Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 31, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
5041 7.2 重要
Network
デル PowerProtect DP Series Appliance
data domain operating system
デルのdata domain operating system等の複数製品におけるOS コマンドインジェクションの脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2026-23774 2026-04-24 11:33 2026-04-20 Show GitHub Exploit DB Packet Storm
5042 8.7 重要
Network
decidim decidim Decidim Free Software AssociationのDecidimにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-23891 2026-04-24 11:33 2026-04-13 Show GitHub Exploit DB Packet Storm
5043 4.9 警告
Network
OctoberCMS October OctoberCMSのOctoberにおける複数の脆弱性 CWE-200
CWE-94
CVE-2026-25125 2026-04-24 11:33 2026-04-14 Show GitHub Exploit DB Packet Storm
5044 6.7 警告
Network
フォーティネット FortiSandbox
FortiSandbox Cloud
フォーティネットのFortiSandbox等の複数製品におけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-25691 2026-04-24 11:33 2026-04-14 Show GitHub Exploit DB Packet Storm
5045 6.1 警告
Local
Zulip Zulip Zulipにおけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2026-26058 2026-04-24 11:33 2026-04-3 Show GitHub Exploit DB Packet Storm
5046 8.8 重要
Network
デル PowerProtect DP Series Appliance
data domain operating system
デルのdata domain operating system等の複数製品における重要な機能に対する認証の欠如に関する脆弱性 CWE-306
重要な機能に対する認証の欠如 解説
CVE-2026-26944 2026-04-24 11:33 2026-04-20 Show GitHub Exploit DB Packet Storm
5047 6.1 警告
Network
Jeremiah Lowin FastMCP Jeremiah LowinのFastMCPにおけるフィルタリングの回避に関する脆弱性 CWE-441
フィルタリング回避
CVE-2026-27124 2026-04-24 11:33 2026-04-3 Show GitHub Exploit DB Packet Storm
5048 2.7
Network
フォーティネット FortiSandbox
FortiSandbox Cloud
フォーティネットのFortiSandbox等の複数製品における認証情報の不十分な保護に関する脆弱性 CWE-522
認証情報の不十分な保護
CVE-2026-27316 2026-04-24 11:33 2026-04-14 Show GitHub Exploit DB Packet Storm
5049 6.3 警告
Network
OpenPrinting CUPS OpenPrintingのCUPSにおける不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2026-27447 2026-04-24 11:32 2026-04-3 Show GitHub Exploit DB Packet Storm
5050 4.7 警告
Local
kernel.org util-linux kernel.orgのutil-linuxにおける複数の脆弱性 CWE-269
CWE-367
CWE-367
CWE-59
CVE-2026-27456 2026-04-24 11:32 2026-04-3 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 31, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
350231 - bea weblogic_server BEA WebLogic Server and Express 6.0 through 7.0 does not properly restrict access to certain internal servlets that perform administrative functions, which allows remote attackers to read arbitrary f… NVD-CWE-Other
CVE-2003-0151 2016-10-18 11:30 2003-03-24 Show GitHub Exploit DB Packet Storm
350232 - mozilla bonsai Cross-site scripting vulnerabilities (XSS) in bonsai Mozilla CVS query tool allow remote attackers to execute arbitrary web script via (1) the file, root, or rev parameters to cvslog.cgi, (2) the fil… NVD-CWE-Other
CVE-2003-0154 2016-10-18 11:30 2003-04-2 Show GitHub Exploit DB Packet Storm
350233 - cross_referencer lxr Directory traversal vulnerability in Cross-Referencing Linux (LXR) allows remote attackers to read arbitrary files via .. (dot dot) sequences in the v parameter. NVD-CWE-Other
CVE-2003-0156 2016-10-18 11:30 2003-03-24 Show GitHub Exploit DB Packet Storm
350234 - gaim-encryption gaim-encryption decrypt_msg for the Gaim-Encryption GAIM plugin 1.15 and earlier does not properly validate a message length parameter, which allows remote attackers to cause a denial of service (crash) via a negati… NVD-CWE-Other
CVE-2003-0163 2016-10-18 11:30 2003-05-5 Show GitHub Exploit DB Packet Storm
350235 - hp instant_toptools hpnst.exe in the GoAhead-Webs webserver for HP Instant TopTools before 5.55 allows remote attackers to cause a denial of service (CPU consumption) via a request to hpnst.exe that calls itself, which … NVD-CWE-Other
CVE-2003-0169 2016-10-18 11:30 2003-04-11 Show GitHub Exploit DB Packet Storm
350236 - borland_software
firebirdsql
interbase
firebird
Buffer overflow gds_lock_mgr of Interbase Database 6.x allows local users to gain privileges via a long ISC_LOCK_ENV environment variable (INTERBASE_LOCK). NVD-CWE-Other
CVE-2003-0197 2016-10-18 11:30 2003-04-11 Show GitHub Exploit DB Packet Storm
350237 - kde kde KDE 2 and KDE 3.1.1 and earlier 3.x versions allows attackers to execute arbitrary commands via (1) PostScript (PS) or (2) PDF files, related to missing -dPARANOIDSAFER and -dSAFER arguments when usi… NVD-CWE-Other
CVE-2003-0204 2016-10-18 11:30 2003-05-5 Show GitHub Exploit DB Packet Storm
350238 - gkrellm_newsticker gkrellm_newsticker gkrellm-newsticker gkrellm plugin before 0.3-3.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the ticker title of a URI. NVD-CWE-Other
CVE-2003-0205 2016-10-18 11:30 2003-05-12 Show GitHub Exploit DB Packet Storm
350239 - gkrellm_newsticker gkrellm_newsticker gkrellm-newsticker gkrellm plugin before 0.3-3.1 allows remote attackers to cause a denial of service (crash) via (1) link or (2) title elements that contain multiple lines. NVD-CWE-Other
CVE-2003-0206 2016-10-18 11:30 2003-05-12 Show GitHub Exploit DB Packet Storm
350240 - macromedia flash Cross-site scripting (XSS) vulnerability in Macromedia Flash ad user tracking capability allows remote attackers to insert arbitrary Javascript via the clickTAG field. NVD-CWE-Other
CVE-2003-0208 2016-10-18 11:30 2003-05-5 Show GitHub Exploit DB Packet Storm