Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":April 29, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228241 7.5 危険 phpwind - PHPWind の admin.php における SQL インジェクションの脆弱性 - CVE-2006-7101 2012-12-20 18:18 2007-03-3 Show GitHub Exploit DB Packet Storm
228242 6.8 警告 phpBB - phpBB Insert User の includes/functions_mod_user.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2006-7100 2012-12-20 18:18 2007-03-3 Show GitHub Exploit DB Packet Storm
228243 5 警告 solarpay - SolarPay の index.php におけるディレクトリトラバーサルの脆弱性 - CVE-2006-7099 2012-12-20 18:18 2007-03-3 Show GitHub Exploit DB Packet Storm
228244 10 危険 taskfreak - TaskFreak! における脆弱性 - CVE-2006-7097 2012-12-20 18:18 2007-03-2 Show GitHub Exploit DB Packet Storm
228245 6.8 警告 phpbb security - phpBB Security の phpbb_security.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2006-7090 2012-12-20 18:18 2007-03-2 Show GitHub Exploit DB Packet Storm
228246 7.5 危険 simple php forum - Simple PHP Forum における SQL インジェクションの脆弱性 - CVE-2006-7088 2012-12-20 18:18 2007-03-2 Show GitHub Exploit DB Packet Storm
228247 4.3 警告 rigter portal system - RPS における XSS 攻撃を実行される脆弱性 - CVE-2006-7085 2012-12-20 18:18 2007-03-2 Show GitHub Exploit DB Packet Storm
228248 4.3 警告 rigter portal system - RPS の index.php におけるディレクトリトラバーサルの脆弱性 - CVE-2006-7083 2012-12-20 18:18 2007-03-2 Show GitHub Exploit DB Packet Storm
228249 7.5 危険 rigter portal system - RPS における認証を回避される脆弱性 - CVE-2006-7082 2012-12-20 18:18 2007-03-2 Show GitHub Exploit DB Packet Storm
228250 7.5 危険 phpnews - PhpNews における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-7081 2012-12-20 18:18 2007-03-2 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 29, 2026, 4:51 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1241 7.3 HIGH
Network
- - Una falla de seguridad ha sido descubierta en itsourcecode Payroll Management System 1.0. Afectada por esta vulnerabilidad es una funcionalidad desconocida del archivo /manage_user.php del componente… CWE-74
CWE-89
Injection
SQL Injection
CVE-2026-5237 2026-04-25 03:12 2026-04-1 Show GitHub Exploit DB Packet Storm
1242 7.3 HIGH
Network
- - A weakness has been identified in itsourcecode Payroll Management System 1.0. Affected by this issue is some unknown functionality of the file /view_employee.php of the component Parameter Handler. E… CWE-74
CWE-89
Injection
SQL Injection
CVE-2026-5238 2026-04-25 03:12 2026-04-1 Show GitHub Exploit DB Packet Storm
1243 5.3 MEDIUM
Local
- - Se identificó una vulnerabilidad en Axiomatic Bento4 hasta la versión 1.6.0-641. Se ve afectada la función AP4_BitReader::SkipBits del archivo Ap4Dac4Atom.cpp del componente DSI v1 Parser. Dicha mani… CWE-119
CWE-122
Incorrect Access of Indexable Resource ('Range Error') 
Heap-based Buffer Overflow
CVE-2026-5236 2026-04-25 03:12 2026-04-1 Show GitHub Exploit DB Packet Storm
1244 6.5 MEDIUM
Network
- - The Booking for Appointments and Events Calendar - Amelia plugin for WordPress is vulnerable to SQL Injection via the `sort` parameter in the payments listing endpoint in all versions up to, and incl… CWE-89
SQL Injection
CVE-2026-4668 2026-04-25 03:12 2026-04-1 Show GitHub Exploit DB Packet Storm
1245 6.5 MEDIUM
Network
- - El plugin Booking for Appointments and Events Calendar - Amelia para WordPress es vulnerable a inyección SQL a través del parámetro `sort` en el endpoint de listado de pagos en todas las versiones ha… CWE-89
SQL Injection
CVE-2026-4668 2026-04-25 03:12 2026-04-1 Show GitHub Exploit DB Packet Storm
1246 7.3 HIGH
Network
- - Se ha identificado una debilidad en itsourcecode Payroll Management System 1.0. Este problema afecta a alguna funcionalidad desconocida del archivo /view_employee.php del componente Gestor de Parámet… CWE-74
CWE-89
Injection
SQL Injection
CVE-2026-5238 2026-04-25 03:12 2026-04-1 Show GitHub Exploit DB Packet Storm
1247 4.3 MEDIUM
Network
- - A security vulnerability has been detected in code-projects BloodBank Managing System 1.0. This affects an unknown part of the file /admin_state.php. The manipulation of the argument statename leads … CWE-79
CWE-94
Cross-site Scripting
Code Injection
CVE-2026-5240 2026-04-25 03:12 2026-04-1 Show GitHub Exploit DB Packet Storm
1248 4.3 MEDIUM
Network
- - Una vulnerabilidad de seguridad ha sido detectada en code-projects BloodBank Managing System 1.0. Esto afecta una parte desconocida del archivo /admin_state.php. La manipulación del argumento statena… CWE-79
CWE-94
Cross-site Scripting
Code Injection
CVE-2026-5240 2026-04-25 03:12 2026-04-1 Show GitHub Exploit DB Packet Storm
1249 6.3 MEDIUM
Network
- - A vulnerability has been found in gougucms 4.08.18. This affects the function reg_submit of the file gougucms-master\app\home\controller\Login.php of the component User Registration Handler. Such man… CWE-913
CWE-915
 Improper Control of Dynamically-Managed Code Resources
 Improperly Controlled Modification of Dynamically-Determined Object Attributes
CVE-2026-5248 2026-04-25 03:12 2026-04-1 Show GitHub Exploit DB Packet Storm
1250 4.3 MEDIUM
Network
- - The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the entries_shortcode() function in al… CWE-862
 Missing Authorization
CVE-2026-3831 2026-04-25 03:12 2026-04-1 Show GitHub Exploit DB Packet Storm