Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 26, 2026, noon

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
4051 8.8 重要
Network
M1k1o Neko M1k1oのNekoにおける複数の脆弱性 CWE-20
CWE-269
CWE-284
CWE-639
CWE-862
CVE-2026-39386 2026-04-27 11:27 2026-04-21 Show GitHub Exploit DB Packet Storm
4052 8.8 重要
Network
Lawnchair Lawnchair Lawnchairにおけるコマンドインジェクションの脆弱性 CWE-77
コマンドインジェクション
CVE-2026-39866 2026-04-27 11:27 2026-04-21 Show GitHub Exploit DB Packet Storm
4053 6.1 警告
Network
NetFoundry zrok NetFoundryのzrokにおける複数の脆弱性 CWE-116
CWE-79
CVE-2026-40302 2026-04-27 11:27 2026-04-17 Show GitHub Exploit DB Packet Storm
4054 7.5 重要
Network
NetFoundry zrok NetFoundryのzrokにおける複数の脆弱性 CWE-400
CWE-789
CVE-2026-40303 2026-04-27 11:27 2026-04-17 Show GitHub Exploit DB Packet Storm
4055 5.3 警告
Network
NetFoundry zrok NetFoundryのzrokにおける複数の脆弱性 CWE-284
CWE-863
CVE-2026-40304 2026-04-27 11:27 2026-04-17 Show GitHub Exploit DB Packet Storm
4056 8.8 重要
Network
HKUDS OpenHarness HKUDSのOpenHarnessにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2026-40502 2026-04-27 11:27 2026-04-16 Show GitHub Exploit DB Packet Storm
4057 6.5 警告
Network
HKUDS OpenHarness HKUDSのOpenHarnessにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-40503 2026-04-27 11:27 2026-04-16 Show GitHub Exploit DB Packet Storm
4058 8.8 重要
Network
FreePBX API Module FreePBXのAPI ModuleにおけるOS コマンドインジェクションの脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2026-40520 2026-04-27 11:26 2026-04-21 Show GitHub Exploit DB Packet Storm
4059 6.1 警告
Network
Yusuke Inuzuka (yuin) goldmark Yusuke Inuzuka (yuin)のgoldmarkにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-5160 2026-04-27 11:26 2026-04-15 Show GitHub Exploit DB Packet Storm
4060 6.5 警告
Network
GitLab.org GitLab GitLab.orgのGitLabにおける制限またはスロットリング無しのリソースの割り当てに関する脆弱性 CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2025-0186 2026-04-27 11:26 2026-04-22 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 26, 2026, 4:05 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
347171 - versatilebulletinboard versatilebulletinboard getversions.php in versatileBulletinBoard (vBB) 1.0.0 RC2 lists the versions of all installed scripts, which allows remote attackers to obtain sensitive information via a direct request. NVD-CWE-Other
CVE-2005-3261 2016-10-18 12:34 2005-10-20 Show GitHub Exploit DB Packet Storm
347172 - flatnuke flatnuke Cross-site scripting (XSS) vulnerability in index.php for FlatNuke 2.5.6 allows remote attackers to inject arbitrary web script or HTML via the user parameter in a profile operation, a different vuln… NVD-CWE-Other
CVE-2005-3306 2016-10-18 12:34 2005-10-26 Show GitHub Exploit DB Packet Storm
347173 - - - Directory traversal vulnerability in index.php for FlatNuke 2.5.6 allows remote attackers to read arbitrary files via ".." sequences in the (1) user parameter in a profile operation or (2) quale para… NVD-CWE-Other
CVE-2005-3307 2016-10-18 12:34 2005-10-26 Show GitHub Exploit DB Packet Storm
347174 - bmc software_control-m_agent BMC Software Control-M 6.1.03 for Solaris, and possibly other platforms, allows local users to overwrite arbitrary files via a symlink attack on temporary files. NVD-CWE-Other
CVE-2005-3311 2016-10-18 12:34 2005-10-26 Show GitHub Exploit DB Packet Storm
347175 - - - Network Appliance Data ONTAP 7.0 and earlier allows iSCSI Initiators to bypass iSCSI authentication via a modified client that skips the Security (Start) mode, as required by the Login Negotiation pr… NVD-CWE-Other
CVE-2005-3327 2016-10-18 12:34 2005-10-27 Show GitHub Exploit DB Packet Storm
347176 - punbb punbb PHP remote file inclusion vulnerability in common.php in PunBB 1.1.2 through 1.1.5 allows remote attackers to execute arbitrary code via the pun_root parameter. NVD-CWE-Other
CVE-2005-3328 2016-10-18 12:34 2005-10-27 Show GitHub Exploit DB Packet Storm
347177 - rsa authentication_agent_for_web Cross-site scripting (XSS) vulnerability in RSA Authentication Agent for Web 5.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the image parameter in a GetPic operati… NVD-CWE-Other
CVE-2005-3329 2016-10-18 12:34 2005-10-27 Show GitHub Exploit DB Packet Storm
347178 - flatnuke flatnuke Cross-site scripting (XSS) vulnerability in forum/index.php in FlatNuke 2.5.6 allows remote attackers to inject arbitrary web script or HTML via the nome parameter in a login operation, a variant of … NVD-CWE-Other
CVE-2005-3361 2016-10-18 12:34 2005-10-28 Show GitHub Exploit DB Packet Storm
347179 - platinum dboardgear Multiple SQL injection vulnerabilities in DboardGear allow remote attackers to execute arbitrary SQL commands via (1) the buddy parameter in buddy.php, (2) the u2uid parameter in u2u.php, and (3) an … NVD-CWE-Other
CVE-2005-3364 2016-10-18 12:34 2005-10-30 Show GitHub Exploit DB Packet Storm
347180 - sparkleblog sparkleblog Cross-site scripting (XSS) vulnerability in journal.php in SparkleBlog 2.1 allows remote attackers to inject arbitrary web script or HTML via the name field. NVD-CWE-Other
CVE-2005-3367 2016-10-18 12:34 2005-10-30 Show GitHub Exploit DB Packet Storm