Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 17, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
230121 6.8 警告 XOOPS - XOOPS 用の Cjay Content モジュールにおける PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-3220 2012-12-20 18:19 2007-06-14 Show GitHub Exploit DB Packet Storm
230122 7.5 危険 prototype of an php application - PHP アプリケーションの Prototype における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-3217 2012-12-20 18:19 2007-06-14 Show GitHub Exploit DB Packet Storm
230123 6.8 警告 PHPMailer project - PHPMailer における任意のシェルコマンドを実行される脆弱性 - CVE-2007-3215 2012-12-20 18:19 2007-06-11 Show GitHub Exploit DB Packet Storm
230124 10 危険 PhpWiki - PhpWiki の lib/WikiUser/LDAP.php における認証を回避される脆弱性 - CVE-2007-3193 2012-12-20 18:19 2007-06-12 Show GitHub Exploit DB Packet Storm
230125 6.8 警告 vincent hor - Calendarix における SQL インジェクションの脆弱性 - CVE-2007-3183 2012-12-20 18:19 2007-06-26 Show GitHub Exploit DB Packet Storm
230126 4.3 警告 vincent hor - Calendarix におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-3182 2012-12-20 18:19 2007-06-26 Show GitHub Exploit DB Packet Storm
230127 7.5 危険 zindizayn okul web sistemi - Zindizayn Okul Web Sistemi における SQL インジェクションの脆弱性 - CVE-2007-3178 2012-12-20 18:19 2007-06-11 Show GitHub Exploit DB Packet Storm
230128 7.5 危険 w2b - W2B Online Banking における SQL インジェクションの脆弱性 - CVE-2007-3175 2012-12-20 18:19 2007-06-11 Show GitHub Exploit DB Packet Storm
230129 4.3 警告 w2b - W2B Online Banking の auth.w2b におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-3174 2012-12-20 18:19 2007-06-11 Show GitHub Exploit DB Packet Storm
230130 5 警告 uebimiau - Uebimiau Webmail の demo/pop3/error.php におけるディレクトリトラバーサルの脆弱性 - CVE-2007-3172 2012-12-20 18:19 2007-06-11 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 18, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
2121 5.3 MEDIUM
Network
- - An information disclosure vulnerability in dnsmasq allows remote attackers to bypass source checks via a crafted DNS packet with RFC 7871 client subnet information. - CVE-2026-4893 2026-05-12 23:15 2026-05-12 Show GitHub Exploit DB Packet Storm
2122 - - - An unauthenticated remote attacker may exhaust all available TCP connections in the CODESYS Modbus TCP Server stack if a race condition in connection handling is successfully exploited, preventing le… CWE-772
 Missing Release of Resource after Effective Lifetime
CVE-2026-35227 2026-05-12 23:15 2026-05-12 Show GitHub Exploit DB Packet Storm
2123 - - - A remote code execution vulnerability exists in Code Runner MCP Server when run with the --transport http option, which exposes the /mcp JSON-RPC endpoint without authentication on port 3088. An unau… CWE-306
Missing Authentication for Critical Function
CVE-2026-5029 2026-05-12 23:15 2026-05-12 Show GitHub Exploit DB Packet Storm
2124 - - - ATutor is vulnerable to Reflected XSS in /install/upgrade.php endpoint. An attacker can provide a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's br… CWE-79
Cross-site Scripting
CVE-2026-6909 2026-05-12 23:15 2026-05-11 Show GitHub Exploit DB Packet Storm
2125 - - - ATutor is vulnerable to Reflected XSS in /install/install.php endpoint. An attacker can provide a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's br… CWE-79
Cross-site Scripting
CVE-2026-6956 2026-05-12 23:15 2026-05-11 Show GitHub Exploit DB Packet Storm
2126 9.8 CRITICAL
Network
cross-crypto cross-implementation CROSS implementation contains reference and optimized implementations of the CROSS post-quantum signature algorithm. Prior to commit fc6b7e7, there is a buffer overflow in crypto_sign_open() caused b… CWE-121
CWE-122
Stack-based Buffer Overflow
Heap-based Buffer Overflow
CVE-2026-41509 2026-05-12 23:15 2026-05-8 Show GitHub Exploit DB Packet Storm
2127 8.1 HIGH
Network
- - An issue exists in Amazon Redshift JDBC Driver versions prior to 2.2.2. Under certain conditions, the driver could load and execute arbitrary classes when processing JDBC connection URL parameters. A… CWE-470
Unsafe Reflection
CVE-2026-8178 2026-05-12 23:13 2026-05-9 Show GitHub Exploit DB Packet Storm
2128 - - - An authorization issue was addressed with improved state management. This issue is fixed in macOS Tahoe 26.4. An app may be able to access sensitive user data. - CVE-2026-20696 2026-05-12 23:13 2026-05-12 Show GitHub Exploit DB Packet Storm
2129 - - - A race condition was addressed with additional validation. This issue is fixed in macOS Tahoe 26.4. An app may be able to access sensitive user data. - CVE-2026-28830 2026-05-12 23:13 2026-05-12 Show GitHub Exploit DB Packet Storm
2130 6.7 MEDIUM
Local
- - ACAP applications can gain elevated privileges due to improper input validation during the installation process, potentially leading to privilege escalation. This vulnerability can only be exploited … CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2026-0541 2026-05-12 23:13 2026-05-12 Show GitHub Exploit DB Packet Storm