Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 4, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228421 7.8 危険 r2k - R2K Gallery の galeria.php におけるディレクトリトラバーサルの脆弱性 - CVE-2007-2642 2012-12-20 18:19 2007-05-13 Show GitHub Exploit DB Packet Storm
228422 7.5 危険 w1l3d4 - W1L3D4 Philboard の W1L3D4_bolum.asp における SQL インジェクションの脆弱性 - CVE-2007-2641 2012-12-20 18:19 2007-05-13 Show GitHub Exploit DB Packet Storm
228423 10 危険 prosysinfo - TFTPdWin におけるディレクトリトラバーサルの脆弱性 - CVE-2007-2639 2012-12-20 18:19 2007-05-13 Show GitHub Exploit DB Packet Storm
228424 10 危険 positive software - H-Sphere SiteStudio におけるディレクトリトラバーサルの脆弱性 - CVE-2007-2633 2012-12-20 18:19 2007-05-13 Show GitHub Exploit DB Packet Storm
228425 7.5 危険 SquirrelMail Project - SquirrelMail におけるクロスサイトリクエストフォージェリの脆弱性 - CVE-2007-2631 2012-12-20 18:19 2007-05-13 Show GitHub Exploit DB Packet Storm
228426 6.8 警告 WordPress.org - WordPress の sidebar.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-2627 2012-12-20 18:19 2007-05-11 Show GitHub Exploit DB Packet Storm
228427 7.5 危険 taskdriver - TaskDriver における SQL インジェクションの脆弱性 - CVE-2007-2622 2012-12-20 18:19 2007-05-11 Show GitHub Exploit DB Packet Storm
228428 4.6 警告 シマンテック - Symantec pcAnywhere における資格情報を取得される脆弱性 - CVE-2007-2619 2012-12-20 18:19 2007-05-11 Show GitHub Exploit DB Packet Storm
228429 2.1 注意 サン・マイクロシステムズ - Sun Solaris の SRS Net Connect Software Proxy Core パッケージにおける任意のファイルの最初の行を読まれる脆弱性 - CVE-2007-2617 2012-12-20 18:19 2007-05-11 Show GitHub Exploit DB Packet Storm
228430 7.5 危険 phphtmllib - phpHtmlLib の examples/widget8.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-2614 2012-12-20 18:19 2007-05-11 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 4, 2026, 4:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1771 - - - In the Linux kernel, the following vulnerability has been resolved: wireguard: device: use exit_rtnl callback instead of manual rtnl_lock in pre_exit wg_netns_pre_exit() manually acquires rtnl_lock… - CVE-2026-31579 2026-04-27 21:16 2026-04-25 Show GitHub Exploit DB Packet Storm
1772 - - - In the Linux kernel, the following vulnerability has been resolved: clockevents: Add missing resets of the next_event_forced flag The prevention mechanism against timer interrupt starvation missed … - CVE-2026-31574 2026-04-27 21:16 2026-04-25 Show GitHub Exploit DB Packet Storm
1773 5.3 MEDIUM
Network
oracle jdk
graalvm
graalvm_for_jdk
jre
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JGSS). Supported versions that are affected are Oracle Java SE: 8… CWE-693
 Protection Mechanism Failure
CVE-2026-22013 2026-04-27 21:15 2026-04-22 Show GitHub Exploit DB Packet Storm
1774 2.9 LOW
Local
oracle graalvm
graalvm_for_jdk
jre
jdk
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java S… CWE-200
Information Exposure
CVE-2026-22007 2026-04-27 21:14 2026-04-22 Show GitHub Exploit DB Packet Storm
1775 5.4 MEDIUM
Network
- - A client-side authorization flaw in Lightspeed Classroom v5.1.2.1763770643 allows unauthenticated attackers to impersonate users by bypassing integrity checks and abusing client-generated authorizati… CWE-863
 Incorrect Authorization
CVE-2026-30368 2026-04-27 20:16 2026-04-25 Show GitHub Exploit DB Packet Storm
1776 5.3 MEDIUM
Network
- - A security vulnerability has been detected in CodeAstro Online Job Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /users/user-cvs/. The manipulation leads to file … CWE-200
CWE-538
Information Exposure
 File and Directory Information Exposure
CVE-2026-7071 2026-04-27 10:16 2026-04-27 Show GitHub Exploit DB Packet Storm
1777 9.3 CRITICAL
Network
- - An insufficient encryption vulnerability exists in the Device Authentication functionality of GeoVision GV-IP Device Utility 9.0.5. Listening to broadcast packets can lead to credentials leak. An att… CWE-656
 Reliance on Security Through Obscurity
CVE-2026-42363 2026-04-27 09:16 2026-04-27 Show GitHub Exploit DB Packet Storm
1778 7.5 HIGH
Network
libexpat_project libexpat libexpat before 2.7.6 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document. CWE-331
 Insufficient Entropy
CVE-2026-41080 2026-04-27 07:17 2026-04-17 Show GitHub Exploit DB Packet Storm
1779 7.1 HIGH
Network
elog_project elog ELOG allows an authenticated user to modify or overwrite the configuration file, resulting in denial of service. If the execute facility is specifically enabled with the "-x" command line flag, attac… CWE-862
 Missing Authorization
CVE-2025-64348 2026-04-27 04:26 2025-11-1 Show GitHub Exploit DB Packet Storm
1780 7.1 HIGH
Network
elog_project elog ELOG permite a un usuario autenticado modificar o sobrescribir el archivo de configuración, resultando en denegación de servicio. Si la función de ejecución está específicamente habilitada con el ind… CWE-862
 Missing Authorization
CVE-2025-64348 2026-04-27 04:26 2025-11-1 Show GitHub Exploit DB Packet Storm