Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 27, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
4881 7 重要
Local
マイクロソフト Microsoft Windows Server 2019
Microsoft Windows 10 1607
Microsoft Windows Server 2016
Microsoft Windows 11 23h2
Microsoft …
Microsoft Resilient File System の特権昇格の脆弱性 CWE-362
CWE-416
CVE-2026-32091 2026-04-23 10:13 2026-04-14 Show GitHub Exploit DB Packet Storm
4882 7.8 重要
Local
マイクロソフト Microsoft Windows 11 23h2
Microsoft Windows 10 22h2
Microsoft Windows 10 21h2
Microsoft Windows Server 2025
Microsoft Wind…
デスクトップ ウィンドウ マネージャーの特権昇格の脆弱性 CWE-416
解放済みメモリの使用
CVE-2026-32155 2026-04-23 10:13 2026-04-14 Show GitHub Exploit DB Packet Storm
4883 7.5 重要
Network
Apache Software Foundation Apache Airflow Apache Software FoundationのApache Airflowにおける不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2026-32228 2026-04-23 10:13 2026-04-18 Show GitHub Exploit DB Packet Storm
4884 3.7
Network
Apache Software Foundation Apache Airflow Apache Software FoundationのApache Airflowにおける誤った領域へのリソースの漏えいに関する脆弱性 CWE-668
誤った領域へのリソースの漏えい
CVE-2026-32690 2026-04-23 10:13 2026-04-18 Show GitHub Exploit DB Packet Storm
4885 7.8 重要
Local
Curtis Galloway libexif Libexif ProjectのLibexifにおける整数アンダーフローの脆弱性 CWE-191
整数アンダーフロー
CVE-2026-32775 2026-04-23 10:13 2026-03-16 Show GitHub Exploit DB Packet Storm
4886 3.1
Network
Weblate Weblate Weblateにおけるアクセス制御に関する脆弱性 CWE-284
不適切なアクセス制御
CVE-2026-33212 2026-04-23 10:13 2026-04-15 Show GitHub Exploit DB Packet Storm
4887 4.3 警告
Network
Weblate Weblate Weblateにおける認証の欠如に関する脆弱性 CWE-862
認証の欠如
CVE-2026-33214 2026-04-23 10:13 2026-04-15 Show GitHub Exploit DB Packet Storm
4888 6.8 警告
Network
Weblate Weblate Weblateにおける複数の脆弱性 CWE-200
CWE-22
CVE-2026-33220 2026-04-23 10:13 2026-04-15 Show GitHub Exploit DB Packet Storm
4889 8 重要
Network
Weblate Weblate Weblateにおける複数の脆弱性 CWE-23
CWE-434
CWE-94
CVE-2026-33435 2026-04-23 10:13 2026-04-15 Show GitHub Exploit DB Packet Storm
4890 5 警告
Network
Weblate Weblate Weblateにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-33440 2026-04-23 10:13 2026-04-15 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 28, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
353311 - mercur mercur_messaging Mercur Messaging 2005 SP2 allows remote attackers to read the source code of .ctml files via a URL with a trailing hex-encoded space ("%20"). NVD-CWE-Other
CVE-2005-1656 2008-09-6 05:49 2005-05-18 Show GitHub Exploit DB Packet Storm
353312 - mercur mercur_messaging Multiple directory traversal vulnerabilities in Mercur Messaging 2005 SP2 allow remote attackers to perform unauthorized file operations via the Folder.Id parameter to (1) deletefolder.ctml, (2) dele… NVD-CWE-Other
CVE-2005-1657 2008-09-6 05:49 2005-05-18 Show GitHub Exploit DB Packet Storm
353313 - myserver myserver Directory traversal vulnerability in filemanager.cpp in MyServer 0.8 allows remote attackers to list the parent directory of the web root via a URL with a "..." (triple dot). NVD-CWE-Other
CVE-2005-1658 2008-09-6 05:49 2005-05-18 Show GitHub Exploit DB Packet Storm
353314 - - - Cross-site scripting (XSS) vulnerability in filemanager.cpp in MyServer 0.8 allows remote attackers to inject arbitrary Javascript via a URL with a "..." (triple dot) followed by an onmouseover even… NVD-CWE-Other
CVE-2005-1659 2008-09-6 05:49 2005-05-18 Show GitHub Exploit DB Packet Storm
353315 - jeuce jeuce_personal_web_server Jeuce Personal Webserver 2.13 allows remote attackers to cause a denial of service (server crash) via a long GET request, possibly triggering a buffer overflow. NVD-CWE-Other
CVE-2005-1661 2008-09-6 05:49 2005-05-18 Show GitHub Exploit DB Packet Storm
353316 - ubertec help_center_live Multiple cross-site scripting (XSS) vulnerabilities in Help Center Live allow remote attackers to inject arbitrary web script or HTML via the (1) find parameter to index.php, (2) name or (3) message … NVD-CWE-Other
CVE-2005-1672 2008-09-6 05:49 2005-05-19 Show GitHub Exploit DB Packet Storm
353317 - ubertec help_center_live Multiple SQL injection vulnerabilities in Help Center Live allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to index.php, (2) tid parameter to view.php, fid parameter… NVD-CWE-Other
CVE-2005-1673 2008-09-6 05:49 2005-05-19 Show GitHub Exploit DB Packet Storm
353318 - groove groove_workspace
virtual_office
Groove Virtual Office before 3.1 build 2338, before 3.1a build 2364, and Groove Workspace before 2.5n build 1871 installs the client installation directories with insecure EVERYBODY permissions, whic… NVD-CWE-Other
CVE-2005-1675 2008-09-6 05:49 2005-05-20 Show GitHub Exploit DB Packet Storm
353319 - groove groove_workspace
virtual_office
Multiple cross-site scripting (XSS) vulnerabilities in Groove Mobile Workspace in Groove Virtual Office before 3.1 build 2338, before 3.1a build 2364, and Groove Workspace before 2.5n build 1871 allo… NVD-CWE-Other
CVE-2005-1676 2008-09-6 05:49 2005-05-20 Show GitHub Exploit DB Packet Storm
353320 - groove groove_workspace
virtual_office
Unknown vulnerability in Groove Virtual Office before 3.1 build 2338, before 3.1a build 2364, and Groove Workspace before 2.5n build 1871 allows remote attackers to bypass restrictions on COM objects. NVD-CWE-Other
CVE-2005-1677 2008-09-6 05:49 2005-05-20 Show GitHub Exploit DB Packet Storm