Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 18, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
4301 7.1 重要
Local
Vim Vim Vimにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-35177 2026-04-21 10:46 2026-04-6 Show GitHub Exploit DB Packet Storm
4302 7.7 重要
Network
pyLoad-ng project pyLoad-ng pyLoad-ng projectのpyLoad-ngにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-35187 2026-04-21 10:46 2026-04-6 Show GitHub Exploit DB Packet Storm
4303 7.5 重要
Network
saleor saleor saleorにおける制限またはスロットリング無しのリソースの割り当てに関する脆弱性 CWE-770
制限またはスロットリング無しのリソースの割り当て
CVE-2026-35401 2026-04-21 10:46 2026-04-8 Show GitHub Exploit DB Packet Storm
4304 9.3 緊急
Network
Monospace Inc Directus Monospace IncのDirectusにおける複数の脆弱性 CWE-346
CWE-693
CVE-2026-35408 2026-04-21 10:46 2026-04-6 Show GitHub Exploit DB Packet Storm
4305 7.7 重要
Network
Monospace Inc Directus Monospace IncのDirectusにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-35409 2026-04-21 10:46 2026-04-6 Show GitHub Exploit DB Packet Storm
4306 6.1 警告
Network
Monospace Inc Directus Monospace IncのDirectusにおける複数の脆弱性 CWE-184
CWE-601
CVE-2026-35410 2026-04-21 10:46 2026-04-6 Show GitHub Exploit DB Packet Storm
4307 4.3 警告
Network
Monospace Inc Directus Monospace IncのDirectusにおけるオープンリダイレクトの脆弱性 CWE-601
オープンリダイレクト
CVE-2026-35411 2026-04-21 10:46 2026-04-6 Show GitHub Exploit DB Packet Storm
4308 8.1 重要
Network
Monospace Inc Directus Monospace IncのDirectusにおける不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2026-35412 2026-04-21 10:46 2026-04-6 Show GitHub Exploit DB Packet Storm
4309 5.3 警告
Network
Monospace Inc Directus Monospace IncのDirectusにおける情報漏えいに関する脆弱性 CWE-200
CWE-noinfo
CVE-2026-35413 2026-04-21 10:46 2026-04-6 Show GitHub Exploit DB Packet Storm
4310 6.5 警告
Network
Monospace Inc Directus Monospace IncのDirectusにおける複数の脆弱性 CWE-400
CWE-770
CVE-2026-35441 2026-04-21 10:46 2026-04-6 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 18, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
348951 - freebsd freebsd jail.c in jail in FreeBSD 8.0 and 8.1-PRERELEASE, when the "-l -U root" options are omitted, does not properly restrict access to the current working directory, which might allow local users to read,… CWE-264
Permissions, Privileges, and Access Controls
CVE-2010-2022 2010-06-1 13:00 2010-05-29 Show GitHub Exploit DB Packet Storm
348952 - intervations filecopa Directory traversal vulnerability in the FTP service in FileCOPA before 5.03 allows remote attackers to read or overwrite arbitrary files via unknown vectors. NOTE: the provenance of this informatio… CWE-22
Path Traversal
CVE-2010-2112 2010-06-1 13:00 2010-05-29 Show GitHub Exploit DB Packet Storm
348953 - brekeke pbx Cross-site request forgery (CSRF) vulnerability in pbx/gate in Brekeke PBX 2.4.4.8 allows remote attackers to hijack the authentication of users for requests that change passwords via the pbxadmin.we… CWE-352
 Origin Validation Error
CVE-2010-2114 2010-06-1 13:00 2010-05-29 Show GitHub Exploit DB Packet Storm
348954 - solarwinds tftp_server SolarWinds TFTP Server 10.4.0.10 allows remote attackers to cause a denial of service (no new connections) via a crafted read request. CWE-20
 Improper Input Validation 
CVE-2010-2115 2010-06-1 13:00 2010-05-29 Show GitHub Exploit DB Packet Storm
348955 - hp mercury_testdirector_for_quality_center Unspecified vulnerability in HP TestDirector for Quality Center 9.2 before Patch8 allows remote attackers to modify data via unknown vectors. NVD-CWE-noinfo
CVE-2010-1959 2010-05-29 14:47 2010-05-28 Show GitHub Exploit DB Packet Storm
348956 - microsoft asp.net Microsoft ASP.NET 2.0 does not prevent setting the InnerHtml property on a control that inherits from HtmlContainerControl, which allows remote attackers to conduct cross-site scripting (XSS) attacks… CWE-79
Cross-site Scripting
CVE-2010-2084 2010-05-28 13:00 2010-05-28 Show GitHub Exploit DB Packet Storm
348957 - microsoft .net_framework The default configuration of ASP.NET in Microsoft .NET before 1.1 has a value of FALSE for the EnableViewStateMac property, which allows remote attackers to conduct cross-site scripting (XSS) attacks… CWE-79
Cross-site Scripting
CVE-2010-2085 2010-05-28 13:00 2010-05-28 Show GitHub Exploit DB Packet Storm
348958 - apache myfaces Apache MyFaces 1.1.7 and 1.2.8, as used in IBM WebSphere Application Server and other applications, does not properly handle an unencrypted view state, which allows remote attackers to conduct cross-… CWE-79
Cross-site Scripting
CVE-2010-2086 2010-05-28 13:00 2010-05-28 Show GitHub Exploit DB Packet Storm
348959 - microsoft asp.net ASP.NET in Microsoft .NET 3.5 does not properly handle an unencrypted view state, which allows remote attackers to conduct cross-site scripting (XSS) attacks against the form control via the __VIEWST… CWE-79
Cross-site Scripting
CVE-2010-2088 2010-05-28 13:00 2010-05-28 Show GitHub Exploit DB Packet Storm
348960 - cmsqlite cmsqlite SQL injection vulnerability in index.php in CMSQlite 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the c parameter. CWE-89
SQL Injection
CVE-2010-2095 2010-05-28 13:00 2010-05-28 Show GitHub Exploit DB Packet Storm