Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 4, 2026, 4 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
4101 7.5 重要
Network
lxml lxml lxmlにおけるXML 外部エンティティの脆弱性 CWE-611
XML 外部エンティティ参照の不適切な制限
CVE-2026-41066 2026-04-30 12:27 2026-04-24 Show GitHub Exploit DB Packet Storm
4102 7.7 重要
Network
The Kyverno Authors Kyverno The Kyverno AuthorsのKyvernoにおける不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2026-41068 2026-04-30 12:27 2026-04-24 Show GitHub Exploit DB Packet Storm
4103 8.8 重要
Network
pyLoad pyLoad pyLoadにおけるセッション期限に関する脆弱性 CWE-613
不適切なセッション期限
CVE-2026-41133 2026-04-30 12:27 2026-04-22 Show GitHub Exploit DB Packet Storm
4104 8.2 重要
Network
Minio Inc. Minio Minio Inc.のMinioにおける認証に関する脆弱性 CWE-287
不適切な認証
CVE-2026-41145 2026-04-30 12:27 2026-04-22 Show GitHub Exploit DB Packet Storm
4105 9.8 緊急
Network
JetBrains Junie JetBrainsのJunieにおけるコマンドインジェクションの脆弱性 CWE-77
コマンドインジェクション
CVE-2026-41153 2026-04-30 12:27 2026-04-17 Show GitHub Exploit DB Packet Storm
4106 8.1 重要
Network
Statamic Statamic Statamicにおけるクラスまたはコードを選択する外部から制御された入力の使用に関する脆弱性 CWE-470
クラスまたはコードを選択する外部から制御された入力の使用
CVE-2026-41175 2026-04-30 12:27 2026-04-22 Show GitHub Exploit DB Packet Storm
4107 9.8 緊急
Network
Rclone Rclone Rcloneにおける重要な機能に対する認証の欠如に関する脆弱性 CWE-306
重要な機能に対する認証の欠如 解説
CVE-2026-41176 2026-04-30 12:27 2026-04-23 Show GitHub Exploit DB Packet Storm
4108 9.8 緊急
Network
Rclone Rclone Rcloneにおける複数の脆弱性 CWE-306
CWE-78
CVE-2026-41179 2026-04-30 12:27 2026-04-23 Show GitHub Exploit DB Packet Storm
4109 9.9 緊急
Network
Froxlor Froxlor FroxlorにおけるPHP リモートファイルインクルージョンの脆弱性 CWE-98
PHP リモートファイルインクルージョン
CVE-2026-41228 2026-04-30 12:27 2026-04-23 Show GitHub Exploit DB Packet Storm
4110 9.1 緊急
Network
Froxlor Froxlor Froxlorにおけるコードインジェクションの脆弱性 CWE-94
コード・インジェクション
CVE-2026-41229 2026-04-30 12:27 2026-04-23 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 4, 2026, 4:17 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
314811 5.0 MEDIUM
Network
- - The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on multiple user privilege/security functions provided in vers… CWE-284
Improper Access Control
CVE-2020-36831 2024-10-16 16:15 2024-10-16 Show GitHub Exploit DB Packet Storm
314812 9.8 CRITICAL
Network
- - The SiteGround Optimizer plugin for WordPress is vulnerable to authorization bypass leading to Remote Code Execution and Local File Inclusion in versions up to, and including, 5.0.12 due to incorrect… CWE-862
 Missing Authorization
CVE-2019-25217 2024-10-16 16:15 2024-10-16 Show GitHub Exploit DB Packet Storm
314813 7.2 HIGH
Network
- - The Rich Review plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the POST body 'update' parameter in versions up to, and including, 1.7.4 due to insufficient input sanitization a… CWE-79
Cross-site Scripting
CVE-2019-25216 2024-10-16 16:15 2024-10-16 Show GitHub Exploit DB Packet Storm
314814 7.3 HIGH
Network
- - The ARI-Adminer plugin for WordPress is vulnerable to authorization bypass due to a lack of file access controls in nearly every file of the plugin in versions up to, and including, 1.1.14. This make… CWE-862
 Missing Authorization
CVE-2019-25215 2024-10-16 16:15 2024-10-16 Show GitHub Exploit DB Packet Storm
314815 7.2 HIGH
Network
- - The ShopWP plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST API routes in versions up to, and including, 2.0.4. This makes it possible for … CWE-862
 Missing Authorization
CVE-2019-25214 2024-10-16 16:15 2024-10-16 Show GitHub Exploit DB Packet Storm
314816 8.3 HIGH
Network
- - The Formidable Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters submitted during form entries like 'after_html' in versions before 2.05.03 due to… CWE-79
Cross-site Scripting
CVE-2017-20192 2024-10-16 16:15 2024-10-16 Show GitHub Exploit DB Packet Storm
314817 7.2 HIGH
Network
- - The MainWP Dashboard – The Private WordPress Manager for Multiple Website Maintenance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mwp_setup_purchase_username’ parameter… - CVE-2016-15041 2024-10-16 16:15 2024-10-16 Show GitHub Exploit DB Packet Storm
314818 - - - The Kento Post View Counter plugin for WordPress is vulnerable to SQL Injection via the 'kento_pvc_geo' parameter in versions up to, and including, 2.8 due to insufficient escaping on the user suppli… CWE-89
SQL Injection
CVE-2016-15040 2024-10-16 16:15 2024-10-16 Show GitHub Exploit DB Packet Storm
314819 8.3 HIGH
Network
- - The Mapplic and Mapplic Lite plugins for WordPress are vulnerable to Server-Side Request Forgery in versions up to, and including 6.1, 1.0 respectively. This makes it possible for attackers to forger… CWE-918
Server-Side Request Forgery (SSRF) 
CVE-2012-10018 2024-10-16 16:15 2024-10-16 Show GitHub Exploit DB Packet Storm
314820 - - - The Community by PeepSo – Social Network, Membership, Registration, User Profiles, Premium – Mobile App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via URLs in posts, comments, … CWE-79
Cross-site Scripting
CVE-2024-9873 2024-10-16 15:15 2024-10-16 Show GitHub Exploit DB Packet Storm