Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 15, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
2681 - - (複数のベンダ) (複数の製品) CISA ICS Advisory / ICS Medical Advisory(2026年05月19日) - - 2026-05-21 16:17 2026-05-20 Show GitHub Exploit DB Packet Storm
2682 6.1 警告
Network
Northern.tech cfengine Northern.techのcfengineにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-24710 2026-05-21 10:55 2026-05-14 Show GitHub Exploit DB Packet Storm
2683 5.3 警告
Network
Northern.tech cfengine Northern.techのcfengineにおけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2026-24711 2026-05-21 10:55 2026-05-14 Show GitHub Exploit DB Packet Storm
2684 7.3 重要
Network
Northern.tech cfengine Northern.techのcfengineにおけるコマンドインジェクションの脆弱性 CWE-77
コマンドインジェクション
CVE-2026-24712 2026-05-21 10:55 2026-05-14 Show GitHub Exploit DB Packet Storm
2685 9.8 緊急
Network
Open JS Foundation WebdriverIO Open JS FoundationのWebdriverIOにおけるOS コマンドインジェクションの脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2026-25244 2026-05-21 10:55 2026-05-18 Show GitHub Exploit DB Packet Storm
2686 6.5 警告
Network
マイクロソフト Power Automate for Desktop Microsoft Power Automate デスクトップの情報漏えいの脆弱性 CWE-200
情報漏えい
CVE-2026-40374 2026-05-21 10:55 2026-05-12 Show GitHub Exploit DB Packet Storm
2687 7.8 重要
Local
protobufjs project protobufjs-cli protobufjs projectのprotobufjs-cliにおけるOS コマンドインジェクションの脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2026-42290 2026-05-21 10:55 2026-05-13 Show GitHub Exploit DB Packet Storm
2688 6.1 警告
Network
beaugunderson ip-address beaugundersonのip-addressにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-42338 2026-05-21 10:55 2026-05-12 Show GitHub Exploit DB Packet Storm
2689 7.6 重要
Network
PocketBase PocketBase PocketBaseにおける認証に関する脆弱性 CWE-287
不適切な認証
CVE-2026-44166 2026-05-21 10:55 2026-05-12 Show GitHub Exploit DB Packet Storm
2690 7.2 重要
Network
German Cancer Research Center (DKFZ) nnU-Net German Cancer Research Center (DKFZ)のnnU-Netにおけるインジェクションに関する脆弱性 CWE-74
インジェクション
CVE-2026-44246 2026-05-21 10:55 2026-05-12 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 16, 2026, 4:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
344721 - davide_libenzi xmail Buffer overflow in XMail POP3 server before version 0.59 allows remote attackers to execute arbitrary commands via a long USER command. NVD-CWE-Other
CVE-2000-0840 2017-12-19 11:29 2000-11-14 Show GitHub Exploit DB Packet Storm
344722 - davide_libenzi xmail Buffer overflow in XMail POP3 server before version 0.59 allows remote attackers to execute arbitrary commands via a long APOP command. NVD-CWE-Other
CVE-2000-0841 2017-12-19 11:29 2000-11-14 Show GitHub Exploit DB Packet Storm
344723 - sebastian_kienzl muh The logging capability in muh 2.05d IRC server does not properly cleanse user-injected format strings, which allows remote attackers to cause a denial of service or execute arbitrary commands via a m… NVD-CWE-Other
CVE-2000-0857 2017-12-19 11:29 2000-11-14 Show GitHub Exploit DB Packet Storm
344724 - borland_software interbase_superserver Interbase 6 SuperServer for Linux allows an attacker to cause a denial of service via a query containing 0 bytes. NVD-CWE-Other
CVE-2000-0866 2017-12-19 11:29 2000-11-14 Show GitHub Exploit DB Packet Storm
344725 - nathan_purciful phpphotoalbum explorer.php in PhotoAlbum 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) attack. NVD-CWE-Other
CVE-2000-0872 2017-12-19 11:29 2000-11-14 Show GitHub Exploit DB Packet Storm
344726 - plus_technologies lpplus LPPlus programs dccsched, dcclpdser, dccbkst, dccshut, dcclpdshut, and dccbkstshut are installed setuid root and world executable, which allows arbitrary local users to start and stop various LPD ser… NVD-CWE-Other
CVE-2000-0879 2017-12-19 11:29 2000-11-14 Show GitHub Exploit DB Packet Storm
344727 - plus_technologies lpplus LPPlus creates the lpdprocess file with world-writeable permissions, which allows local users to kill arbitrary processes by specifying an alternate process ID and using the setuid dcclpdshut program… NVD-CWE-Other
CVE-2000-0880 2017-12-19 11:29 2000-11-14 Show GitHub Exploit DB Packet Storm
344728 - plus_technologies lpplus The dccscan setuid program in LPPlus does not properly check if the user has the permissions to print the file that is specified to dccscan, which allows local users to print arbitrary files. NVD-CWE-Other
CVE-2000-0881 2017-12-19 11:29 2000-11-14 Show GitHub Exploit DB Packet Storm
344729 - nathan_purciful phpphotoalbum getalbum.php in PhotoAlbum before 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) attack. NVD-CWE-Other
CVE-2000-0902 2017-12-19 11:29 2000-12-19 Show GitHub Exploit DB Packet Storm
344730 - moreover.com cached_feed.cgi_script Directory traversal vulnerability in Moreover.com cached_feed.cgi script version 4.July.00 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the category or format paramete… NVD-CWE-Other
CVE-2000-0906 2017-12-19 11:29 2000-12-19 Show GitHub Exploit DB Packet Storm