Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 6, 2026, 2 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
237451 7.5 危険 neosys - Neon WebMail の updateuser サーブレットにおける任意のユーザの情報を変更される脆弱性 - CVE-2006-4954 2012-09-25 15:35 2006-09-23 Show GitHub Exploit DB Packet Storm
237452 7.5 危険 neosys - Neon WebMail における SQL インジェクションの脆弱性 - CVE-2006-4953 2012-09-25 15:35 2006-09-23 Show GitHub Exploit DB Packet Storm
237453 7.5 危険 neosys - Neon WebMail の updatemail サーブレットにおける電子メールメッセージを移動される脆弱性 - CVE-2006-4952 2012-09-25 15:35 2006-09-23 Show GitHub Exploit DB Packet Storm
237454 7.5 危険 neosys - Neon WebMail における任意の JSP コードを実行される脆弱性 - CVE-2006-4951 2012-09-25 15:35 2006-09-23 Show GitHub Exploit DB Packet Storm
237455 5 警告 Moodle - Moodle の course/jumpto.php における重要な情報を取得される脆弱性 - CVE-2006-4943 2012-09-25 15:35 2006-09-12 Show GitHub Exploit DB Packet Storm
237456 4.6 警告 Moodle - Moodle における LaTeX 出力ファイルなどを dataroot ディレクトリの最上位レベルに書き込まれる脆弱性 - CVE-2006-4942 2012-09-25 15:35 2006-09-12 Show GitHub Exploit DB Packet Storm
237457 4.3 警告 Moodle - Moodle におけるクロスサイトスクリプティングの脆弱性 - CVE-2006-4941 2012-09-25 15:35 2006-09-12 Show GitHub Exploit DB Packet Storm
237458 5 警告 Moodle - Moodle の login/forgot_password.php における重要な情報を取得される脆弱性 - CVE-2006-4940 2012-09-25 15:35 2006-09-12 Show GitHub Exploit DB Packet Storm
237459 5 警告 Moodle - Moodle の backup/backup_scheduled.php におけるパス名を取得される脆弱性 - CVE-2006-4939 2012-09-25 15:35 2006-09-12 Show GitHub Exploit DB Packet Storm
237460 4 警告 Moodle - Moodle の help.php におけるエラーメッセージ内のパスを取得される脆弱性 - CVE-2006-4938 2012-09-25 15:35 2006-09-12 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 6, 2026, 4:08 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
411 8.8 HIGH
Network
- - Improper neutralization of CRLF sequences ('CRLF injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Update allows Authentication Bypass. This issue affects P… Update CWE-93
CRLF Injection
CVE-2026-5140 2026-05-4 23:16 2026-04-29 Show GitHub Exploit DB Packet Storm
412 - - - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accid… New - CVE-2026-4928 2026-05-4 23:16 2026-05-4 Show GitHub Exploit DB Packet Storm
413 7.7 HIGH
Network
- - In Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data. Update CWE-212
 Improper Removal of Sensitive Information Before Storage or Transfer
CVE-2026-43824 2026-05-4 23:16 2026-05-2 Show GitHub Exploit DB Packet Storm
414 5.3 MEDIUM
Network
- - Starlet versions through 0.31 for Perl allows HTTP Request Smuggling via Improper Header Precedence. Starlet incorrectly prioritizes "Content-Length" over "Transfer-Encoding: chunked" when both head… New CWE-444
HTTP Request Smuggling
CVE-2026-40561 2026-05-4 23:16 2026-05-3 Show GitHub Exploit DB Packet Storm
415 6.7 MEDIUM
Local
- - In slbc, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interacti… New CWE-843
Type Confusion
CVE-2026-20451 2026-05-4 23:16 2026-05-4 Show GitHub Exploit DB Packet Storm
416 6.5 MEDIUM
Adjacent
- - In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with… New CWE-617
 Reachable Assertion
CVE-2026-20450 2026-05-4 23:16 2026-05-4 Show GitHub Exploit DB Packet Storm
417 6.5 MEDIUM
Adjacent
- - In Modem, there is a possible system crash due to a heap buffer overflow. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with n… New CWE-120
Classic Buffer Overflow
CVE-2026-20449 2026-05-4 23:16 2026-05-4 Show GitHub Exploit DB Packet Storm
418 6.7 MEDIUM
Local
- - In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege if a malicious actor has already obtained the System priv… New CWE-280
Improper Handling of Insufficient Permissions or Privileges 
CVE-2026-20448 2026-05-4 23:16 2026-05-4 Show GitHub Exploit DB Packet Storm
419 6.7 MEDIUM
Local
- - In geniezone, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privileg… New CWE-125
Out-of-bounds Read
CVE-2026-20447 2026-05-4 23:16 2026-05-4 Show GitHub Exploit DB Packet Storm
420 6.5 MEDIUM
Adjacent
amazon freertos-plus-tcp Insufficient packet validation in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to bypass all checksum and minimum-size validation by spoofing the Ethernet source MAC ad… Update CWE-290
 Authentication Bypass by Spoofing
CVE-2026-7422 2026-05-4 22:43 2026-04-30 Show GitHub Exploit DB Packet Storm