Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 2, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
5241 5.3 警告
Network
jqlang jq jqlangのjqにおける複数の脆弱性 CWE-170
CWE-20
CVE-2026-33948 2026-04-23 10:12 2026-04-14 Show GitHub Exploit DB Packet Storm
5242 4.3 警告
Network
openwebui open webui openwebuiのopen webuiにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-34225 2026-04-23 10:12 2026-04-14 Show GitHub Exploit DB Packet Storm
5243 7.7 重要
Network
Weblate Weblate Weblateにおける複数の脆弱性 CWE-200
CWE-22
CWE-59
CVE-2026-34242 2026-04-23 10:12 2026-04-15 Show GitHub Exploit DB Packet Storm
5244 5 警告
Network
Weblate Weblate Weblateにおける複数の脆弱性 CWE-200
CWE-918
CVE-2026-34244 2026-04-23 10:12 2026-04-15 Show GitHub Exploit DB Packet Storm
5245 8.8 重要
Network
Weblate Weblate Weblateにおける権限管理に関する脆弱性 CWE-269
不適切な権限管理
CVE-2026-34393 2026-04-23 10:12 2026-04-15 Show GitHub Exploit DB Packet Storm
5246 6.5 警告
Network
McGill University LORIS (Longitudinal Online Research and Imaging System) McGill UniversityのLORIS (Longitudinal Online Research and Imaging System)におけるユーザ制御の鍵による認証回避に関する脆弱性 CWE-639
ユーザ制御の鍵による認証回避
CVE-2026-34985 2026-04-23 10:12 2026-04-8 Show GitHub Exploit DB Packet Storm
5247 6.5 警告
Network
McGill University LORIS (Longitudinal Online Research and Imaging System) McGill UniversityのLORIS (Longitudinal Online Research and Imaging System)におけるユーザ制御の鍵による認証回避に関する脆弱性 CWE-639
ユーザ制御の鍵による認証回避
CVE-2026-35165 2026-04-23 10:12 2026-04-8 Show GitHub Exploit DB Packet Storm
5248 5.4 警告
Network
McGill University LORIS (Longitudinal Online Research and Imaging System) McGill UniversityのLORIS (Longitudinal Online Research and Imaging System)における複数の脆弱性 CWE-552
CWE-79
CWE-79
CVE-2026-35169 2026-04-23 10:12 2026-04-8 Show GitHub Exploit DB Packet Storm
5249 4.3 警告
Network
McGill University LORIS (Longitudinal Online Research and Imaging System) McGill UniversityのLORIS (Longitudinal Online Research and Imaging System)におけるリンク解釈に関する脆弱性 CWE-59
リンク解釈の問題
CVE-2026-35400 2026-04-23 10:12 2026-04-8 Show GitHub Exploit DB Packet Storm
5250 5.4 警告
Network
McGill University LORIS (Longitudinal Online Research and Imaging System) McGill UniversityのLORIS (Longitudinal Online Research and Imaging System)におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-35403 2026-04-23 10:12 2026-04-8 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 3, 2026, 4:18 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
354621 - w.m.r._simpson bookreview Multiple cross-site scripting (XSS) vulnerabilities in BookReview beta 1.0 allow remote attackers to inject arbitrary web script or HTML via the node parameter to (1) add_review.htm, (2) suggest_revi… NVD-CWE-Other
CVE-2005-1782 2008-09-6 05:50 2005-05-26 Show GitHub Exploit DB Packet Storm
354622 - hosting_controller hosting_controller Hosting Controller 6.1 HotFix 2.0 and earlier allows remote attackers to steal passwords and gain privileges via a modified emailaddress parameter in an updateprofile action for UserProfile.asp. NVD-CWE-Other
CVE-2005-1784 2008-09-6 05:50 2005-05-27 Show GitHub Exploit DB Packet Storm
354623 - hosting_controller hosting_controller SQL injection vulnerability in resellerresources.asp in Hosting Controller 6.1 Hotfix 2.0 allows remote attackers to execute arbitrary SQL commands via the jresourceid parameter. NVD-CWE-Other
CVE-2005-1788 2008-09-6 05:50 2005-06-1 Show GitHub Exploit DB Packet Storm
354624 - india_software_solution shopping_cart SQL injection vulnerability in SignIn.asp in India Software Solution shopping cart allows remote attackers to execute arbitrary SQL commands via the password. NVD-CWE-Other
CVE-2005-1789 2008-09-6 05:50 2005-05-29 Show GitHub Exploit DB Packet Storm
354625 - microsoft windows_xp Memory leak in Windows Management Instrumentation (WMI) service allows attackers to cause a denial of service (memory consumption and crash) by creating security contexts more quickly than they can b… NVD-CWE-Other
CVE-2005-1792 2008-09-6 05:50 2005-06-1 Show GitHub Exploit DB Packet Storm
354626 - openssl openssl The design of Advanced Encryption Standard (AES), aka Rijndael, allows remote attackers to recover AES keys via timing attacks on S-box lookups, which are difficult to perform in constant time in AES… NVD-CWE-Other
CVE-2005-1797 2008-09-6 05:50 2005-05-26 Show GitHub Exploit DB Packet Storm
354627 - serverscheck monitoring_software Directory traversal vulnerability in ServersCheck Monitoring Software 5.9.0 to 5.10.0 allows remote attackers to read arbitrary files via .. (dot dot) sequences in an HTTP request. NVD-CWE-Other
CVE-2005-1798 2008-09-6 05:50 2005-05-29 Show GitHub Exploit DB Packet Storm
354628 - freestyle wiki
wikilite
Cross-site scripting (XSS) vulnerability in FreeStyle Wiki 3.5.7 and WikiLite (FSWikiLite) .10 allows remote attackers to inject arbitrary web script or HTML via unknown vectors. NVD-CWE-Other
CVE-2005-1799 2008-09-6 05:50 2005-05-31 Show GitHub Exploit DB Packet Storm
354629 - nortel contivity
vpn_router_1010
vpn_router_1050
vpn_router_1100
vpn_router_1700
vpn_router_1740
vpn_router_2700
vpn_router_5000
vpn_router_600
Nortel VPN Router (aka Contivity) allows remote attackers to cause a denial of service (crash) via an IPsec IKE packet with a malformed ISAKMP header. NVD-CWE-Other
CVE-2005-1802 2008-09-6 05:50 2005-05-27 Show GitHub Exploit DB Packet Storm
354630 - net_portal_dynamic_system net_portal_dynamic_system Multiple cross-site scripting (XSS) vulnerabilities in Net Portal Dynamic System (NPDS) 5.0 allow remote attackers to inject arbitrary web script or HTML via the language parameter to (1) admin.php, … NVD-CWE-Other
CVE-2005-1803 2008-09-6 05:50 2005-05-29 Show GitHub Exploit DB Packet Storm