Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 30, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
4161 7.4 重要
Network
OpenProject OpenProject OpenProjectにおける過度な認証試行の不適切な制限に関する脆弱性 CWE-307
過度な認証試行の不適切な制限
CVE-2026-33667 2026-04-30 11:03 2026-04-15 Show GitHub Exploit DB Packet Storm
4162 6.7 警告
Local
デル data domain operating system デルのdata domain operating systemにおける権限管理に関する脆弱性 CWE-269
不適切な権限管理
CVE-2026-35154 2026-04-30 11:03 2026-04-20 Show GitHub Exploit DB Packet Storm
4163 3.3
Local
Uutils uutils coreutils Uutilsのuutils coreutilsにおける指定された機能の不適切な提供に関する脆弱性 CWE-684
指定された機能の不適切な提供
CVE-2026-35379 2026-04-30 11:03 2026-04-22 Show GitHub Exploit DB Packet Storm
4164 5.5 警告
Local
Uutils uutils coreutils Uutilsのuutils coreutilsにおける入力確認に関する脆弱性 CWE-20
CWE-noinfo
CVE-2026-35380 2026-04-30 11:03 2026-04-22 Show GitHub Exploit DB Packet Storm
4165 10 緊急
Network
マイクロソフト Microsoft Entra ID Microsoft Entra ID Entitlement Management Spoofing Vulnerability CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-35431 2026-04-30 11:03 2026-04-23 Show GitHub Exploit DB Packet Storm
4166 5.3 警告
Network
oobabooga TextGen oobaboogaのTextGenにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-35484 2026-04-30 11:03 2026-04-7 Show GitHub Exploit DB Packet Storm
4167 7.5 重要
Network
oobabooga TextGen oobaboogaのTextGenにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-35485 2026-04-30 11:03 2026-04-7 Show GitHub Exploit DB Packet Storm
4168 8.8 重要
Network
Pi-hole FTLDNS Pi-holeのFTLDNSにおける複数の脆弱性 CWE-78
CWE-93
CVE-2026-35517 2026-04-30 11:03 2026-04-7 Show GitHub Exploit DB Packet Storm
4169 8.8 重要
Network
Pi-hole FTLDNS Pi-holeのFTLDNSにおける複数の脆弱性 CWE-78
CWE-93
CVE-2026-35518 2026-04-30 11:03 2026-04-7 Show GitHub Exploit DB Packet Storm
4170 8.8 重要
Network
Pi-hole FTLDNS Pi-holeのFTLDNSにおける複数の脆弱性 CWE-78
CWE-93
CVE-2026-35519 2026-04-30 11:03 2026-04-7 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 30, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
346781 - moosegallery moosegallery PHP remote file inclusion vulnerability in display.php in MooseGallery allows remote attackers to execute arbitrary PHP code via the type parameter. NVD-CWE-Other
CVE-2005-2331 2017-07-11 10:32 2005-07-20 Show GitHub Exploit DB Packet Storm
346782 - rim blackberry_enterprise_server The BlackBerry Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) 4.0 to version 4.0 Service Pack 2 allows attackers to cause a denial of service via a malformed Portab… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2005-2344 2017-07-11 10:32 2005-12-31 Show GitHub Exploit DB Packet Storm
346783 - emc navisphere_manager Directory traversal vulnerability in EMC Navisphere Manager 6.4.1.0.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL. NVD-CWE-Other
CVE-2005-2357 2017-07-11 10:32 2005-08-16 Show GitHub Exploit DB Packet Storm
346784 - freebsd freebsd The AES-XCBC-MAC algorithm in IPsec in FreeBSD 5.3 and 5.4, when used for authentication without other encryption, uses a constant key instead of the one that was assigned by the system administrator… NVD-CWE-Other
CVE-2005-2359 2017-07-11 10:32 2005-08-5 Show GitHub Exploit DB Packet Storm
346785 - mandrakesoft mandrake_linux
mandrake_linux_corporate_server
nss_ldap 181 to versions before 213, as used in Mandrake Corporate Server and Mandrake 10.0, and other operating systems, does not properly handle a SIGPIPE signal when sending a search request to an… NVD-CWE-Other
CVE-2005-2377 2017-07-11 10:32 2005-07-26 Show GitHub Exploit DB Packet Storm
346786 - mozilla firefox Mozilla Firefox 1.0.4 and 1.0.5 does not choose the challenge with the strongest authentication scheme available as required by RFC2617, which might cause credentials to be sent in plaintext even if … NVD-CWE-Other
CVE-2005-2395 2017-07-11 10:32 2005-07-27 Show GitHub Exploit DB Packet Storm
346787 - mediawiki mediawiki Cross-site scripting (XSS) vulnerability in MediaWiki 1.4.6 and earlier allows remote attackers to inject arbitrary web script or HTML via a parameter to the page move template. NVD-CWE-Other
CVE-2005-2396 2017-07-11 10:32 2005-07-27 Show GitHub Exploit DB Packet Storm
346788 - gnu phpbook Cross-site scripting (XSS) vulnerability in guestbook.php in phpBook 1.46 allows remote attackers to inject arbitrary web script or HTML via the admin parameter. NVD-CWE-Other
CVE-2005-2397 2017-07-11 10:32 2005-07-27 Show GitHub Exploit DB Packet Storm
346789 - php_surveyor php_surveyor Multiple SQL injection vulnerabilities in PHP Surveyor 0.98 allows remote attackers to execute arbitrary SQL commands via (1) the sid, start, and id parameters to browse.php, the sid parameter to (2)… NVD-CWE-Other
CVE-2005-2398 2017-07-11 10:32 2005-07-27 Show GitHub Exploit DB Packet Storm
346790 - phpfinance phpfinance The inc.login.php scripts in PHPFinance 0.3 allows remote attackers to bypass the login and gain privileges. NVD-CWE-Other
CVE-2005-2400 2017-07-11 10:32 2005-07-27 Show GitHub Exploit DB Packet Storm