Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 27, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
246601 6.8 警告 flap - FlaP における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-2940 2012-06-26 15:46 2007-05-30 Show GitHub Exploit DB Packet Storm
246602 7.5 危険 frequency clock - Frequency Clock における PHP リモートファイルインクルージョンの脆弱性 - CVE-2007-2936 2012-06-26 15:46 2007-05-30 Show GitHub Exploit DB Packet Storm
246603 7.5 危険 fundanemt - Fundanemt の core/spellcheck/spellcheck.php における任意のコマンドを実行される脆弱性 - CVE-2007-2935 2012-06-26 15:46 2007-05-28 Show GitHub Exploit DB Packet Storm
246604 9.3 危険 コーレル株式会社 - Corel / Micrografx ActiveCGM Browser ActiveX コントロールの acgm.dll におけるバッファオーバーフローの脆弱性 - CVE-2007-2921 2012-06-26 15:46 2007-06-14 Show GitHub Exploit DB Packet Storm
246605 9.3 危険 e-book systems - E-Book Systems FlipViewer の FViewerLoading ActiveX コントロールにおけるスタックベースのバッファオーバーフローの脆弱性 - CVE-2007-2919 2012-06-26 15:46 2007-06-6 Show GitHub Exploit DB Packet Storm
246606 9.3 危険 Authentium - Authentium Command Antivirus の odapi.dll の特定の ActiveX コントロールにおけるバッファオーバーフローの脆弱性 - CVE-2007-2917 2012-06-26 15:46 2007-05-31 Show GitHub Exploit DB Packet Storm
246607 4.3 警告 gmtt - GMTT Music Distro の showown.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-2916 2012-06-26 15:46 2007-05-30 Show GitHub Exploit DB Packet Storm
246608 4.3 警告 clonuswiki - ClonusWiki の index.php におけるクロスサイトスクリプティングの脆弱性 - CVE-2007-2913 2012-06-26 15:46 2007-05-30 Show GitHub Exploit DB Packet Storm
246609 7.5 危険 2z project - 2z project の includes/rating.php における SQL インジェクションの脆弱性 - CVE-2007-2905 2012-06-26 15:46 2007-05-30 Show GitHub Exploit DB Packet Storm
246610 7.5 危険 Dokeos - Dokeos の main/auth/my_progress.php における SQL インジェクションの脆弱性 - CVE-2007-2902 2012-06-26 15:46 2007-05-30 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 28, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
411 7.1 HIGH
Network
- - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in phbernard Favicon favicon-by-realfavicongenerator allows Reflected XSS.This issue affects Favicon… New CWE-79
Cross-site Scripting
CVE-2026-42754 2026-05-27 23:50 2026-05-27 Show GitHub Exploit DB Packet Storm
412 9.3 CRITICAL
Network
- - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 TableOn posts-table-filterable allows Blind SQL Injection.This issue affects TableOn: … New CWE-89
SQL Injection
CVE-2026-42755 2026-05-27 23:50 2026-05-27 Show GitHub Exploit DB Packet Storm
413 9.9 CRITICAL
Network
- - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ludwig You QuickWebP – Compress / Optimize Images & Convert WebP | SEO Friendly quickwebp all… New CWE-22
Path Traversal
CVE-2026-42756 2026-05-27 23:50 2026-05-27 Show GitHub Exploit DB Packet Storm
414 9.9 CRITICAL
Network
- - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows Path Traversal.This issue affects Webi… New CWE-22
Path Traversal
CVE-2026-42757 2026-05-27 23:50 2026-05-27 Show GitHub Exploit DB Packet Storm
415 9.8 CRITICAL
Network
- - Incorrect Privilege Assignment vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows Privilege Escalation.This issue affects WebinarIgnition: from n/a through < 4.08.253. New CWE-266
 Incorrect Privilege Assignment
CVE-2026-42758 2026-05-27 23:50 2026-05-27 Show GitHub Exploit DB Packet Storm
416 7.1 HIGH
Network
- - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Timo Affiliate Super Assistent amazonsimpleadmin allows Stored XSS.This issue affects Affiliate S… New CWE-79
Cross-site Scripting
CVE-2026-42759 2026-05-27 23:50 2026-05-27 Show GitHub Exploit DB Packet Storm
417 7.5 HIGH
Network
- - Authentication Bypass Using an Alternate Path or Channel vulnerability in revmakx Backup and Staging by WP Time Capsule wp-time-capsule allows Password Recovery Exploitation.This issue affects Backup… New CWE-288
Authentication Bypass Using an Alternate Path or Channel
CVE-2026-42760 2026-05-27 23:50 2026-05-27 Show GitHub Exploit DB Packet Storm
418 9.3 CRITICAL
Network
- - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 Active Products Tables for WooCommerce profit-products-tables-for-woocommerce allows B… New CWE-89
SQL Injection
CVE-2026-42761 2026-05-27 23:50 2026-05-27 Show GitHub Exploit DB Packet Storm
419 7.1 HIGH
Network
- - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS vikbooking allows DOM-Based XSS.This issue affects… New CWE-79
Cross-site Scripting
CVE-2026-42762 2026-05-27 23:50 2026-05-27 Show GitHub Exploit DB Packet Storm
420 4.3 MEDIUM
Network
- - Missing Authorization vulnerability in WebToffee Product Import Export for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Product Import Expo… New CWE-862
 Missing Authorization
CVE-2026-48971 2026-05-27 23:50 2026-05-27 Show GitHub Exploit DB Packet Storm