Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 13, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
3261 5.4 警告
Network
lfprojects mlflow lfprojectsのmlflowにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-33865 2026-04-21 10:43 2026-04-7 Show GitHub Exploit DB Packet Storm
3262 4.3 警告
Network
lfprojects mlflow lfprojectsのmlflowにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2026-33866 2026-04-21 10:43 2026-04-7 Show GitHub Exploit DB Packet Storm
3263 9.1 緊急
Network
Mervin Praison (MervinPraison) PraisonAI Mervin Praison (MervinPraison)のPraisonAIにおける信頼できない制御領域からの機能の組み込みに関する脆弱性 CWE-829
信頼性のない制御領域からの機能の組み込み
CVE-2026-40313 2026-04-21 10:43 2026-04-14 Show GitHub Exploit DB Packet Storm
3264 6.5 警告
Network
PAC4J pac4j PAC4Jのpac4jにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2026-40458 2026-04-21 10:43 2026-04-17 Show GitHub Exploit DB Packet Storm
3265 8.8 重要
Network
PAC4J pac4j PAC4Jのpac4jにおけるLDAP インジェクションの脆弱性 CWE-90
LDAP インジェクション
CVE-2026-40459 2026-04-21 10:43 2026-04-17 Show GitHub Exploit DB Packet Storm
3266 7.8 重要
Local
Rubicon Communications, LLC (Netgate). NETGATE Registry Cleaner Rubicon Communications, LLC (Netgate).のNETGATE Registry Cleanerにおける引用されない検索パスまたは要素に関する脆弱性 CWE-428
引用されない検索パスまたは要素
CVE-2016-20057 2026-04-21 10:43 2026-04-4 Show GitHub Exploit DB Packet Storm
3267 6.1 警告
Network
Thank You/Like System project Thank You/Like System MyBB GroupのThank You/Like Systemにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2018-25247 2026-04-21 10:43 2026-04-4 Show GitHub Exploit DB Packet Storm
3268 6.1 警告
Network
MyBB Group MyBB Last User's Threads MyBB GroupのMyBB Last User's Threadsにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2018-25250 2026-04-21 10:43 2026-04-4 Show GitHub Exploit DB Packet Storm
3269 5.5 警告
Local
AnyBurn AnyBurn AnyBurnにおける再利用前に削除されていないリソース内重要情報に関する脆弱性 CWE-226
再利用前に削除されていないリソース内重要情報
CVE-2019-25657 2026-04-21 10:43 2026-04-5 Show GitHub Exploit DB Packet Storm
3270 5.5 警告
Local
Hainsoft.com LanHelper Hainsoft.comのLanHelperにおける境界外書き込みに関する脆弱性 CWE-787
境界外書き込み
CVE-2019-25660 2026-04-21 10:43 2026-04-5 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 13, 2026, 5:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
350851 - software602 602pro_lan_suite The Czech edition of Software602's Web Server before 2002.0.02.0916 allows remote attackers to gain administrator privileges via direct HTTP requests to the /admin/ directory, which is not password p… NVD-CWE-Other
CVE-2002-2152 2008-09-6 05:32 2002-12-31 Show GitHub Exploit DB Packet Storm
350852 - cerulean_studios trillian Format string vulnerability in the error handling of IRC invite responses for Trillian 0.725 and 0.73 allows remote IRC servers to execute arbitrary code via an invite to a channel with format string… NVD-CWE-Other
CVE-2002-2155 2008-09-6 05:32 2002-12-31 Show GitHub Exploit DB Packet Storm
350853 - cerulean_studios trillian Buffer overflow in Trillian 0.73 allows remote IRC servers to execute arbitrary code via a long PING response. NVD-CWE-Other
CVE-2002-2156 2008-09-6 05:32 2002-12-31 Show GitHub Exploit DB Packet Storm
350854 - zendocs zentrack zenTrack 2.0.3 and earlier allows remote attackers to obtain the full path to the web root via an invalid ticket ID, which leaks the path in an error message. NVD-CWE-Other
CVE-2002-2158 2008-09-6 05:32 2002-12-31 Show GitHub Exploit DB Packet Storm
350855 - kerio personal_firewall Kerio Personal Firewall (KPF) 2.1.4 and earlier allows remote attackers to cause a denial of service (hang and CPU consumption) via a SYN packet flood. NVD-CWE-Other
CVE-2002-2161 2008-09-6 05:32 2002-12-31 Show GitHub Exploit DB Packet Storm
350856 - cerulean_studios trillian Cerulean Studios Trillian 0.73 and earlier use weak encrypttion (XOR) for storing user passwords in .ini files in the Trillian directory, which allows local users to gain access to other user account… NVD-CWE-Other
CVE-2002-2162 2008-09-6 05:32 2002-12-31 Show GitHub Exploit DB Packet Storm
350857 - killervault kvpoll KvPoll 1.1 allows remote authenticated users to vote more than once by setting the "already_voted" cookie by various methods, including a direct call to clear_cookies.php. NVD-CWE-Other
CVE-2002-2163 2008-09-6 05:32 2002-12-31 Show GitHub Exploit DB Packet Storm
350858 - microsoft outlook_express Buffer overflow in Microsoft Outlook Express 5.0, 5.5, and 6.0 allows remote attackers to cause a denial of service (crash) via a long <A HREF> link. NVD-CWE-Other
CVE-2002-2164 2008-09-6 05:32 2002-12-31 Show GitHub Exploit DB Packet Storm
350859 - imho imho_webmail The IMHO Webmail module 0.97.3 and earlier for Roxen leaks the REFERER from the browser's previous login session in an error page, which allows local users to read another user's inbox. NVD-CWE-Other
CVE-2002-2165 2008-09-6 05:32 2002-12-31 Show GitHub Exploit DB Packet Storm
350860 - e-zone_media_inc. fusetalk Cross-site scripting (XSS) vulnerability in FuseTalk 2.0 and 3.0 allows remote attackers to insert arbitrary HTML and web script. NVD-CWE-Other
CVE-2002-2166 2008-09-6 05:32 2002-12-31 Show GitHub Exploit DB Packet Storm