Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228551 7.5 危険 FlashTux - WeeChat におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2012-5854 2012-11-20 18:15 2012-11-9 Show GitHub Exploit DB Packet Storm
228552 4.3 警告 Piwik - Piwik におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2012-4541 2012-11-20 18:12 2012-11-19 Show GitHub Exploit DB Packet Storm
228553 5 警告 libvirt.org - libvirt の virNetServerProgramDispatchCall 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2012-4423 2012-11-20 18:11 2012-09-14 Show GitHub Exploit DB Packet Storm
228554 4.3 警告 The Document Foundation
OpenOffice.org Project
- LibreOffice および OpenOffice.org におけるサービス運用妨害 (DoS) の脆弱性 CWE-Other
その他
CVE-2012-4233 2012-11-20 18:10 2012-10-31 Show GitHub Exploit DB Packet Storm
228555 7.2 危険 NVIDIA - NVIDIA UNIX グラフィックスドライバにおける任意の物理メモリロケーションに書き込まれる脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2012-4225 2012-11-20 18:09 2012-08-2 Show GitHub Exploit DB Packet Storm
228556 5 警告 David Benjamin - nspluginwrapper におけるアクセス制限を回避される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2011-2486 2012-11-20 18:06 2011-06-30 Show GitHub Exploit DB Packet Storm
228557 6.8 警告 GNOME Project
T1lib
teTeX
- 複数の製品で使用される t1lib におけるサービス運用妨害 (DoS) の脆弱性 CWE-189
数値処理の問題
CVE-2011-5244 2012-11-20 17:49 2011-03-16 Show GitHub Exploit DB Packet Storm
228558 6.8 警告 GNOME Project
T1lib
teTeX
- 複数の製品で使用される t1lib におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2011-0433 2012-11-20 17:47 2011-02-17 Show GitHub Exploit DB Packet Storm
228559 6.8 警告 Steve Baker - PLIB の ssg/ssgParser.cxx におけるスタックベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2012-4552 2012-11-20 17:31 2012-11-18 Show GitHub Exploit DB Packet Storm
228560 7.5 危険 GEGL - GEGL の operations/external/ppm-load.c における整数オーバーフローの脆弱性 CWE-189
数値処理の問題
CVE-2012-4433 2012-11-20 16:25 2012-11-18 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 22, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
341 6.1 MEDIUM
Network
- - zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, the proxyUi template engine uses Go's text/template (which performs no HTML escaping) instead of html/… CWE-79
CWE-116
Cross-site Scripting
 Improper Encoding or Escaping of Output
CVE-2026-40302 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
342 4.7 MEDIUM
Network
- - DOMSanitizer is a DOM/SVG/MathML Sanitizer for PHP 7.3+. Prior to version 1.0.10, DOMSanitizer::sanitize() allows <style> elements in SVG content but never inspects their text content. CSS url() refe… CWE-79
Cross-site Scripting
CVE-2026-40301 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
343 - - - next-intl provides internationalization for Next.js. Applications using the `next-intl` middleware prior to version 4.9.1with `localePrefix: 'as-needed'` could construct URLs where path handling and … CWE-601
Open Redirect
CVE-2026-40299 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
344 6.5 MEDIUM
Network
- - OpenFGA is an authorization/permission engine built for developers. In versions 0.1.4 through 1.13.1, when OpenFGA is configured to use preshared-key authentication with the built-in playground enabl… CWE-200
Information Exposure
CVE-2026-40293 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
345 7.5 HIGH
Network
- - WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the 'Member Registration' (Cadastrar Sócio) functi… CWE-79
Cross-site Scripting
CVE-2026-40286 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
346 6.8 MEDIUM
Network
- - WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vulnerability allows an authenticated user to inject malicious JavaScript via the … CWE-79
Cross-site Scripting
CVE-2026-40284 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
347 - - - WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vulnerability allows an authenticated user to inject malicious JavaScript into the… CWE-79
Cross-site Scripting
CVE-2026-40282 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
348 8.1 HIGH
Network
- - HomeBox is a home inventory and organization system. Versions prior to 0.25.0 contain a vulnerability where the defaultGroup ID remained permanently assigned to a user after being invited to a group,… CWE-708
 Incorrect Ownership Assignment
CVE-2026-40196 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
349 5.4 MEDIUM
Network
- - The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. In versions 4.12.0 through 4.17.1, simultaneous requests that trigger a nonce retry may cause the prox… CWE-362
CWE-863
Race Condition
 Incorrect Authorization
CVE-2026-40155 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm
350 - - - Claude Code is an agentic coding tool. In versions prior to 2.1.75 on Windows, Claude Code loaded the system-wide default configuration from C:\ProgramData\ClaudeCode\managed-settings.json without va… CWE-426
 Untrusted Search Path
CVE-2026-35603 2026-04-18 06:16 2026-04-18 Show GitHub Exploit DB Packet Storm