Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 25, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
4021 5.5 警告
Local
マイクロソフト Microsoft Windows Server 2019
Microsoft Windows 11 23h2
Microsoft Windows 11 26h1
Microsoft Windows 10 1809
Microsoft Wind…
Windows COM サーバーの情報漏えいの脆弱性 CWE-843
型の取り違え
CVE-2026-20806 2026-04-27 11:28 2026-04-14 Show GitHub Exploit DB Packet Storm
4022 4.6 警告
Physics
マイクロソフト Microsoft Windows Server 2019
Microsoft Windows 10 1607
Microsoft Windows Server 2016
Microsoft Windows 11 23h2
Microsoft …
Windows 回復環境のセキュリティ機能バイパスの脆弱性 CWE-212
保存または転送前の重要な情報の不適切な削除
CVE-2026-20928 2026-04-27 11:28 2026-04-14 Show GitHub Exploit DB Packet Storm
4023 7.8 重要
Local
マイクロソフト Microsoft Windows Server 2019
Microsoft Windows 11 23h2
Microsoft Windows 10 1809
Microsoft Windows 10 22h2
Microsoft Wind…
Windows Management サービスの特権昇格の脆弱性 CWE-362
競合状態
CVE-2026-20930 2026-04-27 11:28 2026-04-14 Show GitHub Exploit DB Packet Storm
4024 6 警告
Local
オラクル JDK
JRE
Oracle GraalVM
オラクルのOracle GraalVM等の複数製品におけるリソースの枯渇に関する脆弱性 CWE-400
リソースの枯渇
CVE-2026-22003 2026-04-27 11:28 2026-04-21 Show GitHub Exploit DB Packet Storm
4025 3.7
Network
Pivotal Software, Inc. Spring Security VMwareのSpring Securityにおけるタイミングの違いに起因する情報漏えいに関する脆弱性 CWE-208
タイミングの違いに起因する情報漏えい
CVE-2026-22746 2026-04-27 11:28 2026-04-22 Show GitHub Exploit DB Packet Storm
4026 8.1 重要
Network
Pivotal Software, Inc. Spring Security VMwareのSpring Securityにおけるホストの不一致による証明書の検証に関する脆弱性 CWE-297
ホストの不一致による証明書の不適切な検証
CVE-2026-22747 2026-04-27 11:28 2026-04-22 Show GitHub Exploit DB Packet Storm
4027 6.5 警告
Network
Pivotal Software, Inc. Spring Security VMwareのSpring Securityにおける入力確認に関する脆弱性 CWE-20
不適切な入力確認
CVE-2026-22748 2026-04-27 11:28 2026-04-22 Show GitHub Exploit DB Packet Storm
4028 7.5 重要
Network
Pivotal Software, Inc. Spring Security VMwareのSpring Securityにおける保護メカニズムの不具合に関する脆弱性 CWE-693
保護メカニズムの不具合
CVE-2026-22753 2026-04-27 11:28 2026-04-22 Show GitHub Exploit DB Packet Storm
4029 7.5 重要
Network
Pivotal Software, Inc. Spring Security VMwareのSpring Securityにおけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2026-22754 2026-04-27 11:28 2026-04-22 Show GitHub Exploit DB Packet Storm
4030 7.8 重要
Local
Linux Linux Kernel LinuxのLinux Kernelにおける解放済みメモリの使用に関する脆弱性 CWE-416
解放済みメモリの使用
CVE-2026-23344 2026-04-27 11:28 2026-03-25 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 26, 2026, 4:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
347121 - phpwebthings phpwebthings Cross-site scripting (XSS) vulnerability in forum.php in PhpWebThings 1.4.4 allows remote attackers to inject arbitrary web script or HTML via the forum parameter. NVD-CWE-Other
CVE-2005-3584 2016-10-18 12:36 2005-11-16 Show GitHub Exploit DB Packet Storm
347122 - cutephp cutenews index.php CuteNews 1.4.0 and earlier allows remote attackers to obtain the path of the installation path of the application by triggering an error message, such as by entering multiple ../ (dot dot s… NVD-CWE-Other
CVE-2005-3592 2016-10-18 12:36 2005-11-16 Show GitHub Exploit DB Packet Storm
347123 - e107 e107 game_score.php in e107 allows remote attackers to insert high scores via HTTP POST methods utilizing the $player_name, $player_score, and $game_name variables. NVD-CWE-Other
CVE-2005-3594 2016-10-18 12:36 2005-11-16 Show GitHub Exploit DB Packet Storm
347124 - phpmyadmin phpmyadmin phpMyAdmin 2.7.0-beta1 and earlier allows remote attackers to obtain the full path of the server via direct requests to multiple scripts in the libraries directory. NVD-CWE-Other
CVE-2005-3622 2016-10-18 12:36 2005-11-16 Show GitHub Exploit DB Packet Storm
347125 - moodle moodle jumpto.php in Moodle 1.5.2 allows remote attackers to redirect users to other sites via the jump parameter. NVD-CWE-Other
CVE-2005-3649 2016-10-18 12:36 2005-11-17 Show GitHub Exploit DB Packet Storm
347126 - realnetworks realplayer Buffer overflow in RealNetworks RealPlayer 10 and 10.5 allows remote attackers to execute arbitrary code via a crafted image in a RealPlayer Skin (RJS) file. NOTE: due to the lack of details, it is … NVD-CWE-Other
CVE-2005-3677 2016-10-18 12:36 2005-11-19 Show GitHub Exploit DB Packet Storm
347127 - activecampaign 1-2-all_broadcast_email SQL injection vulnerability in admin/index.php in ActiveCampaign 1-2-All Broadcast Email allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username field in … NVD-CWE-Other
CVE-2005-3679 2016-10-18 12:36 2005-11-19 Show GitHub Exploit DB Packet Storm
347128 - xoops xoops Directory traversal vulnerability in editor_registry.php in XOOPS 2.2.3 allows remote attackers to read or include arbitrary local files via a .. (dot dot) in the xoopsConfig[language] parameter. NVD-CWE-Other
CVE-2005-3680 2016-10-18 12:36 2005-11-19 Show GitHub Exploit DB Packet Storm
347129 - xoops wf-downloads SQL injection vulnerability in viewcat.php in XOOPS WF-Downloads module 2.05 allows remote attackers to execute arbitrary SQL commands via the list parameter. NVD-CWE-Other
CVE-2005-3681 2016-10-18 12:36 2005-11-19 Show GitHub Exploit DB Packet Storm
347130 - hitachi ip5000_voip_wifi_phone Hitachi IP5000 VOIP WIFI Phone 1.5.6 has a hard-coded administrator password of "0000", which allows attackers with physical access to obtain sensitive information and modify the phone's configuratio… NVD-CWE-Other
CVE-2005-3719 2016-10-18 12:36 2005-11-21 Show GitHub Exploit DB Packet Storm