Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 31, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
232201 7.5 危険 トレンドマイクロ - Linux 用の Trend Micro ServerProtect における任意の Web ページをアクセスされる脆弱性 - CVE-2007-1168 2012-12-20 18:19 2007-03-2 Show GitHub Exploit DB Packet Storm
232202 7.5 危険 webSPELL - webSPELL の printview.php における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-1163 2012-12-20 18:19 2007-03-2 Show GitHub Exploit DB Packet Storm
232203 10 危険 webSPELL - webSPELL における認証を回避される脆弱性 CWE-287
不適切な認証
CVE-2007-1160 2012-12-20 18:19 2007-03-2 Show GitHub Exploit DB Packet Storm
232204 4.3 警告 pyrophobia - Pyrophobia の modules/out.php におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-1159 2012-12-20 18:19 2007-03-2 Show GitHub Exploit DB Packet Storm
232205 5 警告 postnuke software foundation - PostNuke 用の Pagesetter モジュールにおけるディレクトリトラバーサルの脆弱性 - CVE-2007-1158 2012-12-20 18:19 2007-03-2 Show GitHub Exploit DB Packet Storm
232206 4.6 警告 webSPELL - webSPELL における任意の PHP コードを実行される脆弱性 CWE-20
不適切な入力確認
CVE-2007-1155 2012-12-20 18:19 2007-03-2 Show GitHub Exploit DB Packet Storm
232207 6.8 警告 webSPELL - webSPELL における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2007-1154 2012-12-20 18:19 2007-03-2 Show GitHub Exploit DB Packet Storm
232208 5 警告 pyrophobia - Pyrophobia におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2007-1152 2012-12-20 18:19 2007-03-2 Show GitHub Exploit DB Packet Storm
232209 4.3 警告 reamday enterprises - Magic News Plus におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2007-1142 2012-12-20 18:19 2007-03-2 Show GitHub Exploit DB Packet Storm
232210 7.5 危険 reamday enterprises - Magic News Plus の preview.php における PHP リモートファイルインクルージョンの脆弱性 CWE-94
コード・インジェクション
CVE-2007-1141 2012-12-20 18:19 2007-03-2 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 1, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
781 8.5 HIGH
Network
networktocode nautobot Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, Nautobot's Webhook data model and associated feature set could be configured by users with sufficient… New CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2026-44797 2026-05-29 22:26 2026-05-29 Show GitHub Exploit DB Packet Storm
782 - - - Rejected reason: Further research determined the issue is not a vulnerability. New - CVE-2026-45611 2026-05-29 22:16 2026-05-29 Show GitHub Exploit DB Packet Storm
783 9.9 CRITICAL
Network
- - RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In 0.24.0 and earlier, a Jinja2 template injection in the prompt generator (rag/prompts/generator.py) allows any authenticated u… New CWE-1336
 Improper Neutralization of Special Elements Used in a Template Engine
CVE-2026-45312 2026-05-29 22:16 2026-05-29 Show GitHub Exploit DB Packet Storm
784 6.4 MEDIUM
Network
- - The Automotive Car Dealership Business WordPress Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Project Details' custom field in Portfolio Items in all versions up to, and … New CWE-79
Cross-site Scripting
CVE-2025-14042 2026-05-29 22:09 2026-05-29 Show GitHub Exploit DB Packet Storm
785 4.4 MEDIUM
Network
- - The Post Snippets plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.0.19. This is due to insufficient output escaping of imported snippet conte… New CWE-79
Cross-site Scripting
CVE-2026-7430 2026-05-29 22:09 2026-05-29 Show GitHub Exploit DB Packet Storm
786 4.3 MEDIUM
Network
- - The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to and including 6.3.7. This is due to insufficient acc… New CWE-200
Information Exposure
CVE-2026-8995 2026-05-29 22:09 2026-05-29 Show GitHub Exploit DB Packet Storm
787 5.3 MEDIUM
Network
- - The Breeze plugin for WordPress is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in all versions up to, and including, 2.5.2 This is due to improper verification of the `wo… New CWE-200
Information Exposure
CVE-2026-2128 2026-05-29 22:09 2026-05-29 Show GitHub Exploit DB Packet Storm
788 8.8 HIGH
Network
- - The WooCommerce Infinite Scroll and Ajax Pagination plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.8 via the 'settings' parameter in the 'import_se… New CWE-502
 Deserialization of Untrusted Data
CVE-2025-11993 2026-05-29 22:09 2026-05-29 Show GitHub Exploit DB Packet Storm
789 6.4 MEDIUM
Network
- - The StatCounter – Free Real Time Visitor Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.1 This is due to insufficient output escaping on… New CWE-79
Cross-site Scripting
CVE-2026-6275 2026-05-29 22:09 2026-05-29 Show GitHub Exploit DB Packet Storm
790 7.2 HIGH
Network
- - The Link Whisper Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user_id parameter in all versions up to, and including, 0.9.0 due to insufficient input sanitization an… New CWE-79
Cross-site Scripting
CVE-2025-11262 2026-05-29 22:09 2026-05-29 Show GitHub Exploit DB Packet Storm