Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 2, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
229321 6.8 警告 ultimate helpdesk - Ultimate HelpDesk の index.asp におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-6380 2012-12-20 18:02 2006-12-7 Show GitHub Exploit DB Packet Storm
229322 7.5 危険 widcomm - BTSaveMySql における設定情報を取得される脆弱性 - CVE-2006-6378 2012-12-20 18:02 2006-12-7 Show GitHub Exploit DB Packet Storm
229323 7.5 危険 uploadscript - Uploadscript における admin パスワードハッシュを取得される脆弱性 - CVE-2006-6377 2012-12-20 18:02 2006-12-7 Show GitHub Exploit DB Packet Storm
229324 6.8 警告 Simple Machines - SMF の display.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-6375 2012-12-20 18:02 2006-12-7 Show GitHub Exploit DB Packet Storm
229325 7.5 危険 The phpMyAdmin Project - PhpMyAdmin における CRLF インジェクションの脆弱性 - CVE-2006-6374 2012-12-20 18:02 2006-12-7 Show GitHub Exploit DB Packet Storm
229326 5 警告 The phpMyAdmin Project - PhpMyAdmin における重要な情報を取得される脆弱性 - CVE-2006-6373 2012-12-20 18:02 2006-12-7 Show GitHub Exploit DB Packet Storm
229327 7.5 危険 sergey korostel - PHP Upload Center の activate.php における PHP リモートファイルインクルージョンの脆弱性 - CVE-2006-6360 2012-12-20 18:02 2006-12-7 Show GitHub Exploit DB Packet Storm
229328 6.8 警告 stefan frech - Stefan Frech online-bookmarks におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-6359 2012-12-20 18:02 2006-12-7 Show GitHub Exploit DB Packet Storm
229329 7.5 危険 stefan frech - Stefan Frech online-bookmarks の auth.inc における SQL インジェクションの脆弱性 - CVE-2006-6358 2012-12-20 18:02 2006-12-7 Show GitHub Exploit DB Packet Storm
229330 7.5 危険 SAP - SAP IGS におけるディレクトリトラバーサルの脆弱性 - CVE-2006-6345 2012-12-20 18:02 2006-12-6 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 2, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
801 7.3 HIGH
Network
- - A security vulnerability has been detected in vanna-ai vanna up to 2.0.2. The affected element is an unknown function of the component Legacy Flask API. The manipulation leads to improper authorizati… CWE-266
CWE-285
 Incorrect Privilege Assignment
Improper Authorization
CVE-2026-6977 2026-04-29 10:00 2026-04-25 Show GitHub Exploit DB Packet Storm
802 4.7 MEDIUM
Network
- - A vulnerability was detected in JiZhiCMS up to 2.5.6. The impacted element is the function htmlspecialchars_decode of the file /index.php/admins/Sys/addcache.html. The manipulation of the argument sq… CWE-74
CWE-89
Injection
SQL Injection
CVE-2026-6978 2026-04-29 10:00 2026-04-25 Show GitHub Exploit DB Packet Storm
803 6.3 MEDIUM
Network
- - A flaw has been found in devlikeapro WAHA up to 2026.3.4. This affects an unknown function of the file src/api/media.controller.ts of the component API Request Handler. This manipulation causes serve… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-6979 2026-04-29 10:00 2026-04-25 Show GitHub Exploit DB Packet Storm
804 4.7 MEDIUM
Network
- - A vulnerability was identified in pagekit up to 1.0.18. Affected by this issue is some unknown functionality of the file /index.php/admin/system/update/download. The manipulation of the argument url … CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-6983 2026-04-29 10:00 2026-04-26 Show GitHub Exploit DB Packet Storm
805 4.7 MEDIUM
Network
- - A security flaw has been discovered in AstrBotDevs AstrBot up to 4.22.1. This affects the function create_template of the file astrbot/dashboard/routes/t2i.py of the component Dashboard API. The mani… CWE-791
CWE-1336
 Incomplete Filtering of Special Elements
 Improper Neutralization of Special Elements Used in a Template Engine
CVE-2026-6984 2026-04-29 10:00 2026-04-26 Show GitHub Exploit DB Packet Storm
806 7.3 HIGH
Network
- - A vulnerability was detected in PicoClaw up to 0.2.4. Impacted is an unknown function of the file /api/gateway/restart of the component Web Launcher Management Plane. Performing a manipulation result… CWE-74
CWE-77
Injection
Command Injection
CVE-2026-6987 2026-04-29 10:00 2026-04-26 Show GitHub Exploit DB Packet Storm
807 3.5 LOW
Network
- - A vulnerability was found in projeto-siga siga 11.0.3.18. The affected element is an unknown function of the file /sigawf/app/responsavel/novo. Performing a manipulation of the argument Nome/Descriçã… CWE-79
CWE-94
Cross-site Scripting
Code Injection
CVE-2026-6990 2026-04-29 10:00 2026-04-26 Show GitHub Exploit DB Packet Storm
808 6.3 MEDIUM
Network
- - A vulnerability was determined in colinhacks Zod up to 4.3.6. The impacted element is an unknown function of the file packages/zod/src/v4/core/regexes.ts of the component CUID Data Type Handler. Exec… CWE-74
CWE-89
Injection
SQL Injection
CVE-2026-6991 2026-04-29 10:00 2026-04-26 Show GitHub Exploit DB Packet Storm
809 2.4 LOW
Network
- - A security flaw has been discovered in BDCOM P3310D 0.4.2 10.1.0F Build 86345. The impacted element is an unknown function of the file /index.asp of the component New User Page. Performing a manipula… CWE-79
CWE-94
Cross-site Scripting
Code Injection
CVE-2026-6995 2026-04-29 10:00 2026-04-26 Show GitHub Exploit DB Packet Storm
810 2.4 LOW
Network
- - A weakness has been identified in BDCOM P3310D 0.4.2 10.1.0F Build 86345. This affects an unknown function of the component rmon event Tab. Executing a manipulation of the argument Description can le… CWE-79
CWE-94
Cross-site Scripting
Code Injection
CVE-2026-6996 2026-04-29 10:00 2026-04-26 Show GitHub Exploit DB Packet Storm