Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 29, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
4851 7.1 重要
Network
WWBN AVideo WWBNのAVideoにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-39370 2026-04-24 11:42 2026-04-7 Show GitHub Exploit DB Packet Storm
4852 7.8 重要
Local
Vim Vim Vimにおけるコードインジェクションの脆弱性 CWE-94
コード・インジェクション
CVE-2026-39881 2026-04-24 11:42 2026-04-8 Show GitHub Exploit DB Packet Storm
4853 5.3 警告
Network
OpenEXR OpenEXR OpenEXRにおける整数オーバーフローの脆弱性 CWE-190
整数オーバーフローまたはラップアラウンド
CVE-2026-39886 2026-04-24 11:42 2026-04-21 Show GitHub Exploit DB Packet Storm
4854 8.8 重要
Network
Mervin Praison (MervinPraison) PraisonAI Mervin Praison (MervinPraison)のPraisonAIにおけるコードインジェクションの脆弱性 CWE-94
コード・インジェクション
CVE-2026-39891 2026-04-24 11:42 2026-04-8 Show GitHub Exploit DB Packet Storm
4855 4.3 警告
Network
lycheeorg lychee lycheeorgのLycheeにおける不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2026-39957 2026-04-24 11:42 2026-04-9 Show GitHub Exploit DB Packet Storm
4856 9.6 緊急
Network
MISP MISP MISPにおけるLDAP インジェクションの脆弱性 CWE-90
LDAP インジェクション
CVE-2026-39962 2026-04-24 11:42 2026-04-9 Show GitHub Exploit DB Packet Storm
4857 6.9 警告
Network
s9y Serendipity s9yのSerendipityにおける検証および完全性チェックを行っていない Cookie への依存に関する脆弱性 CWE-565
検証および完全性チェックを行っていない Cookie への依存
CVE-2026-39963 2026-04-24 11:42 2026-04-15 Show GitHub Exploit DB Packet Storm
4858 7.2 重要
Network
s9y Serendipity s9yのSerendipityにおけるHTTP レスポンス分割に関する脆弱性 CWE-113
HTTP レスポンスの分割
CVE-2026-39971 2026-04-24 11:42 2026-04-15 Show GitHub Exploit DB Packet Storm
4859 7.1 重要
Local
apktool apktool Apktoolにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-39973 2026-04-24 11:42 2026-04-21 Show GitHub Exploit DB Packet Storm
4860 5.3 警告
Network
Apache Software Foundation Apache log4net Apache Software FoundationのApache log4netにおけるエンコードおよびエスケープに関する脆弱性 CWE-116
不適切なエンコード、または出力のエスケープ
CVE-2026-40021 2026-04-24 11:42 2026-04-10 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 29, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
348571 - immunix immunix Buffer overflow in url_filename function for wget 1.8.1 allows attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a long URL. NVD-CWE-Other
CVE-2002-1565 2017-07-11 10:29 2003-06-16 Show GitHub Exploit DB Packet Storm
348572 - netris netris netris 0.5, and possibly other versions before 0.52, when running with the -w (wait) option, allows remote attackers to cause a denial of service (crash) via a long string to port 9284. NVD-CWE-Other
CVE-2002-1566 2017-07-11 10:29 2003-08-27 Show GitHub Exploit DB Packet Storm
348573 - ghostview
gv
ghostview
gv
gv 3.5.8, and possibly earlier versions, allows remote attackers to execute arbitrary commands via shell metacharacters in the filename for (1) a PDF file or (2) a gzip file. NVD-CWE-Other
CVE-2002-1569 2017-07-11 10:29 2003-11-17 Show GitHub Exploit DB Packet Storm
348574 - ucd-snmp ucd-snmp Heap-based buffer overflow in snmpnetstat for ucd-snmp 4.2.3 and earlier, and net-snmp, allows remote attackers to execute arbitrary code via multiple getnextrequest PDU messages with conflicting ifi… NVD-CWE-Other
CVE-2002-1570 2017-07-11 10:29 2003-11-3 Show GitHub Exploit DB Packet Storm
348575 - mit cgiemail cgiemail allows remote attackers to use cgiemail as a spam proxy via CRLF injection of encoded newline (%0a) characters in parameters such as "required-subject," which can be used to modify the CC, B… NVD-CWE-Other
CVE-2002-1575 2017-07-11 10:29 2004-03-3 Show GitHub Exploit DB Packet Storm
348576 - sap sap_db lserver in SAP DB 7.3 and earlier uses the current working directory to find and execute the lserversrv program, which allows local users to gain privileges with a malicious lserversrv that is called… NVD-CWE-Other
CVE-2002-1576 2017-07-11 10:29 2004-04-15 Show GitHub Exploit DB Packet Storm
348577 - sap sap_r_3 SAP R/3 2.0B to 4.6D installs several clients with default users and passwords, which allows remote attackers to gain privileges via the (1) SAP*, (2) SAPCPIC, (3) DDIC, (4) EARLYWATCH, or (5) TMSADM… NVD-CWE-Other
CVE-2002-1577 2017-07-11 10:29 2004-04-15 Show GitHub Exploit DB Packet Storm
348578 - sap sap_r_3 The default installation of SAP R/3, when using Oracle and SQL*net V2 3.x, 4.x, and 6.10, allows remote attackers to obtain arbitrary, sensitive SAP data by directly connecting to the Oracle database… NVD-CWE-Other
CVE-2002-1578 2017-07-11 10:29 2004-04-15 Show GitHub Exploit DB Packet Storm
348579 - sap sapgui SAP GUI (Sapgui) 4.6D allows remote attackers to cause a denial of service (crash) via a connection to a high-numbered port, which generates an "unknown connection data" error. NVD-CWE-Other
CVE-2002-1579 2017-07-11 10:29 2004-04-15 Show GitHub Exploit DB Packet Storm
348580 - carnegie_mellon_university cyrus_imap_server Integer overflow in imapparse.c for Cyrus IMAP server 1.4 and 2.1.10 allows remote attackers to execute arbitrary code via a large length value that facilitates a buffer overflow attack, a different … NVD-CWE-Other
CVE-2002-1580 2017-07-11 10:29 2004-06-14 Show GitHub Exploit DB Packet Storm