Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Feb. 9, 2026, 12:59 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
721 5.4 警告
Network
Qode Interactive Backpack Traveler Qode InteractiveのWordPress用Backpack Travelerにおけるユーザ制御の鍵による認証回避に関する脆弱性 CWE-639
ユーザ制御の鍵による認証回避
CVE-2025-69030 2026-02-2 19:30 2025-12-30 Show GitHub Exploit DB Packet Storm
722 5.4 警告
Network
Lullabot Fivestar Qode InteractiveのWordPress用FiveStarにおけるユーザ制御の鍵による認証回避に関する脆弱性 CWE-639
ユーザ制御の鍵による認証回避
CVE-2025-69032 2026-02-2 19:30 2025-12-30 Show GitHub Exploit DB Packet Storm
723 8.1 重要
Network
Qode Interactive Lekker Qode InteractiveのWordPress用LekkerにおけるPHP リモートファイルインクルージョンの脆弱性 CWE-98
PHP リモートファイルインクルージョン
CVE-2025-69034 2026-02-2 19:30 2025-12-30 Show GitHub Exploit DB Packet Storm
724 5.4 警告
Network
remyandrade Domain Availability Checker Using PHP and JavaScript with Source Code Remy AndradeのDomain Availability Checker Using PHP and JavaScript with Source Codeにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2025-70458 2026-02-2 19:30 2026-01-23 Show GitHub Exploit DB Packet Storm
725 6.1 警告
Network
fahadmahmood External Store for Shopify fahadmahmoodのWordPress用External Store for Shopifyにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2025-7808 2026-02-2 19:29 2025-08-14 Show GitHub Exploit DB Packet Storm
726 9.8 緊急
Network
Cockroach Labs cockroach-k8s-request-cert Cockroach Labsのcockroach-k8s-request-certにおける設定ファイル内の空のパスワードに関する脆弱性 CWE-258
設定ファイル内に空のパスワード
CVE-2025-9276 2026-02-2 19:29 2025-09-2 Show GitHub Exploit DB Packet Storm
727 7.5 重要
Network
lfprojects MCP TypeScript SDK lfprojectsのMCP TypeScript SDKにおける非効率的な正規表現の複雑さに関する脆弱性 CWE-1333
非効率的な正規表現の複雑さ
CVE-2026-0621 2026-02-2 19:29 2026-01-5 Show GitHub Exploit DB Packet Storm
728 7.5 重要
Network
TOTOLINK WA1200-PoE Firmware
WA1200-PoE
TOTOLINK等の複数ベンダの製品における複数の脆弱性 CWE-404
CWE-476
CWE-476
CVE-2026-0731 2026-02-2 19:29 2026-01-8 Show GitHub Exploit DB Packet Storm
729 7.8 重要
Local
Google SentencePiece GoogleのSentencePieceにおけるバッファエラーの脆弱性 CWE-119
バッファエラー
CVE-2026-1260 2026-02-2 19:29 2026-01-22 Show GitHub Exploit DB Packet Storm
730 7.2 重要
Network
D-Link Systems, Inc. DCS-700L Firmware D-Link CorporationのDCS-700L Firmwareにおける複数の脆弱性 CWE-74
CWE-77
CWE-77
CVE-2026-1419 2026-02-2 19:29 2026-01-26 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:April 25, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
281 - - - Vite+ is a unified toolchain and entry point for web development. Prior to version 0.1.17, `downloadPackageManager()` accepts an untrusted `version` string and uses it directly in filesystem paths. A… New CWE-22
Path Traversal
CVE-2026-41211 2026-04-24 23:50 2026-04-23 Show GitHub Exploit DB Packet Storm
282 - - - OpenLearn is open-source educational forum software. Prior to commit 844b2a40a69d0c4911580fe501923f0b391313ab, when `safeMode` is enabled, unapproved forum posts are hidden from the public list, but … New CWE-284
Improper Access Control
CVE-2026-41243 2026-04-24 23:50 2026-04-23 Show GitHub Exploit DB Packet Storm
283 - - - Noir is a Domain Specific Language for SNARK proving systems that is designed to use any ACIR compatible proving system, and Brillig is the bytecode ACIR uses for non-determinism. Noir programs can i… New CWE-131
Incorrect Calculation of Buffer Size
CVE-2026-41197 2026-04-24 23:50 2026-04-23 Show GitHub Exploit DB Packet Storm
284 - - - STIG Manager is an API and web client for managing Security Technical Implementation Guides (STIG) assessments of Information Systems. Versions 1.5.10 through 1.6.7 have a reflected Cross-Site Scrip… New CWE-79
Cross-site Scripting
CVE-2026-41200 2026-04-24 23:50 2026-04-23 Show GitHub Exploit DB Packet Storm
285 8.8 HIGH
Network
- - Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Versions of @paperclipai/server prior to 2026.416.0 contain a privilege escalation vulnerability th… New CWE-78
OS Command 
CVE-2026-41208 2026-04-24 23:50 2026-04-23 Show GitHub Exploit DB Packet Storm
286 10.0 CRITICAL
Network
- - Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Prior to version 2026.416.0, an unauthenticated attacker can achieve full remote code execution on … New CWE-287
CWE-862
CWE-1188
Improper Authentication
 Missing Authorization
 Insecure Default Initialization of Resource
CVE-2026-41679 2026-04-24 23:50 2026-04-23 Show GitHub Exploit DB Packet Storm
287 5.4 MEDIUM
Network
- - Successful exploitation of the stored cross-site scripting (XSS) vulnerability could allow an attacker to execute arbitrary JavaScript on any user account that has access to Koollab LMS’ courselet fe… New - CVE-2026-3007 2026-04-24 23:50 2026-04-23 Show GitHub Exploit DB Packet Storm
288 9.9 CRITICAL
Network
- - Froxlor is open source server administration software. Prior to version 2.3.6, the Froxlor API endpoint `Customers.update` (and `Admins.update`) does not validate the `def_language` parameter against… New CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2026-41228 2026-04-24 23:50 2026-04-23 Show GitHub Exploit DB Packet Storm
289 9.1 CRITICAL
Network
- - Froxlor is open source server administration software. Prior to version 2.3.6, `PhpHelper::parseArrayToString()` writes string values into single-quoted PHP string literals without escaping single qu… New CWE-94
Code Injection
CVE-2026-41229 2026-04-24 23:50 2026-04-23 Show GitHub Exploit DB Packet Storm
290 8.5 HIGH
Network
- - Froxlor is open source server administration software. Prior to version 2.3.6, `DomainZones::add()` accepts arbitrary DNS record types without a whitelist and does not sanitize newline characters in … New CWE-93
CRLF Injection
CVE-2026-41230 2026-04-24 23:50 2026-04-23 Show GitHub Exploit DB Packet Storm