Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 6, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
4431 4.8 警告
Network
GFI GFI HelpDesk GFIのGFI HelpDeskにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-23753 2026-04-30 12:14 2026-04-20 Show GitHub Exploit DB Packet Storm
4432 5.4 警告
Network
GFI GFI HelpDesk GFIのGFI HelpDeskにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-23756 2026-04-30 12:13 2026-04-20 Show GitHub Exploit DB Packet Storm
4433 5.4 警告
Network
GFI GFI HelpDesk GFIのGFI HelpDeskにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-23757 2026-04-30 12:13 2026-04-20 Show GitHub Exploit DB Packet Storm
4434 5.4 警告
Network
GFI GFI HelpDesk GFIのGFI HelpDeskにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-23758 2026-04-30 12:13 2026-04-20 Show GitHub Exploit DB Packet Storm
4435 6.5 警告
Network
Mattermost, Inc. Focalboard Mattermost, Inc.のFocalboardにおけるSQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2026-25773 2026-04-30 12:13 2026-04-3 Show GitHub Exploit DB Packet Storm
4436 4.3 警告
Network
Mattermost, Inc. Focalboard Mattermost, Inc.のFocalboardにおけるユーザ制御の鍵による認証回避に関する脆弱性 CWE-639
ユーザ制御の鍵による認証回避
CVE-2026-28736 2026-04-30 12:13 2026-04-3 Show GitHub Exploit DB Packet Storm
4437 7.8 重要
Local
DeepCool DeepCreative DeepCoolのDeepCreativeにおける安全でない継承されたパーミッションに関する脆弱性 CWE-277
安全でない継承されたパーミッション
CVE-2026-30266 2026-04-30 12:13 2026-04-20 Show GitHub Exploit DB Packet Storm
4438 7.5 重要
Network
Angeet ES3 KVM Firmware AngeetのES3 KVM Firmwareにおける重要な機能に対する認証の欠如に関する脆弱性 CWE-306
重要な機能に対する認証の欠如 解説
CVE-2026-32297 2026-04-30 12:13 2026-03-17 Show GitHub Exploit DB Packet Storm
4439 9.1 緊急
Network
Angeet ES3 KVM Firmware AngeetのES3 KVM FirmwareにおけるOS コマンドインジェクションの脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2026-32298 2026-04-30 12:13 2026-03-17 Show GitHub Exploit DB Packet Storm
4440 7.5 重要
Network
オラクル Oracle Financial Services Customer Screening オラクルのOracle Financial Services Customer Screeningにおける認可に関する脆弱性 CWE-285
不適切な認可
CVE-2026-34320 2026-04-30 12:13 2026-04-21 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 6, 2026, 4:18 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
346601 - sun n1_system_manager Sun N1 System Manager 1.1 for Solaris 10 before patch 121161-01 records system passwords in the world-readable scripts (1) /cr/hd_jobs_db.sh, (2) /cr/hd_plan_checkin.sh, and (3) /cr/oracle_plan_check… NVD-CWE-Other
CVE-2006-2614 2017-07-20 10:31 2006-05-26 Show GitHub Exploit DB Packet Storm
346602 - linux linux_kernel Race condition in Linux kernel 2.6.15 to 2.6.17, when running on SMP platforms, allows local users to cause a denial of service (crash) by creating and exiting a large number of tasks, then accessing… NVD-CWE-Other
CVE-2006-2629 2017-07-20 10:31 2006-05-27 Show GitHub Exploit DB Packet Storm
346603 - cosmicphp cosmicshoppingcart Multiple cross-site scripting (XSS) vulnerabilities in (a) search.php, (b) search_cat.php, (c) search_price.php, and (d) product_details.php in the cosmicshop directory for CosmicShoppingCart allow r… CWE-79
Cross-site Scripting
CVE-2006-2649 2017-07-20 10:31 2006-05-30 Show GitHub Exploit DB Packet Storm
346604 - cosmicphp cosmicshoppingcart SQL injection vulnerability in cosmicshop/search.php in CosmicShoppingCart allows remote attackers to execute arbitrary SQL commands via the max parameter. NVD-CWE-Other
CVE-2006-2650 2017-07-20 10:31 2006-05-30 Show GitHub Exploit DB Packet Storm
346605 - freebsd freebsd Directory traversal vulnerability in smbfs smbfs on FreeBSD 4.10 up to 6.1 allows local users to escape chroot restrictions for an SMB-mounted filesystem via "..\\" sequences. NOTE: this is similar … NVD-CWE-Other
CVE-2006-2654 2017-07-20 10:31 2006-06-2 Show GitHub Exploit DB Packet Storm
346606 - freebsd freebsd The build process for ypserv in FreeBSD 5.3 up to 6.1 accidentally disables access restrictions when using the /var/yp/securenets file, which allows remote attackers to bypass intended access restric… NVD-CWE-Other
CVE-2006-2655 2017-07-20 10:31 2006-06-2 Show GitHub Exploit DB Packet Storm
346607 - sitescape sitescape_forum Dispatch.cgi/_user/uservCard/ in SiteScape Forum 7.2 and possibly earlier generates different responses in a way that allows remote attackers to enumerate valid usernames. NVD-CWE-Other
CVE-2006-2676 2017-07-20 10:31 2006-05-31 Show GitHub Exploit DB Packet Storm
346608 - sitescape sitescape_forum SiteScape Forum 7.2 and possibly earlier stores the avf.rc configuraiton file under the web document root with insufficient access control, which allows remote attackers to obtain sensitive path info… NVD-CWE-Other
CVE-2006-2677 2017-07-20 10:31 2006-05-31 Show GitHub Exploit DB Packet Storm
346609 - cisco vpn_client Unspecified vulnerability in the VPN Client for Windows Graphical User Interface (GUI) (aka the VPN client dialer) in Cisco VPN Client for Windows 4.8.00.* and earlier, except for 4.7.00.0533, allows… NVD-CWE-noinfo
CVE-2006-2679 2017-07-20 10:31 2006-05-31 Show GitHub Exploit DB Packet Storm
346610 - socketmail socketmail PHP remote file inclusion vulnerability in SocketMail Lite and Pro 2.2.6 and earlier, when register_globals and magic_quotes are enabled, allows remote attackers to execute arbitrary PHP code via a U… CWE-94
Code Injection
CVE-2006-2681 2017-07-20 10:31 2006-05-31 Show GitHub Exploit DB Packet Storm