Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":April 29, 2026, noon

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
229241 4.3 警告 orbitcoders - Orbitcoders OrbitMATRIX の index.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-3609 2012-12-20 18:02 2006-07-18 Show GitHub Exploit DB Packet Storm
229242 4.6 警告 flatnuke - Simone Vellei Flatnuke の Gallery モジュールにおける任意の PHP コードを実行される脆弱性 - CVE-2006-3608 2012-12-20 18:02 2006-07-18 Show GitHub Exploit DB Packet Storm
229243 4.3 警告 softbiz - Softbiz Banner Exchange Script におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-3607 2012-12-20 18:02 2006-07-18 Show GitHub Exploit DB Packet Storm
229244 5 警告 マイクロソフト - Microsoft Internet Explorer 6 におけるサービス運用妨害 (DoS) の脆弱性 - CVE-2006-3605 2012-12-20 18:02 2006-07-18 Show GitHub Exploit DB Packet Storm
229245 7.5 危険 seyeon - FlexWATCH Network Camera におけるディレクトリトラバーサルの脆弱性 - CVE-2006-3604 2012-12-20 18:02 2006-07-18 Show GitHub Exploit DB Packet Storm
229246 5.8 警告 seyeon - FlexWATCH Network Camera の index.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-3603 2012-12-20 18:02 2006-07-18 Show GitHub Exploit DB Packet Storm
229247 5 警告 farsinews - FarsiNews の jscripts/tiny_mce/tiny_mce_gzip.php におけるディレクトリトラバーサルの脆弱性 - CVE-2006-3602 2012-12-20 18:02 2006-07-18 Show GitHub Exploit DB Packet Storm
229248 5.1 警告 libtunepimp - TunePimp の LookupTRM::lookup 関数におけるスタックベースのバッファーオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2006-3600 2012-12-20 18:02 2006-07-18 Show GitHub Exploit DB Packet Storm
229249 7.5 危険 PHPNUKE - PHP-Nuke 用の Nuke Advanced Classifieds モジュールにおける SQL インジェクションの脆弱性 - CVE-2006-3599 2012-12-20 18:02 2006-07-18 Show GitHub Exploit DB Packet Storm
229250 7.5 危険 PHPNUKE - PHP-Nuke 用の Sections モジュールにおける SQL インジェクションの脆弱性 - CVE-2006-3598 2012-12-20 18:02 2006-07-18 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 29, 2026, 4:51 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
351 7.3 HIGH
Network
- - A vulnerability was detected in JoeCastrom mcp-chat-studio up to 1.5.0. Affected by this issue is some unknown functionality of the file server/routes/llm.js of the component LLM Models API. Performi… New CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-7147 2026-04-28 04:25 2026-04-28 Show GitHub Exploit DB Packet Storm
352 6.3 MEDIUM
Network
- - A flaw has been found in CodeAstro Online Classroom 1.0. This affects an unknown part of the file /addnewfaculty. Executing a manipulation of the argument fname can lead to sql injection. The attack … New CWE-74
CWE-89
Injection
SQL Injection
CVE-2026-7148 2026-04-28 04:25 2026-04-28 Show GitHub Exploit DB Packet Storm
353 7.3 HIGH
Network
- - A vulnerability has been found in dexhunter kaggle-mcp up to 406127ffcb2b91b8c10e20e6c2ca787fbc1dc92d. This vulnerability affects the function prepare_kaggle_dataset of the file src/kaggle_mcp/server… New CWE-22
Path Traversal
CVE-2026-7149 2026-04-28 04:25 2026-04-28 Show GitHub Exploit DB Packet Storm
354 6.3 MEDIUM
Network
- - A vulnerability was found in dh1011 auto-favicon up to f189116a9259950c2393f114dbcb94dde0ad864b. This issue affects the function generate_favicon_from_url of the file src/auto_favicon/server.py of th… New CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-7150 2026-04-28 04:25 2026-04-28 Show GitHub Exploit DB Packet Storm
355 - - - AdaptiveGRC is vulnerable to Stored XSS via text type fields across the forms. Authenticated attacker can replace the value of the text field in the HTTP POST request. Improper parameter validation b… Update CWE-79
Cross-site Scripting
CVE-2026-4313 2026-04-28 04:23 2026-04-24 Show GitHub Exploit DB Packet Storm
356 7.5 HIGH
Network
getkirby kirby Kirby is an open-source content management system. Kirby's `Xml::value()` method has special handling for `<![CDATA[ ]]>` blocks. If the input value is already valid `CDATA`, it is not escaped a seco… Update CWE-91
Blind XPath Injection
CVE-2026-32870 2026-04-28 04:21 2026-04-24 Show GitHub Exploit DB Packet Storm
357 8.1 HIGH
Network
getkirby kirby Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, Kirby's user permissions control which user role is allowed to perform specific actions to content models in the … Update CWE-1336
 Improper Neutralization of Special Elements Used in a Template Engine
CVE-2026-34587 2026-04-28 04:15 2026-04-24 Show GitHub Exploit DB Packet Storm
358 6.5 MEDIUM
Network
getkirby kirby Kirby is an open-source content management system. Kirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined … Update CWE-863
 Incorrect Authorization
CVE-2026-40099 2026-04-28 04:12 2026-04-24 Show GitHub Exploit DB Packet Storm
359 8.8 HIGH
Network
getkirby kirby Kirby is an open-source content management system. Kirby's user permissions control which user role is allowed to perform specific actions to content models in the CMS. These permissions are defined … Update CWE-863
 Incorrect Authorization
CVE-2026-41325 2026-04-28 04:07 2026-04-24 Show GitHub Exploit DB Packet Storm
360 - - - Marked is a markdown parser and compiler. From 18.0.0 to 18.0.1, a critical Denial of Service (DoS) vulnerability exists in marked. By providing a specific 3-byte input sequence a tab, a vertical tab… Update CWE-400
CWE-674
CWE-835
 Uncontrolled Resource Consumption
 Uncontrolled Recursion
 Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2026-41680 2026-04-28 03:57 2026-04-25 Show GitHub Exploit DB Packet Storm