Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 8, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
5391 6.5 警告
Network
jellyfin jellyfin jellyfinにおけるリソースの枯渇に関する脆弱性 CWE-400
リソースの枯渇
CVE-2026-35034 2026-04-27 11:22 2026-04-14 Show GitHub Exploit DB Packet Storm
5392 8.8 重要
Network
Glances project Glances Nicolas Hennion (nicolargo)のGlancesにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-35587 2026-04-27 11:21 2026-04-21 Show GitHub Exploit DB Packet Storm
5393 9.3 緊急
Network
nanobot nanobot nanobotにおける WebSocket でのオリジン検証の欠如に関する脆弱性 CWE-1385
WebSocket でのオリジン検証の欠如
CVE-2026-35589 2026-04-27 11:21 2026-04-14 Show GitHub Exploit DB Packet Storm
5394 8.8 重要
Network
webkul krayin crm webkulのkrayin crmにおける複数の脆弱性 CWE-269
CWE-639
CVE-2026-38529 2026-04-27 11:21 2026-04-14 Show GitHub Exploit DB Packet Storm
5395 8.1 重要
Network
webkul krayin crm webkulのkrayin crmにおけるユーザ制御の鍵による認証回避に関する脆弱性 CWE-639
ユーザ制御の鍵による認証回避
CVE-2026-38530 2026-04-27 11:21 2026-04-14 Show GitHub Exploit DB Packet Storm
5396 8.1 重要
Network
webkul krayin crm webkulのkrayin crmにおけるユーザ制御の鍵による認証回避に関する脆弱性 CWE-639
ユーザ制御の鍵による認証回避
CVE-2026-38532 2026-04-27 11:21 2026-04-14 Show GitHub Exploit DB Packet Storm
5397 5.4 警告
Network
Istio Istio Istioにおける複数の脆弱性 CWE-185
CWE-863
CVE-2026-39350 2026-04-27 11:21 2026-04-15 Show GitHub Exploit DB Packet Storm
5398 6.5 警告
Network
Project Jupyter nbconvert Project Jupyterのnbconvertにおける複数の脆弱性 CWE-22
CWE-73
CVE-2026-39377 2026-04-27 11:21 2026-04-21 Show GitHub Exploit DB Packet Storm
5399 6.5 警告
Network
Project Jupyter nbconvert Project Jupyterのnbconvertにおける複数の脆弱性 CWE-22
CWE-73
CVE-2026-39378 2026-04-27 11:21 2026-04-21 Show GitHub Exploit DB Packet Storm
5400 7.2 重要
Network
boidcms boidcms boidcmsにおけるPHP リモートファイルインクルージョンの脆弱性 CWE-98
PHP リモートファイルインクルージョン
CVE-2026-39387 2026-04-27 11:21 2026-04-14 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 9, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
349651 - - - SQL injection vulnerability in the Reviews module in PHP-Nuke 6.0 to 7.3 allows remote attackers to execute arbitrary SQL commands via the order parameter. NVD-CWE-Other
CVE-2004-2295 2017-07-11 10:31 2004-12-31 Show GitHub Exploit DB Packet Storm
349652 - francisco_burzi php-nuke The preview_review function in the Reviews module in PHP-Nuke 6.0 to 7.3, when running on Windows systems, allows remote attackers to obtain sensitive information via an invalid date parameter, which… NVD-CWE-Other
CVE-2004-2296 2017-07-11 10:31 2004-12-31 Show GitHub Exploit DB Packet Storm
349653 - francisco_burzi php-nuke The Reviews module in PHP-Nuke 6.0 to 7.3 allows remote attackers to cause a denial of service (CPU and memory consumption) via a large, out-of-range score parameter. NVD-CWE-Other
CVE-2004-2297 2017-07-11 10:31 2004-12-31 Show GitHub Exploit DB Packet Storm
349654 - - - Buffer overflow in Omnicron OmniHTTPd 3.0a and earlier allows remote attackers to execute arbitrary code via an HTTP GET request with a long Range header. NVD-CWE-Other
CVE-2004-2299 2017-07-11 10:31 2004-12-31 Show GitHub Exploit DB Packet Storm
349655 - ucd-snmp ucd-snmp Buffer overflow in snmpd in ucd-snmp 4.2.6 and earlier, when installed setuid root, allows local users to execute arbitrary code via a long -p command line argument. NOTE: it is not clear whether th… NVD-CWE-Other
CVE-2004-2300 2017-07-11 10:31 2004-12-31 Show GitHub Exploit DB Packet Storm
349656 - - - Eudora before 6.1.1 allows remote attackers to cause a denial of service (crash) via an e-mail with a long "To:" field, possibly due to a buffer overflow. NVD-CWE-Other
CVE-2004-2301 2017-07-11 10:31 2004-12-31 Show GitHub Exploit DB Packet Storm
349657 - mtools mformat MTools Mformat before 3.9.9, when installed setuid root, creates files with world-readable and world-writable permissions, which allows local users to read and overwrite files. NVD-CWE-Other
CVE-2004-2303 2017-07-11 10:31 2004-12-31 Show GitHub Exploit DB Packet Storm
349658 - cerulean_studios trillian
trillian_pro
Integer overflow in Trillian 0.74 and earlier, and Trillian Pro 2.01 and earlier, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a directIM packet that t… NVD-CWE-Other
CVE-2004-2304 2017-07-11 10:31 2004-12-31 Show GitHub Exploit DB Packet Storm
349659 - cpanel cpanel Cross-site scripting (XSS) vulnerability in cPanel 9.1.0 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the dir parameter in dohtaccess.html. NVD-CWE-Other
CVE-2004-2308 2017-07-11 10:31 2004-12-31 Show GitHub Exploit DB Packet Storm
349660 - crob crob_ftp_server Directory traversal vulnerability in Crob FTP Server 3.5.1 allows local users to browse outside the FTP root via multiple ../ (dot dot slash) in the DIR command. NVD-CWE-Other
CVE-2004-2309 2017-07-11 10:31 2004-12-31 Show GitHub Exploit DB Packet Storm