Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
229111 3.5 注意 オラクル - Oracle E-Business Suite の Oracle Marketing における Publish Item の処理に関する脆弱性 CWE-noinfo
情報不足
CVE-2012-3164 2012-10-19 15:45 2012-10-16 Show GitHub Exploit DB Packet Storm
229112 1.7 注意 オラクル - Oracle E-Business Suite の Oracle Applications Framework における MDS ローディングの処理に関する脆弱性 CWE-noinfo
情報不足
CVE-2012-3162 2012-10-19 15:44 2012-10-16 Show GitHub Exploit DB Packet Storm
229113 3.5 注意 オラクル - Oracle E-Business Suite の Oracle Field Service における Wireless/WAP アップロードの処理に関する脆弱性 CWE-noinfo
情報不足
CVE-2012-3148 2012-10-19 15:42 2012-10-16 Show GitHub Exploit DB Packet Storm
229114 4.3 警告 オラクル - Oracle E-Business Suite の Oracle Application Object Library における Signon の処理に関する脆弱性 CWE-noinfo
情報不足
CVE-2012-3139 2012-10-19 15:41 2012-10-16 Show GitHub Exploit DB Packet Storm
229115 4.3 警告 オラクル - Oracle E-Business Suite の Oracle iStore における Web インターフェースの処理に関する脆弱性 CWE-noinfo
情報不足
CVE-2012-3138 2012-10-19 15:41 2012-10-16 Show GitHub Exploit DB Packet Storm
229116 4 警告 オラクル - Oracle PeopleSoft Products の PeopleSoft Enterprise Campus Solutions における Self-Service の処理に関する脆弱性 CWE-noinfo
情報不足
CVE-2012-3201 2012-10-19 15:25 2012-10-16 Show GitHub Exploit DB Packet Storm
229117 4 警告 オラクル - Oracle PeopleSoft Products の PeopleSoft Enterprise PeopleTools における Query の処理に関する脆弱性 CWE-noinfo
情報不足
CVE-2012-3198 2012-10-19 15:24 2012-10-16 Show GitHub Exploit DB Packet Storm
229118 4 警告 オラクル - Oracle PeopleSoft Products の PeopleSoft Enterprise PeopleTools における Portal の処理に関する脆弱性 CWE-noinfo
情報不足
CVE-2012-3195 2012-10-19 15:22 2012-10-16 Show GitHub Exploit DB Packet Storm
229119 2.1 注意 オラクル - Oracle PeopleSoft Products の PeopleSoft Enterprise PeopleTools における Data Mover の処理に関する脆弱性 CWE-noinfo
情報不足
CVE-2012-3191 2012-10-19 15:20 2012-10-16 Show GitHub Exploit DB Packet Storm
229120 3.5 注意 オラクル - Oracle PeopleSoft Products の PeopleSoft Enterprise PeopleTools における PIA Core Technology の処理に関する脆弱性 CWE-noinfo
情報不足
CVE-2012-3188 2012-10-19 15:19 2012-10-16 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 25, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
281 - - - Vite+ is a unified toolchain and entry point for web development. Prior to version 0.1.17, `downloadPackageManager()` accepts an untrusted `version` string and uses it directly in filesystem paths. A… New CWE-22
Path Traversal
CVE-2026-41211 2026-04-24 23:50 2026-04-23 Show GitHub Exploit DB Packet Storm
282 - - - OpenLearn is open-source educational forum software. Prior to commit 844b2a40a69d0c4911580fe501923f0b391313ab, when `safeMode` is enabled, unapproved forum posts are hidden from the public list, but … New CWE-284
Improper Access Control
CVE-2026-41243 2026-04-24 23:50 2026-04-23 Show GitHub Exploit DB Packet Storm
283 - - - Noir is a Domain Specific Language for SNARK proving systems that is designed to use any ACIR compatible proving system, and Brillig is the bytecode ACIR uses for non-determinism. Noir programs can i… New CWE-131
Incorrect Calculation of Buffer Size
CVE-2026-41197 2026-04-24 23:50 2026-04-23 Show GitHub Exploit DB Packet Storm
284 - - - STIG Manager is an API and web client for managing Security Technical Implementation Guides (STIG) assessments of Information Systems. Versions 1.5.10 through 1.6.7 have a reflected Cross-Site Scrip… New CWE-79
Cross-site Scripting
CVE-2026-41200 2026-04-24 23:50 2026-04-23 Show GitHub Exploit DB Packet Storm
285 8.8 HIGH
Network
- - Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Versions of @paperclipai/server prior to 2026.416.0 contain a privilege escalation vulnerability th… New CWE-78
OS Command 
CVE-2026-41208 2026-04-24 23:50 2026-04-23 Show GitHub Exploit DB Packet Storm
286 10.0 CRITICAL
Network
- - Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Prior to version 2026.416.0, an unauthenticated attacker can achieve full remote code execution on … New CWE-287
CWE-862
CWE-1188
Improper Authentication
 Missing Authorization
 Insecure Default Initialization of Resource
CVE-2026-41679 2026-04-24 23:50 2026-04-23 Show GitHub Exploit DB Packet Storm
287 5.4 MEDIUM
Network
- - Successful exploitation of the stored cross-site scripting (XSS) vulnerability could allow an attacker to execute arbitrary JavaScript on any user account that has access to Koollab LMS’ courselet fe… New - CVE-2026-3007 2026-04-24 23:50 2026-04-23 Show GitHub Exploit DB Packet Storm
288 9.9 CRITICAL
Network
- - Froxlor is open source server administration software. Prior to version 2.3.6, the Froxlor API endpoint `Customers.update` (and `Admins.update`) does not validate the `def_language` parameter against… New CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2026-41228 2026-04-24 23:50 2026-04-23 Show GitHub Exploit DB Packet Storm
289 9.1 CRITICAL
Network
- - Froxlor is open source server administration software. Prior to version 2.3.6, `PhpHelper::parseArrayToString()` writes string values into single-quoted PHP string literals without escaping single qu… New CWE-94
Code Injection
CVE-2026-41229 2026-04-24 23:50 2026-04-23 Show GitHub Exploit DB Packet Storm
290 8.5 HIGH
Network
- - Froxlor is open source server administration software. Prior to version 2.3.6, `DomainZones::add()` accepts arbitrary DNS record types without a whitelist and does not sanitize newline characters in … New CWE-93
CRLF Injection
CVE-2026-41230 2026-04-24 23:50 2026-04-23 Show GitHub Exploit DB Packet Storm