Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 5, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
4991 8.8 重要
Network
OpenMage Magento OpenMageのMagentoにおける危険なタイプのファイルの無制限アップロードに関する脆弱性 CWE-434
危険なタイプのファイルの無制限アップロード
CVE-2026-40488 2026-04-27 11:21 2026-04-20 Show GitHub Exploit DB Packet Storm
4992 9.1 緊急
Network
FreeScout FreeScout FreeScoutにおける複数の脆弱性 CWE-330
CWE-340
CVE-2026-40496 2026-04-27 11:21 2026-04-21 Show GitHub Exploit DB Packet Storm
4993 8.1 重要
Network
FreeScout FreeScout FreeScoutにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-40497 2026-04-27 11:20 2026-04-21 Show GitHub Exploit DB Packet Storm
4994 8.8 重要
Network
PJSIP pjsip PJSIPのpjsipにおけるヒープベースのバッファオーバーフローの脆弱性 CWE-122
ヒープオーバーフロー
CVE-2026-40614 2026-04-27 11:20 2026-04-21 Show GitHub Exploit DB Packet Storm
4995 6.5 警告
Network
decidim decidim Decidim Free Software AssociationのDecidimにおける不適切な権限設定に関する脆弱性 CWE-266
不適切な権限設定
CVE-2026-40869 2026-04-27 11:20 2026-04-21 Show GitHub Exploit DB Packet Storm
4996 9.8 緊急
Network
PJSIP pjsip PJSIPのpjsipにおけるスタックベースのバッファオーバーフローの脆弱性 CWE-121
スタックオーバーフロー
CVE-2026-40892 2026-04-27 11:20 2026-04-21 Show GitHub Exploit DB Packet Storm
4997 7.5 重要
Network
follow-redirects project Follow Redirects Follow Redirects projectのFollow Redirectsにおける情報漏えいに関する脆弱性 CWE-200
CWE-noinfo
CVE-2026-40895 2026-04-27 11:20 2026-04-21 Show GitHub Exploit DB Packet Storm
4998 6.5 警告
Network
WWBN AVideo WWBNのAVideoにおけるユーザ制御の鍵による認証回避に関する脆弱性 CWE-639
ユーザ制御の鍵による認証回避
CVE-2026-40907 2026-04-27 11:20 2026-04-21 Show GitHub Exploit DB Packet Storm
4999 5.3 警告
Network
WWBN AVideo WWBNのAVideoにおける情報漏えいに関する脆弱性 CWE-200
情報漏えい
CVE-2026-40908 2026-04-27 11:20 2026-04-21 Show GitHub Exploit DB Packet Storm
5000 6.5 警告
Network
WWBN AVideo WWBNのAVideoにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-40909 2026-04-27 11:20 2026-04-21 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 5, 2026, 4:11 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
347591 - asp_press acs_blog Cross-site scripting (XSS) vulnerability in ACS Blog 1.1.1 allows remote attackers to inject arbitrary web script or HTML via onmouseover or onload events in (1) img, (2) link, or (3) mail tags. NVD-CWE-Other
CVE-2005-0945 2017-07-11 10:32 2005-05-2 Show GitHub Exploit DB Packet Storm
347592 - coinsoft_technologies phpcoin Directory traversal vulnerability in auxpage.php in phpCoin 1.2.1b and earlier allows remote attackers to read and execute arbitrary files via a .. (dot dot) in the page parameter. NVD-CWE-Other
CVE-2005-0947 2017-07-11 10:32 2005-05-2 Show GitHub Exploit DB Packet Storm
347593 - iatek portalapp SQL injection vulnerability in ad_click.asp for PortalApp allows remote attackers to execute arbitrary SQL commands via the banner_id parameter. NVD-CWE-Other
CVE-2005-0948 2017-07-11 10:32 2005-05-2 Show GitHub Exploit DB Packet Storm
347594 - iatek portalapp Multiple cross-site scripting (XSS) vulnerabilities in content.asp in Iatek PortalApp allow remote attackers to inject arbitrary web script or HTML via the (1) contenttype or (2) keywords parameter. NVD-CWE-Other
CVE-2005-0949 2017-07-11 10:32 2005-05-2 Show GitHub Exploit DB Packet Storm
347595 - faststone 4in1_browser Directory traversal vulnerability in FastStone 4in1 Browser 1.2 allows remote attackers to read arbitrary files via a (1) ... (triple dot) or (2) ..\ (dot dot backslash) in the URL. NVD-CWE-Other
CVE-2005-0950 2017-07-11 10:32 2005-03-29 Show GitHub Exploit DB Packet Storm
347596 - bay_technical_associates rpc3_telnet Bay Technical Associates RPC-3 Telnet Host 3.05 allows remote attackers to bypass authentication by pressing the escape and enter keys at the username prompt. NVD-CWE-Other
CVE-2005-0957 2017-07-11 10:32 2005-03-31 Show GitHub Exploit DB Packet Storm
347597 - lighthouse_development squirrelcart SQL injection vulnerability in index.php for Lighthouse Squirrelcart allows remote attackers to execute arbitrary SQL commands via the (1) crn parameter in a show action or (2) rn parameter in a show… NVD-CWE-Other
CVE-2005-0962 2017-07-11 10:32 2005-05-2 Show GitHub Exploit DB Packet Storm
347598 - toshiba acpi_flash_bios An error in the Toshiba ACPI BIOS 1.6 causes the BIOS to only examine the first slot in the Master Boot Record (MBR) table for an active partition, which prevents the system from booting even though … NVD-CWE-Other
CVE-2005-0963 2017-07-11 10:32 2005-05-2 Show GitHub Exploit DB Packet Storm
347599 - kerio personal_firewall Unknown vulnerability in Kerio Personal Firewall 4.1.2 and earlier allows local users to bypass firewall rules via a malicious process that impersonates a legitimate process that has fewer restrictio… NVD-CWE-Other
CVE-2005-0964 2017-07-11 10:32 2005-05-2 Show GitHub Exploit DB Packet Storm
347600 - apple
opendarwin
mac_os_x
mac_os_x_server
darwin_kernel
Integer signedness error in the parse_machfile function in the mach-o loader (mach_loader.c) for the Darwin Kernel as used in Mac OS X 10.3.7, and other versions before 10.3.9, allows local users to … NVD-CWE-Other
CVE-2005-0975 2017-07-11 10:32 2005-05-2 Show GitHub Exploit DB Packet Storm