Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 9, 2026, 10 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
5421 5.4 警告
Network
Docmost Docmost Docmostにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-40927 2026-04-27 11:20 2026-04-21 Show GitHub Exploit DB Packet Storm
5422 5.4 警告
Network
WWBN AVideo WWBNのAVideoにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2026-40928 2026-04-27 11:20 2026-04-21 Show GitHub Exploit DB Packet Storm
5423 5.4 警告
Network
WWBN AVideo WWBNのAVideoにおけるクロスサイトリクエストフォージェリの脆弱性 CWE-352
同一生成元ポリシー違反
CVE-2026-40929 2026-04-27 11:20 2026-04-21 Show GitHub Exploit DB Packet Storm
5424 7.8 重要
Local
node-modules compressing node-modulesのcompressingにおけるリンク解釈に関する脆弱性 CWE-59
リンク解釈の問題
CVE-2026-40931 2026-04-27 11:20 2026-04-21 Show GitHub Exploit DB Packet Storm
5425 5.3 警告
Network
WWBN AVideo WWBNのAVideoにおける推測可能な CAPTCHA の脆弱性 CWE-804
推測可能な CAPTCHA
CVE-2026-40935 2026-04-27 11:20 2026-04-21 Show GitHub Exploit DB Packet Storm
5426 5.3 警告
Network
WWBN AVideo WWBNのAVideoにおけるサーバサイドのリクエストフォージェリの脆弱性 CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-41055 2026-04-27 11:20 2026-04-21 Show GitHub Exploit DB Packet Storm
5427 8.1 重要
Network
WWBN AVideo WWBNのAVideoにおける過度に許容されるクロスドメインホワイトリストに関する脆弱性 CWE-942
過度に許容されるクロスドメインホワイトリスト
CVE-2026-41056 2026-04-27 11:20 2026-04-21 Show GitHub Exploit DB Packet Storm
5428 7.5 重要
Network
libexpat project libexpat libexpat projectのlibexpatにおけるエントロピー不足に関する脆弱性 CWE-331
エントロピー不足
CVE-2026-41080 2026-04-27 11:20 2026-04-16 Show GitHub Exploit DB Packet Storm
5429 7.5 重要
Network
free5gc free5gc
pcf
free5GCのfree5GC等の複数製品におけるリソースの枯渇に関する脆弱性 CWE-400
リソースの枯渇
CVE-2026-41135 2026-04-27 11:20 2026-04-22 Show GitHub Exploit DB Packet Storm
5430 5.3 警告
Network
free5gc free5gc
amf
free5GCのamf等の複数製品における予期せぬ動作に関する脆弱性  CWE-440
予期せぬ動作
CVE-2026-41136 2026-04-27 11:20 2026-04-22 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 9, 2026, 4:16 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
348461 - punbb punbb Cross-site scripting (XSS) vulnerability in PunBB 1.2.3 allows remote attackers to inject arbitrary web script or HTML via the (1) email or (2) Jabber parameters. NVD-CWE-Other
CVE-2005-0818 2017-07-11 10:32 2005-05-2 Show GitHub Exploit DB Packet Storm
348462 - - - Unknown vulnerability in Citrix MetaFrame Conferencing Manager 3.0 allows conference members to bypass organizer restrictions to control the keyboard and mouse. NVD-CWE-Other
CVE-2005-0821 2017-07-11 10:32 2005-05-2 Show GitHub Exploit DB Packet Storm
348463 - thepoolclub ipool
isnooker
ThePoolClub (1) iPool and (2) iSnooker 1.6.81 and earlier stores usernames and passwords in cleartext in the MyDetails.txt file, which allows local users to gain privileges. NVD-CWE-Other
CVE-2005-0823 2017-07-11 10:32 2005-05-2 Show GitHub Exploit DB Packet Storm
348464 - ollydbg ollydbg OllyDbg 1.10 and earlier allows remote attackers to cause a denial of service (application crash) via a dynamic link library (DLL) with a long filename. NVD-CWE-Other
CVE-2005-0826 2017-07-11 10:32 2005-05-2 Show GitHub Exploit DB Packet Storm
348465 - icecast icecast IceCast 2.20 allows remote attackers to bypass the XSL parser and obtain the source for XSL files via a request for a .xsl file with a trailing . (dot). NVD-CWE-Other
CVE-2005-0837 2017-07-11 10:32 2005-05-2 Show GitHub Exploit DB Packet Storm
348466 - icecast icecast Multiple buffer overflows in the XSL parser for IceCast 2.20 may allow attackers to cause a denial of service and possibly execute arbitrary code via (1) a long test value in an xsl:when tag, (2) a l… NVD-CWE-Other
CVE-2005-0838 2017-07-11 10:32 2005-05-2 Show GitHub Exploit DB Packet Storm
348467 - phpmyfamily phpmyfamily SQL injection vulnerability in (1) people.php, (2) track.php, (3) edit.php, (4) document.php, (5) census.php, (6) passthru.php and possibly other php files in phpMyFamily 1.4.0 allows remote attacker… NVD-CWE-Other
CVE-2005-0841 2017-07-11 10:32 2005-05-2 Show GitHub Exploit DB Packet Storm
348468 - nortel contivity Nortel VPN client 5.01 stores the cleartext password in the memory of the Extranet.exe process, which could allow local users to obtain sensitive information. CWE-310
Cryptographic Issues
CVE-2005-0844 2017-07-11 10:32 2005-05-2 Show GitHub Exploit DB Packet Storm
348469 - funlabs 4x4_off-road_adventure_iii
cabelas_big_game_hunter_2004_season
cabelas_big_game_hunter_2005
cabelas_dangerous_hunts
cabelas_deer_hunt_2005_season
revolution
secret_service_in_harms_…
Multiple games developed by FUN labs, including 4X4 Off-road Adventure III, Big Game Hunter, Dangerous Hunts, Deer Hunt, Revolution, Secret Service, Shadow Force, and US Most Wanted, allow remote att… NVD-CWE-Other
CVE-2005-0848 2017-07-11 10:32 2005-05-2 Show GitHub Exploit DB Packet Storm
348470 - betaparticle betaparticle_blog betaparticle blog (bp blog), posisbly before version 4, allows remote attackers to bypass authentication and (1) upload files via a direct request to upload.asp or (2) delete files via a direct reque… NVD-CWE-Other
CVE-2005-0854 2017-07-11 10:32 2005-05-2 Show GitHub Exploit DB Packet Storm