Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 31, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
4871 5.3 警告
Network
pypdf project pypdf pypdf projectのpypdfにおけるDTD の再帰的なエンティティ参照の不適切な制限に関する脆弱性 CWE-776
DTD の再帰的なエンティティ参照の不適切な制限
CVE-2026-40260 2026-04-24 11:41 2026-04-17 Show GitHub Exploit DB Packet Storm
4872 8.8 重要
Network
Chamilo Association Chamilo LMS Chamilo AssociationのChamilo LMSにおける複数の脆弱性 CWE-269
CWE-863
CVE-2026-40291 2026-04-24 11:41 2026-04-14 Show GitHub Exploit DB Packet Storm
4873 9 緊急
Network
Gitroom Postiz GitroomのPostizにおける複数の脆弱性 CWE-345
CWE-434
CWE-79
CVE-2026-40487 2026-04-24 11:41 2026-04-18 Show GitHub Exploit DB Packet Storm
4874 9.8 緊急
Network
FreeScout FreeScout FreeScoutにおける複数の脆弱性 CWE-200
CWE-284
CWE-770
CVE-2026-40498 2026-04-24 11:41 2026-04-21 Show GitHub Exploit DB Packet Storm
4875 6.1 警告
Network
FreeScout FreeScout FreeScoutにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-40565 2026-04-24 11:41 2026-04-21 Show GitHub Exploit DB Packet Storm
4876 7.1 重要
Network
OpenProject OpenProject OpenProjectにおける複数の脆弱性 CWE-367
CWE-639
CVE-2026-40896 2026-04-24 11:41 2026-04-20 Show GitHub Exploit DB Packet Storm
4877 7.1 重要
Network
WWBN AVideo WWBNのAVideoにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2026-40926 2026-04-24 11:41 2026-04-21 Show GitHub Exploit DB Packet Storm
4878 9.9 緊急
Network
flowiseai flowise flowiseaiのflowiseにおけるOS コマンドインジェクションの脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2026-40933 2026-04-24 11:41 2026-04-21 Show GitHub Exploit DB Packet Storm
4879 9.8 緊急
Network
protobufjs project protobufjs protobufjs projectのprotobufjsにおけるコードインジェクションの脆弱性 CWE-94
コード・インジェクション
CVE-2026-41242 2026-04-24 11:41 2026-04-18 Show GitHub Exploit DB Packet Storm
4880 7.5 重要
Network
Junrar project Junrar Junrar projectのJunrarにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-41245 2026-04-24 11:41 2026-04-20 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 31, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
350321 - easy_software_products
apple
cups
mac_os_x
Multiple integer overflows in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allow remote attackers to execute arbitrary code via (1) the CUPSd HTTP interface, as demonstrated by vanilla-co… NVD-CWE-Other
CVE-2002-1383 2016-10-18 11:26 2002-12-26 Show GitHub Exploit DB Packet Storm
350322 - ehud_gavron tracesroute Buffer overflow in traceroute-nanog (aka traceroute-ng) may allow local users to execute arbitrary code via a long hostname argument. NVD-CWE-Other
CVE-2002-1386 2016-10-18 11:26 2003-01-2 Show GitHub Exploit DB Packet Storm
350323 - ehud_gavron tracesroute The spray mode in traceroute-nanog (aka traceroute-ng) may allow local users to overwrite arbitrary memory locations via an array index overflow using the nprobes (number of probes) argument. NVD-CWE-Other
CVE-2002-1387 2016-10-18 11:26 2003-01-2 Show GitHub Exploit DB Packet Storm
350324 - kde kde Multiple vulnerabilities in KDE 2 and KDE 3.x through 3.0.5 do not quote certain parameters that are inserted into a shell command, which could allow remote attackers to execute arbitrary commands vi… NVD-CWE-Other
CVE-2002-1393 2016-10-18 11:26 2003-01-17 Show GitHub Exploit DB Packet Storm
350325 - postgresql postgresql Buffer overflow in the date parser for PostgreSQL before 7.2.2 allows attackers to cause a denial of service and possibly execute arbitrary code via a long date string, aka a vulnerability "in handli… NVD-CWE-Other
CVE-2002-1398 2016-10-18 11:26 2003-01-17 Show GitHub Exploit DB Packet Storm
350326 - postgresql postgresql Unknown vulnerability in cash_out and possibly other functions in PostgreSQL 7.2.1 and earlier, and possibly later versions before 7.2.3, with unknown impact, based on an invalid integer input which … NVD-CWE-Other
CVE-2002-1399 2016-10-18 11:26 2003-01-17 Show GitHub Exploit DB Packet Storm
350327 - postgresql postgresql Heap-based buffer overflow in the repeat() function for PostgreSQL before 7.2.2 allows attackers to execute arbitrary code by causing repeat() to generate a large string. NVD-CWE-Other
CVE-2002-1400 2016-10-18 11:26 2003-01-17 Show GitHub Exploit DB Packet Storm
350328 - postgresql postgresql Buffer overflows in the (1) TZ and (2) SET TIME ZONE enivronment variables for PostgreSQL 7.2.1 and earlier allow local users to cause a denial of service and possibly execute arbitrary code. NVD-CWE-Other
CVE-2002-1402 2016-10-18 11:26 2003-01-17 Show GitHub Exploit DB Packet Storm
350329 - elinks
links
university_of_kansas
elinks
links
lynx
CRLF injection vulnerability in Lynx 2.8.4 and earlier allows remote attackers to inject false HTTP headers into an HTTP request that is provided on the command line, via a URL containing encoded car… NVD-CWE-Other
CVE-2002-1405 2016-10-18 11:26 2003-02-19 Show GitHub Exploit DB Packet Storm
350330 - inter7 qmailadmin Buffer overflow in qmailadmin allows local users to gain privileges via a long QMAILADMIN_TEMPLATEDIR environment variable. NVD-CWE-Other
CVE-2002-1414 2016-10-18 11:26 2003-04-11 Show GitHub Exploit DB Packet Storm