Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 11, 2026, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
228771 4.3 警告 project alumni - project alumni におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-6126 2012-12-20 18:33 2007-11-26 Show GitHub Exploit DB Packet Storm
228772 7.5 危険 softbiz - Softbiz Freelancers Script の search_form.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-6125 2012-12-20 18:33 2007-11-26 Show GitHub Exploit DB Packet Storm
228773 4.3 警告 softbiz - Softbiz Freelancers Script の signin.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-6124 2012-12-20 18:33 2007-11-26 Show GitHub Exploit DB Packet Storm
228774 6.8 警告 talkback - TalkBack における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2007-6105 2012-12-20 18:33 2007-11-23 Show GitHub Exploit DB Packet Storm
228775 2.6 注意 The phpMyAdmin Project - phpMyAdmin の libraries/auth/cookie.auth.lib.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-6100 2012-12-20 18:33 2007-11-20 Show GitHub Exploit DB Packet Storm
228776 9.3 危険 phpbbviet - phpBBViet の includes/functions_mod_user.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2007-6088 2012-12-20 18:33 2007-11-21 Show GitHub Exploit DB Packet Storm
228777 6.8 警告 vigilecms - VigileCMS の index.php におけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2007-6087 2012-12-20 18:33 2007-11-21 Show GitHub Exploit DB Packet Storm
228778 9.3 危険 vigilecms - VigileCMS の index.php におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2007-6086 2012-12-20 18:33 2007-11-21 Show GitHub Exploit DB Packet Storm
228779 4.3 警告 vigilecms - VigileCMS の index.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-6085 2012-12-20 18:33 2007-11-21 Show GitHub Exploit DB Packet Storm
228780 9.3 危険 sciurus - Sciurus Hosting Panel の acp/savenews.php における任意の PHP コードを挿入される脆弱性 CWE-94
コード・インジェクション
CVE-2007-6082 2012-12-20 18:33 2007-11-21 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 11, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
2361 6.7 MEDIUM
Local
- - Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.93212. CWE-427
 Uncontrolled Search Path Element
CVE-2026-25852 2026-05-1 00:48 2026-04-30 Show GitHub Exploit DB Packet Storm
2362 7.8 HIGH
Local
- - Local privilege escalation due to improper input validation. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.93212, Acronis Cyber Protect Cloud Agent (Windows) … CWE-787
 Out-of-bounds Write
CVE-2026-41220 2026-05-1 00:48 2026-04-30 Show GitHub Exploit DB Packet Storm
2363 7.8 HIGH
Local
- - Local privilege escalation due to improper input validation. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.93212, Acronis Cyber Protect Cloud Agent (Windows) … CWE-123
 Write-what-where Condition
CVE-2026-41952 2026-05-1 00:48 2026-04-30 Show GitHub Exploit DB Packet Storm
2364 6.1 MEDIUM
Network
- - A cross-site scripting (XSS) vulnerability in the custom authenticator driver of opennebula v6.10.0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. CWE-79
Cross-site Scripting
CVE-2025-56534 2026-05-1 00:48 2026-04-30 Show GitHub Exploit DB Packet Storm
2365 6.1 MEDIUM
Network
- - A cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the zone attribute parameter. CWE-79
Cross-site Scripting
CVE-2025-56535 2026-05-1 00:48 2026-04-30 Show GitHub Exploit DB Packet Storm
2366 6.1 MEDIUM
Network
- - A stored cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the user information parameter. CWE-79
Cross-site Scripting
CVE-2025-56536 2026-05-1 00:48 2026-04-30 Show GitHub Exploit DB Packet Storm
2367 6.1 MEDIUM
Network
- - A stored cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 and fixed in v.7.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the virtual… CWE-79
Cross-site Scripting
CVE-2025-56537 2026-05-1 00:48 2026-04-30 Show GitHub Exploit DB Packet Storm
2368 5.3 MEDIUM
Network
- - Merge PACS 7.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by crafting malicious HTML forms targeting the merge-viewer endpoint. Attacker… CWE-352
 Origin Validation Error
CVE-2018-25298 2026-05-1 00:48 2026-04-30 Show GitHub Exploit DB Packet Storm
2369 8.4 HIGH
Local
- - Prime95 29.4b8 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by exploiting structured exception handling (SEH) mechanisms. Attackers can inject malici… CWE-120
Classic Buffer Overflow
CVE-2018-25299 2026-05-1 00:48 2026-04-30 Show GitHub Exploit DB Packet Storm
2370 6.2 MEDIUM
Local
- - librsvg2-bin 2.40.13 contains a buffer overflow vulnerability that allows local attackers to cause a denial of service by processing malformed SVG files. Attackers can supply crafted SVG input to the… CWE-120
Classic Buffer Overflow
CVE-2018-25305 2026-05-1 00:48 2026-04-30 Show GitHub Exploit DB Packet Storm