Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 15, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
4071 6.5 警告
Network
IBM Sterling Connect:Express Adapter for Sterling B2B Integrator IBMのSterling Connect:Express Adapter for Sterling B2B Integratorにおけるセッションの固定化の脆弱性 CWE-384
セッションの固定化
CVE-2025-36115 2026-02-5 15:50 2026-01-20 Show GitHub Exploit DB Packet Storm
4072 8.2 重要
Network
Petlibro, Inc. PETLIBRO Petlibro, Inc.のPETLIBROにおける重要な機能に対する認証の欠如に関する脆弱性 CWE-306
重要な機能に対する認証の欠如 解説
CVE-2025-3646 2026-02-5 15:50 2026-01-4 Show GitHub Exploit DB Packet Storm
4073 5.3 警告
Network
Petlibro, Inc. PETLIBRO Petlibro, Inc.のPETLIBROにおける代替パスまたはチャネルを使用した認証回避に関する脆弱性 CWE-288
代替パスまたはチャネルを使用した認証回避
CVE-2025-3652 2026-02-5 15:50 2026-01-4 Show GitHub Exploit DB Packet Storm
4074 9.8 緊急
Network
Petlibro, Inc. PETLIBRO Petlibro, Inc.のPETLIBROにおける重要な情報を含むインデックスの不適切な承認に関する脆弱性 CWE-612
重要な情報を含むインデックスの不適切な承認
CVE-2025-3653 2026-02-5 15:50 2026-01-4 Show GitHub Exploit DB Packet Storm
4075 9.8 緊急
Network
Petlibro, Inc. PETLIBRO Petlibro, Inc.のPETLIBROにおける重要な情報を含むインデックスの不適切な承認に関する脆弱性 CWE-612
重要な情報を含むインデックスの不適切な承認
CVE-2025-3654 2026-02-5 15:50 2026-01-4 Show GitHub Exploit DB Packet Storm
4076 8.2 重要
Network
Petlibro, Inc. PETLIBRO Petlibro, Inc.のPETLIBROにおける重要な情報を含むインデックスの不適切な承認に関する脆弱性 CWE-612
重要な情報を含むインデックスの不適切な承認
CVE-2025-3660 2026-02-5 15:50 2026-01-4 Show GitHub Exploit DB Packet Storm
4077 6.5 警告
Network
firefly
Sick
Tire Analytics
media server
Field Analytics
Logistics Diagnostic Analytics
Package Analytics
Baggage Analytics
アバイア等の複数ベンダの製品における過度な認証試行の不適切な制限に関する脆弱性 CWE-307
過度な認証試行の不適切な制限
CVE-2025-49186 2026-02-5 15:50 2025-06-12 Show GitHub Exploit DB Packet Storm
4078 7.5 重要
Network
JustDoIt0910 tinyMQTT JustDoIt0910のtinyMQTTにおける有効期限後のメモリの解放の欠如に関する脆弱性 CWE-401
有効期限後のメモリの解放の欠如
CVE-2025-56353 2026-02-5 15:50 2026-01-20 Show GitHub Exploit DB Packet Storm
4079 5.4 警告
Network
School Management System PHP Project School Management System PHP School Management System PHP ProjectのSchool Management System PHPにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2025-63443 2026-02-5 15:50 2025-11-3 Show GitHub Exploit DB Packet Storm
4080 9.8 緊急
Network
opensagres XDocReport opensagresのXDocReportにおけるテンプレートエンジンで使用される特殊な要素の不適切な無効化に関する脆弱性 CWE-1336
テンプレートエンジンで使用される特殊な要素の不適切な無効化
CVE-2025-64087 2026-02-5 15:50 2026-01-20 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 16, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
350651 - pragma_systems pragma_telnetserver Cross-site scripting (XSS) vulnerability in Pragma Systems Telnetserver 6.0 allows remote attackers to inject arbitrary web script or HTML, and hide activities in log files, via a "<!--" (HTML commen… NVD-CWE-Other
CVE-2005-1969 2008-09-6 05:50 2005-06-7 Show GitHub Exploit DB Packet Storm
350652 - symantec pcanywhere Symantec pcAnywhere 10.5x and 11.x before 11.5, with "Launch with Windows" enabled, allows local users with physical access to execute arbitrary commands via the Caller Properties feature. NVD-CWE-Other
CVE-2005-1970 2008-09-6 05:50 2005-06-16 Show GitHub Exploit DB Packet Storm
350653 - interactivephp fusionbb Directory traversal vulnerability in InteractivePHP FusionBB .11 Beta and earlier allows remote attackers to include arbitrary local files via ".." sequences in the language parameter. NVD-CWE-Other
CVE-2005-1971 2008-09-6 05:50 2005-06-16 Show GitHub Exploit DB Packet Storm
350654 - interactivephp fusionbb Multiple SQL injection vulnerabilities in InteractivePHP FusionBB .11 Beta and earlier allow remote attackers to execute arbitrary SQL commands via (1) the username, which is not properly handled by … NVD-CWE-Other
CVE-2005-1972 2008-09-6 05:50 2005-06-13 Show GitHub Exploit DB Packet Storm
350655 - annuaire 1two Multiple cross-site scripting (XSS) vulnerabilities in Annuaire 1Two 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the id parameter to index.php, or the (2) si… NVD-CWE-Other
CVE-2005-1975 2008-09-6 05:50 2005-06-16 Show GitHub Exploit DB Packet Storm
350656 - novell netmail Novell NetMail 3.5.2a, 3.5.2b, and 3.5.2c, when running on Linux, sets the owner and group ID to 500 for certain files, which could allow users or groups with that ID to execute arbitrary code or cau… NVD-CWE-Other
CVE-2005-1976 2008-09-6 05:50 2005-12-31 Show GitHub Exploit DB Packet Storm
350657 - edgewall_software trac Directory traversal vulnerability in Edgewall Trac 0.8.3 and earlier allows remote attackers to read or write arbitrary files via a .. (dot dot) in the id parameter to the (1) upload or (2) attachmen… NVD-CWE-Other
CVE-2005-2007 2008-09-6 05:50 2005-06-19 Show GitHub Exploit DB Packet Storm
350658 - symantec norton_antivirus Symantec AntiVirus 9 Corporate Edition allows local users to gain privileges via the "Scan for viruses" option, which launches a help window with raised privileges, a re-introduction of a vulnerabili… NVD-CWE-Other
CVE-2005-2017 2008-09-6 05:50 2005-08-30 Show GitHub Exploit DB Packet Storm
350659 - freebsd freebsd ipfw in FreeBSD 5.4, when running on Symmetric Multi-Processor (SMP) or Uni Processor (UP) systems with the PREEMPTION kernel option enabled, does not sufficiently lock certain resources while perfor… NVD-CWE-Other
CVE-2005-2019 2008-09-6 05:50 2005-07-5 Show GitHub Exploit DB Packet Storm
350660 - cpanel cpanel Cross-site scripting (XSS) vulnerability in cPanel 9.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the user parameter in the login page. NVD-CWE-Other
CVE-2005-2021 2008-09-6 05:50 2005-06-20 Show GitHub Exploit DB Packet Storm