Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 11, 2026, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228301 3.5 注意 PunBB - PunBB のパスワードリセット機能における新規パスワードを特定される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-1484 2012-12-20 18:52 2008-02-20 Show GitHub Exploit DB Packet Storm
228302 6.8 警告 Xine - xine-lib における整数オーバーフローの脆弱性 CWE-119
CWE-189
CVE-2008-1482 2012-12-20 18:52 2008-03-24 Show GitHub Exploit DB Packet Storm
228303 4.3 警告 webSPELL - webSPELL の index.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-1481 2012-12-20 18:52 2008-03-24 Show GitHub Exploit DB Packet Storm
228304 4.3 警告 s9y - S9Y におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-1476 2012-12-20 18:52 2008-03-18 Show GitHub Exploit DB Packet Storm
228305 6.4 警告 Roundup - Roundup の xml-rpc サーバにおける制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-1475 2012-12-20 18:52 2008-03-24 Show GitHub Exploit DB Packet Storm
228306 4.3 警告 Roundup - Roundup における脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-1474 2012-12-20 18:52 2008-03-24 Show GitHub Exploit DB Packet Storm
228307 7.2 危険 シマンテック - Symantec Altiris Deployment Solution の Altiris Client Service における権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-1473 2012-12-20 18:52 2008-03-10 Show GitHub Exploit DB Packet Storm
228308 4.3 警告 RSAセキュリティ - WebID RSA Authentication Agent の IISWebAgentIF.dll におけるクロスサイトスクリプティング (XSS) 攻撃を実行される脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-1470 2012-12-20 18:52 2008-03-24 Show GitHub Exploit DB Packet Storm
228309 7.5 危険 W-Agora - W-Agora における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2008-1466 2012-12-20 18:52 2008-03-24 Show GitHub Exploit DB Packet Storm
228310 6.8 警告 runcms - RunCMS の Section モジュールにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-1462 2012-12-20 18:52 2008-03-24 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 12, 2026, 5:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
2671 8.4 HIGH
Local
- - Alloksoft Video joiner 4.6.1217 contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string in the License Name field. Attackers can… CWE-120
Classic Buffer Overflow
CVE-2018-25315 2026-04-30 06:22 2026-04-30 Show GitHub Exploit DB Packet Storm
2672 8.8 HIGH
Network
- - Cockpit CMS contains an authenticated remote code execution vulnerability in the /cockpit/collections/save_collection endpoint that allows authenticated attackers with collection management privilege… CWE-94
Code Injection
CVE-2026-34965 2026-04-30 06:22 2026-04-30 Show GitHub Exploit DB Packet Storm
2673 5.3 MEDIUM
Network
- - A security flaw has been discovered in geldata gel-mcp 0.1.0. This impacts the function list_rules/fetch_rule of the file src/gel_mcp/server.py. The manipulation of the argument rule_name results in … CWE-22
Path Traversal
CVE-2026-7403 2026-04-30 06:16 2026-04-30 Show GitHub Exploit DB Packet Storm
2674 7.3 HIGH
Network
- - A weakness has been identified in getsimpletool mcpo-simple-server up to 0.2.0. Affected is the function delete_shared_prompt of the file src/mcpo_simple_server/services/prompt_manager/base_manager.p… CWE-22
CWE-23
Path Traversal
 Relative Path Traversal
CVE-2026-7404 2026-04-30 06:16 2026-04-30 Show GitHub Exploit DB Packet Storm
2675 4.7 MEDIUM
Network
- - A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this vulnerability is the function save_settings of the file /pizzafy/admin/ajax.php?action=save… CWE-74
CWE-89
Injection
SQL Injection
CVE-2026-7407 2026-04-30 06:16 2026-04-30 Show GitHub Exploit DB Packet Storm
2676 4.7 MEDIUM
Network
- - A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this issue is the function save_menu of the file /admin/ajax.php?action=save_menu. Performing a manipulation r… CWE-74
CWE-89
Injection
SQL Injection
CVE-2026-7408 2026-04-30 06:16 2026-04-30 Show GitHub Exploit DB Packet Storm
2677 4.4 MEDIUM
Local
- - A security flaw has been discovered in NousResearch hermes-agent 0.8.0. This affects the function _check_sensitive_path of the file tools/file_tools.py. The manipulation results in symlink following.… CWE-59
CWE-61
Link Following
 UNIX Symbolic Link (Symlink) Following
CVE-2026-7397 2026-04-30 06:16 2026-04-30 Show GitHub Exploit DB Packet Storm
2678 7.3 HIGH
Network
- - A weakness has been identified in florensiawidjaja BioinfoMCP up to 7ada7918b9e515604d3c0ae264d3a9af10bf6e54. This vulnerability affects the function Upload of the file bioinfo_mcp_platform/app.py of… CWE-22
Path Traversal
CVE-2026-7398 2026-04-30 06:16 2026-04-30 Show GitHub Exploit DB Packet Storm
2679 7.3 HIGH
Network
- - A security vulnerability has been detected in geekgod382 filesystem-mcp-server 1.0.0. This issue affects the function is_path_allowed of the file server.py of the component read_file_tool/write_file_… CWE-22
Path Traversal
CVE-2026-7400 2026-04-30 06:16 2026-04-30 Show GitHub Exploit DB Packet Storm
2680 4.3 MEDIUM
Network
- - A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This vulnerability affects unknown code of the file /index.php?action=register of the com… CWE-79
CWE-94
Cross-site Scripting
Code Injection
CVE-2026-7401 2026-04-30 06:16 2026-04-30 Show GitHub Exploit DB Packet Storm