Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 7, 2026, 2:09 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
3251 7.5 重要
Network
lfprojects MCP TypeScript SDK lfprojectsのMCP TypeScript SDKにおける非効率的な正規表現の複雑さに関する脆弱性 CWE-1333
非効率的な正規表現の複雑さ
CVE-2026-0621 2026-02-2 19:29 2026-01-5 Show GitHub Exploit DB Packet Storm
3252 7.5 重要
Network
TOTOLINK WA1200-PoE Firmware
WA1200-PoE
TOTOLINK等の複数ベンダの製品における複数の脆弱性 CWE-404
CWE-476
CWE-476
CVE-2026-0731 2026-02-2 19:29 2026-01-8 Show GitHub Exploit DB Packet Storm
3253 7.8 重要
Local
Google SentencePiece GoogleのSentencePieceにおけるバッファエラーの脆弱性 CWE-119
バッファエラー
CVE-2026-1260 2026-02-2 19:29 2026-01-22 Show GitHub Exploit DB Packet Storm
3254 7.2 重要
Network
D-Link Systems, Inc. DCS-700L Firmware D-Link CorporationのDCS-700L Firmwareにおける複数の脆弱性 CWE-74
CWE-77
CWE-77
CVE-2026-1419 2026-02-2 19:29 2026-01-26 Show GitHub Exploit DB Packet Storm
3255 6.5 警告
Adjacent
UI UniFi Connect EV Station Lite Firmware UIのUniFi Connect EV Station Lite Firmwareにおけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2026-21635 2026-02-2 19:29 2026-01-5 Show GitHub Exploit DB Packet Storm
3256 8.2 重要
Network
Shopify Remix
React Router
ShopifyのReact Router等の複数製品におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-21884 2026-02-2 19:29 2026-01-10 Show GitHub Exploit DB Packet Storm
3257 4.2 警告
Local
オラクル Oracle Enterprise Planning and Budgeting Cloud Service オラクルのOracle Enterprise Planning and Budgeting Cloud Serviceにおける不特定の脆弱性 CWE-noinfo
情報不足
CVE-2026-21922 2026-02-2 19:29 2026-01-20 Show GitHub Exploit DB Packet Storm
3258 6.5 警告
Network
オラクル Oracle Life Sciences Central Designer オラクルのOracle Life Sciences Central Designerにおける不特定の脆弱性 CWE-noinfo
情報不足
CVE-2026-21923 2026-02-2 19:29 2026-01-20 Show GitHub Exploit DB Packet Storm
3259 7.5 重要
Network
オラクル Siebel CRM Deployment オラクルのSiebel CRM Deploymentにおける不特定の脆弱性 CWE-noinfo
情報不足
CVE-2026-21926 2026-02-2 19:29 2026-01-20 Show GitHub Exploit DB Packet Storm
3260 5.3 警告
Network
オラクル MySQL Server オラクルのMySQL Serverにおける不特定の脆弱性 CWE-noinfo
情報不足
CVE-2026-21929 2026-02-2 19:29 2026-01-20 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 7, 2026, 4:22 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
348511 - powerdev encapsbb PHP remote file inclusion vulnerability in index_header.php for EncapsBB 0.3.2_fixed, and possibly other versions, allows remote attackers to execute arbitrary PHP code via the root parameter. NVD-CWE-Other
CVE-2005-0917 2008-09-6 05:47 2005-05-2 Show GitHub Exploit DB Packet Storm
348512 - - - Multiple SQL injection vulnerabilities in Bugtracker.NET 2.0.1 allow remote attackers to execute arbitrary SQL commands via unknown vectors. NVD-CWE-Other
CVE-2005-0920 2008-09-6 05:47 2005-05-2 Show GitHub Exploit DB Packet Storm
348513 - microsoft outlook_connector Microsoft Outlook 2002 Connector for IBM Lotus Domino 2.0 allows local users to save passwords and login credentials locally, even when password caching is disabled by a group policy. NVD-CWE-Other
CVE-2005-0921 2008-09-6 05:47 2005-05-2 Show GitHub Exploit DB Packet Storm
348514 - symantec norton_antivirus
norton_internet_security
norton_system_works
Unknown vulnerability in the Auto-Protect module in Symantec Norton AntiVirus 2004 and 2005, as also used in Internet Security 2004/2005 and System Works 2004/2005, allows attackers to cause a denial… NVD-CWE-Other
CVE-2005-0922 2008-09-6 05:47 2005-05-2 Show GitHub Exploit DB Packet Storm
348515 - symantec norton_antivirus
norton_internet_security
norton_system_works
The SmartScan feature in the Auto-Protect module for Symantec Norton AntiVirus 2004 and 2005, as also used in Internet Security 2004/2005 and System Works 2004/2005, allows attackers to cause a denia… NVD-CWE-Other
CVE-2005-0923 2008-09-6 05:47 2005-05-2 Show GitHub Exploit DB Packet Storm
348516 - web-app.org webapp Unknown vulnerability in subs.pl for WebAPP 0.9.9 through 0.9.9.2 has unknown impact and attack vectors, probably involving shell metacharacters or .. sequences. NVD-CWE-Other
CVE-2005-0927 2008-09-6 05:47 2005-05-2 Show GitHub Exploit DB Packet Storm
348517 - chatness chatness Cross-site scripting (XSS) vulnerability in message.php in Chatness 2.5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) the user field or (2) the message paramete… NVD-CWE-Other
CVE-2005-0930 2008-09-6 05:47 2005-05-2 Show GitHub Exploit DB Packet Storm
348518 - jimmy the_includer PHP remote file inclusion vulnerability in The Includer 1.0 and 1.1 allows remote attackers to execute arbitrary PHP code. NVD-CWE-Other
CVE-2005-0931 2008-09-6 05:47 2005-03-29 Show GitHub Exploit DB Packet Storm
348519 - wackowiki wackowiki Multiple cross-site scripting (XSS) vulnerabilities in WackoWiki R4 allow remote attackers to inject arbitrary web script or HTML via unknown vectors. NVD-CWE-Other
CVE-2005-0934 2008-09-6 05:47 2005-05-2 Show GitHub Exploit DB Packet Storm
348520 - yepyep mtftpd Buffer overflow in the mt_do_dir function in YepYep mtftpd 0.0.3 may allow attackers to execute arbitrary code via a long path. NVD-CWE-Other
CVE-2005-0959 2008-09-6 05:47 2005-05-2 Show GitHub Exploit DB Packet Storm