Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 7, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
5481 5.3 警告
Network
Apache Software Foundation Apache Doris-MCP-Server Apache Software FoundationのApache Doris-MCP-ServerにおけるSQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2025-66335 2026-04-24 11:34 2026-04-20 Show GitHub Exploit DB Packet Storm
5482 6.5 警告
Network
フォーティネット FortiManager Cloud
FortiAnalyzer
FortiAnalyzer Cloud
FortiManager
フォーティネットのFortiAnalyzer等の複数製品におけるパストラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2025-68649 2026-04-24 11:34 2026-04-14 Show GitHub Exploit DB Packet Storm
5483 8.4 重要
Local
Nitro Software Inc. Nitro PDF Pro Nitro Software Inc.のNitro PDF Proにおける解放済みメモリの使用に関する脆弱性 CWE-416
解放済みメモリの使用
CVE-2025-69627 2026-04-24 11:34 2026-04-13 Show GitHub Exploit DB Packet Storm
5484 4.3 警告
Network
Fortra GoAnywhere Managed File Transfer FortraのGoAnywhere Managed File Transferにおけるセッション期限に関する脆弱性 CWE-613
不適切なセッション期限
CVE-2026-0971 2026-04-24 11:34 2026-04-21 Show GitHub Exploit DB Packet Storm
5485 5.4 警告
Network
Fortra GoAnywhere Managed File Transfer FortraのGoAnywhere Managed File Transferにおけるインジェクションに関する脆弱性 CWE-74
インジェクション
CVE-2026-0972 2026-04-24 11:34 2026-04-21 Show GitHub Exploit DB Packet Storm
5486 6.5 警告
Network
Fortra GoAnywhere Managed File Transfer FortraのGoAnywhere Managed File Transferにおけるインジェクションに関する脆弱性 CWE-74
インジェクション
CVE-2026-1089 2026-04-24 11:34 2026-04-21 Show GitHub Exploit DB Packet Storm
5487 4.9 警告
Network
オラクル MySQL Server オラクルのMySQL Serverにおけるリソースの枯渇に関する脆弱性 CWE-400
リソースの枯渇
CVE-2026-21998 2026-04-24 11:34 2026-04-21 Show GitHub Exploit DB Packet Storm
5488 2.7
Network
オラクル MySQL Server オラクルのMySQL Serverにおける情報漏えいに関する脆弱性 CWE-200
情報漏えい
CVE-2026-22001 2026-04-24 11:34 2026-04-21 Show GitHub Exploit DB Packet Storm
5489 4.9 警告
Network
オラクル MySQL Server オラクルのMySQL Serverにおけるリソースの枯渇に関する脆弱性 CWE-400
リソースの枯渇
CVE-2026-22002 2026-04-24 11:34 2026-04-21 Show GitHub Exploit DB Packet Storm
5490 4.9 警告
Network
オラクル MySQL Server オラクルのMySQL Serverにおけるリソースの枯渇に関する脆弱性 CWE-400
リソースの枯渇
CVE-2026-22004 2026-04-24 11:34 2026-04-21 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 7, 2026, 4:13 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
354501 - macromedia jrun Macromedia JRun 3.0 and 3.1 allows remote attackers to obtain duplicate active user session IDs and perform actions as other users via a URL request for the web application directory without the trai… NVD-CWE-Other
CVE-2001-1513 2008-09-11 04:10 2001-12-31 Show GitHub Exploit DB Packet Storm
354502 - postnuke_software_foundation postnuke Cross-site scripting (XSS) vulnerability in user.php in PostNuke 0.64 allows remote attackers to inject arbitrary web script or HTML via the uname parameter. NVD-CWE-Other
CVE-2001-1521 2008-09-11 04:10 2001-12-31 Show GitHub Exploit DB Packet Storm
354503 - francisco_burzi php-nuke Cross-site scripting (XSS) vulnerability in PHP-Nuke 5.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) uname parameter in user.php, (2) ttitle, letter and f… NVD-CWE-Other
CVE-2001-1524 2008-09-11 04:10 2001-12-31 Show GitHub Exploit DB Packet Storm
354504 - microsoft windows_me ssdpsrv.exe in Windows ME allows remote attackers to cause a denial of service by sending multiple newlines in a Simple Service Discovery Protocol (SSDP) message. NOTE: multiple replies to the origi… NVD-CWE-Other
CVE-2001-1552 2008-09-11 04:10 2001-12-31 Show GitHub Exploit DB Packet Storm
354505 - ibm websphere_application_server Cross-site scripting vulnerability in IBM WebSphere 3.02 and 3.5 FP2 allows remote attackers to execute Javascript by inserting the Javascript into (1) a request for a .JSP file, or (2) a request to … NVD-CWE-Other
CVE-2001-0824 2008-09-11 04:09 2001-12-6 Show GitHub Exploit DB Packet Storm
354506 - grant_averett ceberus_ftp_server Cerberus FTP server 1.0 - 1.5 allows remote attackers to cause a denial of service (crash) via a large number of "PASV" requests. NVD-CWE-Other
CVE-2001-0827 2008-09-11 04:09 2001-12-6 Show GitHub Exploit DB Packet Storm
354507 - apache tomcat A cross-site scripting vulnerability in Apache Tomcat 3.2.1 allows a malicious webmaster to embed Javascript in a request for a .JSP file, which causes the Javascript to be inserted into an error mes… NVD-CWE-Other
CVE-2001-0829 2008-09-11 04:09 2001-12-6 Show GitHub Exploit DB Packet Storm
354508 - sane sane Certain backend drivers in the SANE library 1.0.3 and earlier, as used in frontend software such as XSane, allows local users to modify files via a symlink attack on temporary files. NVD-CWE-Other
CVE-2001-0890 2008-09-11 04:09 2001-12-11 Show GitHub Exploit DB Packet Storm
354509 - washington_university wu-ftpd Vulnerability in wu-ftpd 2.6.0, and possibly earlier versions, which is unrelated to the ftpglob bug described in CVE-2001-0550. NVD-CWE-Other
CVE-2001-0935 2008-09-11 04:09 2001-11-28 Show GitHub Exploit DB Packet Storm
354510 - paul_m._jones phorecast Phorecast PHP script before 0.40 allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable. NVD-CWE-Other
CVE-2001-1049 2008-09-11 04:09 2001-10-2 Show GitHub Exploit DB Packet Storm