Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":April 30, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
250841 4.3 警告 Apache Software Foundation - Apache Struts におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2008-2025 2011-06-9 10:20 2009-04-9 Show GitHub Exploit DB Packet Storm
250842 4.3 警告 Stichting NLnet Labs - Unbound DNS リゾルバにサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2011-1922 2011-06-8 11:55 2011-05-26 Show GitHub Exploit DB Packet Storm
250843 7.8 危険 ERLANG - Erlang/OTP SSH ライブラリで生成される乱数が推測可能な問題 CWE-310
暗号の問題
CVE-2011-0766 2011-06-8 11:54 2011-05-26 Show GitHub Exploit DB Packet Storm
250844 10 危険 Google - Google Chrome におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2010-3415 2011-06-8 11:52 2010-09-14 Show GitHub Exploit DB Packet Storm
250845 10 危険 Google - Mac OS X 上で稼働する Google Chrome におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2010-3414 2011-06-8 11:52 2010-09-14 Show GitHub Exploit DB Packet Storm
250846 5 警告 Google - Google Chrome のポップアップブロック機能におけるサービス運用妨害 (DoS) の脆弱性 CWE-noinfo
情報不足
CVE-2010-3413 2011-06-8 11:51 2010-09-14 Show GitHub Exploit DB Packet Storm
250847 9.3 危険 Google - Google Chrome のコンソール実装における競合状態の脆弱性 CWE-362
競合状態
CVE-2010-3412 2011-06-8 11:51 2010-09-14 Show GitHub Exploit DB Packet Storm
250848 5 警告 Google - Linux 上で稼働する Google Chrome におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2010-3411 2011-06-8 11:50 2010-09-14 Show GitHub Exploit DB Packet Storm
250849 9.3 危険 Google
レッドハット
- Google Chrome におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2010-4206 2011-06-8 11:50 2010-11-4 Show GitHub Exploit DB Packet Storm
250850 9.3 危険 Google - Google Chrome におけるサービス運用妨害 (DoS) の脆弱性 CWE-20
不適切な入力確認
CVE-2010-4205 2011-06-8 11:49 2010-11-4 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 30, 2026, 4:58 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
661 6.4 MEDIUM
Network
- - The Woostify plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.5.0 This is due to insufficient input sanitization and output escaping in the bundle… New CWE-79
Cross-site Scripting
CVE-2026-4805 2026-04-28 17:16 2026-04-28 Show GitHub Exploit DB Packet Storm
662 6.5 MEDIUM
Local
- - In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that they can be passed to a shell command. This parsing does not adequately handle metacharacters, leading … New CWE-150
 Improper Neutralization of Escape, Meta, or Control Sequences
CVE-2026-41526 2026-04-28 17:16 2026-04-28 Show GitHub Exploit DB Packet Storm
663 6.5 MEDIUM
Local
- - KDE Dolphin before 25.12.3 allows applications in a Flatpak (or with AppArmor confinement) to open folders outside of the application sandbox without additional scrutiny. Dolphin's implementation of … New CWE-669
 Incorrect Resource Transfer Between Spheres
CVE-2026-41525 2026-04-28 17:16 2026-04-28 Show GitHub Exploit DB Packet Storm
664 - - - Penetration Testing engineers at Amazon have identified a security flaw related to request handling in the web server component that could, under certain conditions, lead to unintended access to prot… New CWE-306
Missing Authentication for Critical Function
CVE-2024-54013 2026-04-28 17:16 2026-04-28 Show GitHub Exploit DB Packet Storm
665 - - - Penetration Testing engineers at Amazon discovered a vulnerability where the camera system failed to properly validate input, allowing specially crafted requests containing malicious commands to be e… New CWE-78
OS Command 
CVE-2024-54012 2026-04-28 17:16 2026-04-28 Show GitHub Exploit DB Packet Storm
666 - - - Penetration Testing engineers at Amazon have discovered a flaw where the camera system fails to properly handle data supplied in certain requests, causing a service disruption. The manufacturer has r… New CWE-20
 Improper Input Validation 
CVE-2024-54011 2026-04-28 17:15 2026-04-28 Show GitHub Exploit DB Packet Storm
667 6.6 MEDIUM
Network
- - OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface. New CWE-829
 Inclusion of Functionality from Untrusted Control Sphere
CVE-2026-42510 2026-04-28 16:16 2026-04-28 Show GitHub Exploit DB Packet Storm
668 8.6 HIGH
Network
- - In Spring AI, various FilterExpressionConverter implementations accept a filter expression object and translate them to specific vector store query languages. In several cases, keys and values are no… New CWE-94
Code Injection
CVE-2026-40967 2026-04-28 16:16 2026-04-28 Show GitHub Exploit DB Packet Storm
669 5.9 MEDIUM
Network
- - In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registe… New CWE-191
 Integer Underflow (Wrap or Wraparound)
CVE-2026-40356 2026-04-28 16:16 2026-04-28 Show GitHub Exploit DB Packet Storm
670 6.4 MEDIUM
Network
- - The Social Post Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Threads embed handler in all versions up to, and including, 2.0.1. This is due to insufficient input sa… New CWE-79
Cross-site Scripting
CVE-2026-6809 2026-04-28 15:16 2026-04-28 Show GitHub Exploit DB Packet Storm