomplete fix for CVE-2026-30881. W… Update CWE-89
SQL Injection
CVE-2026-33714 2026-04-18 00:38 2026-04-15 Show GitHub Exploit DB Packet Storm
274 4.3 MEDIUM
Network
- - Docmost is open-source collaborative wiki and documentation software. An authorization bypass vulnerability in versions 0.70.0 through 0.70.2 exposes restricted child page titles and text snippets th… Update CWE-285
Improper Authorization
CVE-2026-33146 2026-04-18 00:38 2026-04-15 Show GitHub Exploit DB Packet Storm
275 4.6 MEDIUM
Network
- - Docmost is open-source collaborative wiki and documentation software. Versions prior to 0.70.0 are vulnerable to a stored cross-site scripting (XSS) attack due to improper handling of MIME type spoof… Update CWE-79
Cross-site Scripting
CVE-2026-33193 2026-04-18 00:38 2026-04-15 Show GitHub Exploit DB Packet Storm
276 4.9 MEDIUM
Network
- - October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a server-side information disclosure vulnerability in the INI settings parser. Because PHP's… Update CWE-94
CWE-200
Code Injection
Information Exposure
CVE-2026-25125 2026-04-18 00:38 2026-04-15 Show GitHub Exploit DB Packet Storm
277 - - - October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a stored cross-site scripting (XSS) vulnerability in the SVG sanitization logic. The regex p… Update CWE-79
Cross-site Scripting
CVE-2026-25133 2026-04-18 00:38 2026-04-15 Show GitHub Exploit DB Packet Storm
278 7.2 HIGH
Network
- - Chamilo LMS is an open-source learning management system. In version 2.0-RC.2, the file public/main/inc/ajax/install.ajax.php is accessible without authentication on fully installed instances because… Update CWE-306
CWE-918
Missing Authentication for Critical Function
Server-Side Request Forgery (SSRF) 
CVE-2026-33715 2026-04-18 00:38 2026-04-15 Show GitHub Exploit DB Packet Storm
279 8.6 HIGH
Network
- - Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the PENS (Package Exchange Notification Services) plugin endpoint at public/plugin/Pens/pens.php is accessib… Update CWE-306
CWE-918
Missing Authentication for Critical Function
Server-Side Request Forgery (SSRF) 
CVE-2026-34160 2026-04-18 00:38 2026-04-15 Show GitHub Exploit DB Packet Storm
280 - - - Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, a Stored Cross-Site Scripting (XSS) vulnerability exists in the social post attachment upload functionality,… Update CWE-79
Cross-site Scripting
CVE-2026-34161 2026-04-18 00:38 2026-04-15 Show GitHub Exploit DB Packet Storm